Data Exfiltration Attempt
Medium
Open
ALR-00187 · 2026-05-26T01:47:48Z
Description
Large data transfer (2.3GB) to cloud storage from AP-WIFI-03 by user 'k.brown'. Firewall DLP policy triggered — sensitive documents detected.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:47:48
Event ingested by SOC365 Engine
01:47:49
EmilyAI triage started — correlation enrichment
01:47:56
EmilyAI confidence: 97% — escalated to human analyst
01:48:05
Alert assigned to analyst: Sarah Chen
01:50:28
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00167 | 3h ago | Suspicious PowerShell Execution | Medium | Open | AP-WIFI-03 |
| ALR-00015 | 3h ago | Unauthorised USB Device | Informational | False Positive | AP-WIFI-03 |
| ALR-00132 | 6h ago | Shadow IT Discovery | Low | Open | AP-WIFI-03 |
| ALR-00193 | 12h ago | Credential Stuffing Attempt | Low | Investigating | AP-WIFI-03 |
| ALR-00110 | 20h ago | Unauthorised USB Device | Low | Escalated | AP-WIFI-03 |