Data Exfiltration Attempt
Informational
Investigating
ALR-00118 · 2026-04-08T23:29:20Z
Description
Large data transfer (2.3GB) to cloud storage from WS-LAP-011 by user 'a.wilson'. EmilyAI Triage DLP policy triggered — sensitive documents detected.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:29:20
Event ingested by SOC365 Engine
23:29:23
EmilyAI triage started — correlation enrichment
23:29:32
EmilyAI confidence: 90% — escalated to human analyst
23:29:50
Alert assigned to analyst: EmilyAI (auto)
23:30:13
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00046 | 1h ago | Anomalous DNS Query | Medium | Investigating | WS-LAP-011 |
| ALR-00315 | 2h ago | Suspicious Scheduled Task | Low | Resolved | WS-LAP-011 |
| ALR-00035 | 3h ago | Data Exfiltration Attempt | Informational | Escalated | SRV-APP-01 |
| ALR-00184 | 5h ago | Data Exfiltration Attempt | Medium | Escalated | WS-LAP-010 |
| ALR-00243 | 6h ago | Port Scan Detected | Medium | Resolved | WS-LAP-011 |