Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:55:56 UTC

Unusual Outbound Traffic

Informational Escalated
ALR-00094 · 2026-04-08T10:23:11Z

Description

Unusual outbound traffic pattern from WS-LAP-011 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Dark Web Monitor.

Alert Metadata

Alert ID
ALR-00094
Timestamp
2026-04-08T10:23:11Z
Severity
Informational
Status
Escalated
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-011
User Account
j.smith
Source IP
91.213.195.214
Destination IP
10.0.115.15
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1041
Reference
attack.mitre.org/techniques/T1041

Investigation Timeline

10:23:11 Event ingested by SOC365 Engine
10:23:13 EmilyAI triage started — correlation enrichment
10:23:17 EmilyAI confidence: 86% — escalated to human analyst
10:23:29 Alert assigned to analyst: EmilyAI (auto)
10:24:51 Investigation started — querying SIEM and threat intelligence
10:26:18 Containment action taken — endpoint isolated
10:42:07 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00125 57m ago Credential Stuffing Attempt Low Investigating WS-LAP-011
ALR-00206 5h ago Unusual Outbound Traffic Informational False Positive WS-LAP-012
ALR-00173 6h ago Kerberoasting Attempt Low Investigating WS-LAP-011
ALR-00163 10h ago Suspicious Scheduled Task Low Resolved WS-LAP-011
ALR-00264 11h ago Port Scan Detected Critical Investigating WS-LAP-011