Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:54:54 UTC

Insider Threat Indicator

Critical Open
ALR-00055 · 2026-05-24T23:11:10Z

Description

Anomalous after-hours access by 'n.clark' on SRV-WEB-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Firewall.

Alert Metadata

Alert ID
ALR-00055
Timestamp
2026-05-24T23:11:10Z
Severity
Critical
Status
Open
Detection Source
Firewall
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
SRV-WEB-01
User Account
n.clark
Source IP
91.227.195.31
Destination IP
10.1.64.102
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Collection
Technique
T1119
Reference
attack.mitre.org/techniques/T1119

Investigation Timeline

23:11:10 Event ingested by SOC365 Engine
23:11:11 EmilyAI triage started — correlation enrichment
23:11:21 EmilyAI confidence: 78% — escalated to human analyst
23:11:39 Alert assigned to analyst: Marcus Webb
23:14:01 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00449 1h ago Insider Threat Indicator Low Open WS-PC-004
ALR-00093 6h ago Insider Threat Indicator Informational Escalated WS-LAP-011
ALR-00011 7h ago Data Exfiltration Attempt High Escalated SRV-WEB-01
ALR-00114 9h ago Insider Threat Indicator Informational Resolved VM-DEV-01
ALR-00406 10h ago Data Exfiltration Attempt Informational False Positive SRV-WEB-01