Insider Threat Indicator
Informational
Escalated
ALR-00093 · 2026-05-27T09:06:01Z
Description
Anomalous after-hours access by 'j.smith' on WS-LAP-011. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by DLP Module.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:06:01
Event ingested by SOC365 Engine
09:06:02
EmilyAI triage started — correlation enrichment
09:06:08
EmilyAI confidence: 81% — escalated to human analyst
09:06:26
Alert assigned to analyst: EmilyAI (auto)
09:08:36
Investigation started — querying SIEM and threat intelligence
09:13:12
Containment action taken — endpoint isolated
09:16:51
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00449 | 1h ago | Insider Threat Indicator | Low | Open | WS-PC-004 |
| ALR-00114 | 9h ago | Insider Threat Indicator | Informational | Resolved | VM-DEV-01 |
| ALR-00261 | 13h ago | Rogue DHCP Server | High | Open | WS-LAP-011 |
| ALR-00201 | 16h ago | Insider Threat Indicator | Low | Investigating | WS-PC-006 |
| ALR-00223 | 1d ago | Suspicious PowerShell Execution | Medium | Resolved | WS-LAP-011 |