Shadow IT Discovery
Medium
Investigating
ALR-00170 · 2026-05-20T20:47:31Z
Description
EmilyAI Triage discovered unauthorised SaaS application (file sharing) used by 's.jones'. 14GB of company data synced to unapproved cloud storage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:47:31
Event ingested by SOC365 Engine
20:47:34
EmilyAI triage started — correlation enrichment
20:47:43
EmilyAI confidence: 94% — escalated to human analyst
20:48:12
Alert assigned to analyst: Sarah Chen
20:49:28
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00441 | 6h ago | Port Scan Detected | Low | False Positive | AP-WIFI-03 |
| ALR-00291 | 9h ago | Shadow IT Discovery | High | Open | WS-PC-001 |
| ALR-00379 | 12h ago | Insider Threat Indicator | High | Investigating | AP-WIFI-03 |
| ALR-00173 | 18h ago | Kerberoasting Attempt | High | Investigating | AP-WIFI-03 |
| ALR-00459 | 18h ago | Shadow IT Discovery | Informational | Resolved | WS-MAC-005 |