Phishing Email Blocked
Critical
Open
ALR-00140 · 2026-04-12T11:42:36Z
Description
Phishing email targeting 'a.wilson@company.co.uk' blocked by Endpoint Agent. Payload: credential harvesting link mimicking Microsoft 365 login.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:42:36
Event ingested by SOC365 Engine
11:42:38
EmilyAI triage started — correlation enrichment
11:42:48
EmilyAI confidence: 96% — escalated to human analyst
11:43:19
Alert assigned to analyst: Sarah Chen
11:44:10
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00212 | 5h ago | Kerberoasting Attempt | Low | False Positive | WS-PC-002 |
| ALR-00299 | 10h ago | Ransomware Behaviour Detected | Low | Investigating | WS-PC-002 |
| ALR-00110 | 11h ago | Shadow IT Discovery | Low | Investigating | WS-PC-002 |
| ALR-00093 | 11h ago | Unusual Outbound Traffic | High | Open | WS-PC-002 |
| ALR-00462 | 16h ago | Phishing Email Blocked | Medium | False Positive | WS-LAP-011 |