Insider Threat Indicator
Low
False Positive
ALR-00020 · 2026-04-06T11:34:29Z
Description
Anomalous after-hours access by 'j.smith' on SRV-FILE-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Network IDS.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:34:29
Event ingested by SOC365 Engine
11:34:33
EmilyAI triage started — correlation enrichment
11:34:41
EmilyAI confidence: 86% — escalated to human analyst
11:35:04
Alert assigned to analyst: EmilyAI (auto)
11:36:24
Investigation started — querying SIEM and threat intelligence
11:43:28
Containment action taken — endpoint isolated
11:50:13
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00003 | 5h ago | Anomalous DNS Query | Low | False Positive | SRV-FILE-01 |
| ALR-00445 | 6h ago | Pass-the-Hash Detected | Low | Escalated | SRV-FILE-01 |
| ALR-00370 | 7h ago | Unauthorised USB Device | Low | Resolved | SRV-FILE-01 |
| ALR-00095 | 10h ago | Insider Threat Indicator | Low | Open | WS-LAP-012 |
| ALR-00251 | 15h ago | Kerberoasting Attempt | Medium | Investigating | SRV-FILE-01 |