DLP Policy Violation
Medium
Escalated
ALR-00065 · 2026-04-10T15:06:48Z
Description
DLP policy violation: user 'f.hall' attempted to email 3 files classified as 'Confidential' to external address from WS-LAP-012.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
15:06:48
Event ingested by SOC365 Engine
15:06:49
EmilyAI triage started — correlation enrichment
15:07:02
EmilyAI confidence: 88% — escalated to human analyst
15:07:33
Alert assigned to analyst: Anika Patel
15:07:33
Investigation started — querying SIEM and threat intelligence
15:14:57
Containment action taken — endpoint isolated
15:23:56
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00208 | 4h ago | C2 Beacon Activity | Informational | Escalated | WS-LAP-012 |
| ALR-00009 | 4h ago | Brute Force SSH | High | Investigating | WS-LAP-012 |
| ALR-00297 | 6h ago | Certificate Anomaly | Low | Resolved | WS-LAP-012 |
| ALR-00206 | 8h ago | DLP Policy Violation | Low | Resolved | WS-MAC-005 |
| ALR-00321 | 9h ago | Anomalous DNS Query | Medium | Open | WS-LAP-012 |