Phishing Email Blocked
Informational
Escalated
ALR-00017 · 2026-04-09T20:22:36Z
Description
Phishing email targeting 'm.taylor@company.co.uk' blocked by DLP Module. Payload: credential harvesting link mimicking Microsoft 365 login.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:22:36
Event ingested by SOC365 Engine
20:22:37
EmilyAI triage started — correlation enrichment
20:22:41
EmilyAI confidence: 94% — escalated to human analyst
20:23:03
Alert assigned to analyst: EmilyAI (auto)
20:24:47
Investigation started — querying SIEM and threat intelligence
20:28:57
Containment action taken — endpoint isolated
20:34:05
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00416 | 5h ago | Phishing Email Blocked | Low | Open | WS-PC-006 |
| ALR-00485 | 15h ago | Phishing Email Blocked | Critical | Open | SRV-BACKUP-01 |
| ALR-00006 | 1d ago | DecoyPulse Honeypot Triggered | Medium | Open | SRV-APP-01 |
| ALR-00188 | 1d ago | Phishing Email Blocked | Low | Escalated | WS-PC-003 |
| ALR-00347 | 1d ago | C2 Beacon Activity | Low | Escalated | SRV-APP-01 |