Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:59:18 UTC

Data Exfiltration Attempt

Medium Investigating
ALR-00104 · 2026-04-07T17:15:09Z

Description

Large data transfer (2.3GB) to cloud storage from WS-LAP-011 by user 'a.wilson'. DLP Module DLP policy triggered — sensitive documents detected.

Alert Metadata

Alert ID
ALR-00104
Timestamp
2026-04-07T17:15:09Z
Severity
Medium
Status
Investigating
Detection Source
DLP Module
Assigned Analyst
James Okonkwo

Endpoint Information

Hostname
WS-LAP-011
User Account
a.wilson
Source IP
45.15.148.61
Destination IP
10.3.178.64
Origin Country
IN India

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567.002
Reference
attack.mitre.org/techniques/T1567.002

Investigation Timeline

17:15:09 Event ingested by SOC365 Engine
17:15:14 EmilyAI triage started — correlation enrichment
17:15:18 EmilyAI confidence: 87% — escalated to human analyst
17:15:32 Alert assigned to analyst: James Okonkwo
17:17:28 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00101 6h ago Data Exfiltration Attempt Low False Positive SRV-DC-01
ALR-00197 9h ago Credential Stuffing Attempt Medium Escalated WS-LAP-011
ALR-00022 9h ago Data Exfiltration Attempt Medium Resolved AP-WIFI-03
ALR-00215 11h ago Malware Signature Match High Open WS-LAP-011
ALR-00218 17h ago DLP Policy Violation Informational Resolved WS-LAP-011