Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:53:16 UTC

Phishing Email Blocked

Informational False Positive
ALR-00010 · 2026-05-26T23:43:21Z

Description

Phishing email targeting 'h.roberts@company.co.uk' blocked by Email Gateway. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00010
Timestamp
2026-05-26T23:43:21Z
Severity
Informational
Status
False Positive
Detection Source
Email Gateway
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-DC-01
User Account
h.roberts
Source IP
45.136.148.79
Destination IP
10.0.94.175
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

23:43:21 Event ingested by SOC365 Engine
23:43:26 EmilyAI triage started — correlation enrichment
23:43:31 EmilyAI confidence: 84% — escalated to human analyst
23:44:02 Alert assigned to analyst: EmilyAI (auto)
23:46:03 Investigation started — querying SIEM and threat intelligence
23:48:26 Containment action taken — endpoint isolated
23:54:47 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00177 2h ago Kerberoasting Attempt Medium Resolved SRV-DC-01
ALR-00495 10h ago DLP Policy Violation Medium Open SRV-DC-01
ALR-00339 21h ago DLP Policy Violation Informational Investigating SRV-DC-01
ALR-00172 21h ago Suspicious PowerShell Execution Medium Escalated SRV-DC-01
ALR-00192 1d ago Phishing Email Blocked Low Investigating SRV-WEB-01