Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:53:16 UTC

DLP Policy Violation

Medium False Positive
ALR-00065 · 2026-05-23T14:29:26Z

Description

DLP policy violation: user 'r.davies' attempted to email 3 files classified as 'Confidential' to external address from WS-PC-004.

Alert Metadata

Alert ID
ALR-00065
Timestamp
2026-05-23T14:29:26Z
Severity
Medium
Status
False Positive
Detection Source
Email Gateway
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-PC-004
User Account
r.davies
Source IP
103.150.216.96
Destination IP
10.2.230.237
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

14:29:26 Event ingested by SOC365 Engine
14:29:29 EmilyAI triage started — correlation enrichment
14:29:34 EmilyAI confidence: 81% — escalated to human analyst
14:29:58 Alert assigned to analyst: Emma Richardson
14:32:06 Investigation started — querying SIEM and threat intelligence
14:34:10 Containment action taken — endpoint isolated
14:45:50 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00106 2h ago DLP Policy Violation High Investigating WS-PC-004
ALR-00051 5h ago Unauthorised USB Device Medium Resolved WS-PC-004
ALR-00495 10h ago DLP Policy Violation Medium Open SRV-DC-01
ALR-00457 13h ago Failed MFA Challenge High Open WS-PC-004
ALR-00339 21h ago DLP Policy Violation Informational Investigating SRV-DC-01