Tor Exit Node Connection
Low
Resolved
ALR-00074 · 2026-04-11T00:29:29Z
Description
Connection from WS-LAP-010 to known Tor exit node detected by Firewall. User 'l.johnson' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
00:29:29
Event ingested by SOC365 Engine
00:29:31
EmilyAI triage started — correlation enrichment
00:29:37
EmilyAI confidence: 82% — escalated to human analyst
00:29:44
Alert assigned to analyst: EmilyAI (auto)
00:31:24
Investigation started — querying SIEM and threat intelligence
00:34:11
Containment action taken — endpoint isolated
00:46:06
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00464 | 5h ago | Brute Force SSH | Medium | Investigating | WS-LAP-010 |
| ALR-00088 | 14h ago | Certificate Anomaly | Medium | False Positive | WS-LAP-010 |
| ALR-00013 | 17h ago | Anomalous DNS Query | Informational | False Positive | WS-LAP-010 |
| ALR-00289 | 17h ago | Tor Exit Node Connection | Medium | Resolved | SRV-APP-01 |
| ALR-00222 | 18h ago | Suspicious PowerShell Execution | High | Open | WS-LAP-010 |