Unusual Outbound Traffic
Medium
Resolved
ALR-00157 · 2026-04-09T04:21:22Z
Description
Unusual outbound traffic pattern from WS-PC-002 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Cloud Connector.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:21:22
Event ingested by SOC365 Engine
04:21:27
EmilyAI triage started — correlation enrichment
04:21:34
EmilyAI confidence: 85% — escalated to human analyst
04:21:55
Alert assigned to analyst: Sarah Chen
04:22:18
Investigation started — querying SIEM and threat intelligence
04:25:33
Containment action taken — endpoint isolated
04:36:46
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00419 | 10m ago | Unusual Outbound Traffic | Low | Open | SRV-BACKUP-01 |
| ALR-00151 | 19m ago | Brute Force SSH | Informational | Open | WS-PC-002 |
| ALR-00460 | 1h ago | Malware Signature Match | Low | Escalated | WS-PC-002 |
| ALR-00066 | 3h ago | Unusual Outbound Traffic | Medium | False Positive | FW-EDGE-01 |
| ALR-00279 | 4h ago | Ransomware Behaviour Detected | Low | Investigating | WS-PC-002 |