Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:02 UTC

DLP Policy Violation

Informational Investigating
ALR-00026 · 2026-04-07T18:07:04Z

Description

DLP policy violation: user 'm.taylor' attempted to email 3 files classified as 'Confidential' to external address from WS-PC-003.

Alert Metadata

Alert ID
ALR-00026
Timestamp
2026-04-07T18:07:04Z
Severity
Informational
Status
Investigating
Detection Source
Attack Surface Scanner
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-003
User Account
m.taylor
Source IP
45.34.148.181
Destination IP
10.0.54.149
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

18:07:04 Event ingested by SOC365 Engine
18:07:05 EmilyAI triage started — correlation enrichment
18:07:11 EmilyAI confidence: 97% — escalated to human analyst
18:07:44 Alert assigned to analyst: EmilyAI (auto)
18:09:49 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00182 5h ago DLP Policy Violation Medium Escalated SRV-APP-01
ALR-00132 5h ago DLP Policy Violation Low False Positive SRV-WEB-01
ALR-00334 11h ago Unusual Outbound Traffic Low Open WS-PC-003
ALR-00239 13h ago Shadow IT Discovery Low Open WS-PC-003
ALR-00453 18h ago DLP Policy Violation Low False Positive WS-LAP-010