Unusual Outbound Traffic
Medium
Resolved
ALR-00033 · 2026-05-22T18:52:14Z
Description
Unusual outbound traffic pattern from WS-LAP-010 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by SOC365 Engine.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
18:52:14
Event ingested by SOC365 Engine
18:52:16
EmilyAI triage started — correlation enrichment
18:52:25
EmilyAI confidence: 93% — escalated to human analyst
18:52:41
Alert assigned to analyst: Marcus Webb
18:54:51
Investigation started — querying SIEM and threat intelligence
18:58:00
Containment action taken — endpoint isolated
19:10:29
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00105 | 15m ago | Shadow IT Discovery | Low | False Positive | WS-LAP-010 |
| ALR-00483 | 6h ago | Unusual Outbound Traffic | Low | Open | AP-WIFI-03 |
| ALR-00220 | 13h ago | Ransomware Behaviour Detected | Informational | False Positive | WS-LAP-010 |
| ALR-00297 | 14h ago | Malware Signature Match | Informational | Resolved | WS-LAP-010 |
| ALR-00390 | 1d ago | Brute Force SSH | Medium | False Positive | WS-LAP-010 |