Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:04 UTC

Insider Threat Indicator

Low False Positive
ALR-00020 · 2026-04-06T11:34:29Z

Description

Anomalous after-hours access by 'j.smith' on SRV-FILE-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Network IDS.

Alert Metadata

Alert ID
ALR-00020
Timestamp
2026-04-06T11:34:29Z
Severity
Low
Status
False Positive
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-FILE-01
User Account
j.smith
Source IP
194.211.62.121
Destination IP
10.0.114.122
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Collection
Technique
T1119
Reference
attack.mitre.org/techniques/T1119

Investigation Timeline

11:34:29 Event ingested by SOC365 Engine
11:34:33 EmilyAI triage started — correlation enrichment
11:34:41 EmilyAI confidence: 86% — escalated to human analyst
11:35:04 Alert assigned to analyst: EmilyAI (auto)
11:36:24 Investigation started — querying SIEM and threat intelligence
11:43:28 Containment action taken — endpoint isolated
11:50:13 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00003 5h ago Anomalous DNS Query Low False Positive SRV-FILE-01
ALR-00445 6h ago Pass-the-Hash Detected Low Escalated SRV-FILE-01
ALR-00370 7h ago Unauthorised USB Device Low Resolved SRV-FILE-01
ALR-00095 10h ago Insider Threat Indicator Low Open WS-LAP-012
ALR-00251 15h ago Kerberoasting Attempt Medium Investigating SRV-FILE-01