DLP Policy Violation
Medium
False Positive
ALR-00184 · 2026-05-25T17:10:41Z
Description
DLP policy violation: user 'f.hall' attempted to email 3 files classified as 'Confidential' to external address from WS-PC-004.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
17:10:41
Event ingested by SOC365 Engine
17:10:44
EmilyAI triage started — correlation enrichment
17:10:48
EmilyAI confidence: 85% — escalated to human analyst
17:11:22
Alert assigned to analyst: Marcus Webb
17:12:20
Investigation started — querying SIEM and threat intelligence
17:16:49
Containment action taken — endpoint isolated
17:28:48
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00284 | 2h ago | Tor Exit Node Connection | Informational | Investigating | WS-PC-004 |
| ALR-00236 | 13h ago | Data Exfiltration Attempt | Low | Resolved | WS-PC-004 |
| ALR-00024 | 19h ago | DLP Policy Violation | Medium | Escalated | WS-PC-006 |
| ALR-00248 | 19h ago | Phishing Email Blocked | Informational | Resolved | WS-PC-004 |
| ALR-00441 | 23h ago | DLP Policy Violation | Critical | Open | VM-DEV-01 |