Insider Threat Indicator
Informational
Open
ALR-00105 · 2026-04-08T20:17:03Z
Description
Anomalous after-hours access by 'm.taylor' on WS-PC-001. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by DLP Module.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:17:03
Event ingested by SOC365 Engine
20:17:08
EmilyAI triage started — correlation enrichment
20:17:09
EmilyAI confidence: 98% — escalated to human analyst
20:17:30
Alert assigned to analyst: EmilyAI (auto)
20:19:47
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00190 | 3h ago | Credential Stuffing Attempt | Low | Investigating | WS-PC-001 |
| ALR-00141 | 3h ago | Unauthorised USB Device | Informational | Resolved | WS-PC-001 |
| ALR-00174 | 4h ago | Failed MFA Challenge | Informational | Escalated | WS-PC-001 |
| ALR-00219 | 8h ago | Privilege Escalation Attempt | Low | False Positive | WS-PC-001 |
| ALR-00279 | 10h ago | Credential Stuffing Attempt | Medium | Escalated | WS-PC-001 |