Phishing Email Blocked
Low
Open
ALR-00135 · 2026-04-09T21:43:47Z
Description
Phishing email targeting 'm.taylor@company.co.uk' blocked by DecoyPulse. Payload: credential harvesting link mimicking Microsoft 365 login.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:43:47
Event ingested by SOC365 Engine
21:43:51
EmilyAI triage started — correlation enrichment
21:44:00
EmilyAI confidence: 87% — escalated to human analyst
21:44:25
Alert assigned to analyst: EmilyAI (auto)
21:45:17
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00358 | 4h ago | Phishing Email Blocked | Low | Resolved | WS-LAP-012 |
| ALR-00205 | 7h ago | Privilege Escalation Attempt | High | Open | SRV-DC-01 |
| ALR-00292 | 11h ago | Rogue DHCP Server | Medium | False Positive | SRV-DC-01 |
| ALR-00209 | 18h ago | DLP Policy Violation | Informational | False Positive | SRV-DC-01 |
| ALR-00353 | 19h ago | Anomalous DNS Query | Low | Open | SRV-DC-01 |