Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:05:35 UTC

DLP Policy Violation

Low Escalated
ALR-00136 · 2026-05-20T20:52:13Z

Description

DLP policy violation: user 'e.evans' attempted to email 3 files classified as 'Confidential' to external address from SRV-SQL-01.

Alert Metadata

Alert ID
ALR-00136
Timestamp
2026-05-20T20:52:13Z
Severity
Low
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-SQL-01
User Account
e.evans
Source IP
45.179.148.165
Destination IP
10.0.44.137
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

20:52:13 Event ingested by SOC365 Engine
20:52:16 EmilyAI triage started — correlation enrichment
20:52:22 EmilyAI confidence: 84% — escalated to human analyst
20:52:50 Alert assigned to analyst: EmilyAI (auto)
20:53:16 Investigation started — querying SIEM and threat intelligence
20:58:14 Containment action taken — endpoint isolated
21:06:06 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00443 4h ago DLP Policy Violation Low Open SRV-WEB-01
ALR-00028 6h ago Ransomware Behaviour Detected Low Investigating SRV-SQL-01
ALR-00018 9h ago Ransomware Behaviour Detected Informational Resolved SRV-SQL-01
ALR-00421 21h ago Unusual Outbound Traffic Critical Investigating SRV-SQL-01
ALR-00433 22h ago Brute Force SSH Medium False Positive SRV-SQL-01