Tor Exit Node Connection
Informational
False Positive
ALR-00029 · 2026-05-22T06:40:11Z
Description
Connection from WS-MAC-005 to known Tor exit node detected by Cloud Connector. User 'a.wilson' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
06:40:11
Event ingested by SOC365 Engine
06:40:13
EmilyAI triage started — correlation enrichment
06:40:19
EmilyAI confidence: 94% — escalated to human analyst
06:40:34
Alert assigned to analyst: EmilyAI (auto)
06:41:05
Investigation started — querying SIEM and threat intelligence
06:49:54
Containment action taken — endpoint isolated
06:53:21
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00253 | 6h ago | Port Scan Detected | Low | Open | WS-MAC-005 |
| ALR-00409 | 15h ago | DecoyPulse Honeypot Triggered | Medium | Investigating | WS-MAC-005 |
| ALR-00174 | 15h ago | Tor Exit Node Connection | Informational | Resolved | WS-PC-004 |
| ALR-00088 | 1d ago | Credential Stuffing Attempt | Low | Investigating | WS-MAC-005 |
| ALR-00330 | 1d ago | Brute Force SSH | Medium | Investigating | WS-MAC-005 |