Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:09:54 UTC

Unusual Outbound Traffic

Informational Resolved
ALR-00165 · 2026-05-27T04:57:17Z

Description

Unusual outbound traffic pattern from WS-PC-003 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by DLP Module.

Alert Metadata

Alert ID
ALR-00165
Timestamp
2026-05-27T04:57:17Z
Severity
Informational
Status
Resolved
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-003
User Account
m.taylor
Source IP
194.97.62.60
Destination IP
10.3.4.96
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1041
Reference
attack.mitre.org/techniques/T1041

Investigation Timeline

04:57:17 Event ingested by SOC365 Engine
04:57:22 EmilyAI triage started — correlation enrichment
04:57:28 EmilyAI confidence: 85% — escalated to human analyst
04:57:48 Alert assigned to analyst: EmilyAI (auto)
04:58:09 Investigation started — querying SIEM and threat intelligence
05:04:26 Containment action taken — endpoint isolated
05:13:41 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00365 56m ago Ransomware Behaviour Detected Informational Investigating WS-PC-003
ALR-00274 14h ago Certificate Anomaly Low Open WS-PC-003
ALR-00140 15h ago Phishing Email Blocked Informational Open WS-PC-003
ALR-00289 21h ago Unusual Outbound Traffic Low False Positive WS-LAP-011
ALR-00149 1d ago Unusual Outbound Traffic High Escalated SRV-DC-01