Data Exfiltration Attempt
Medium
Investigating
ALR-00104 · 2026-04-07T17:15:09Z
Description
Large data transfer (2.3GB) to cloud storage from WS-LAP-011 by user 'a.wilson'. DLP Module DLP policy triggered — sensitive documents detected.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
17:15:09
Event ingested by SOC365 Engine
17:15:14
EmilyAI triage started — correlation enrichment
17:15:18
EmilyAI confidence: 87% — escalated to human analyst
17:15:32
Alert assigned to analyst: James Okonkwo
17:17:28
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00101 | 6h ago | Data Exfiltration Attempt | Low | False Positive | SRV-DC-01 |
| ALR-00197 | 9h ago | Credential Stuffing Attempt | Medium | Escalated | WS-LAP-011 |
| ALR-00022 | 9h ago | Data Exfiltration Attempt | Medium | Resolved | AP-WIFI-03 |
| ALR-00215 | 11h ago | Malware Signature Match | High | Open | WS-LAP-011 |
| ALR-00218 | 17h ago | DLP Policy Violation | Informational | Resolved | WS-LAP-011 |