Insider Threat Indicator
Medium
Investigating
ALR-00191 · 2026-05-25T11:36:15Z
Description
Anomalous after-hours access by 'r.davies' on FW-EDGE-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Network IDS.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:36:15
Event ingested by SOC365 Engine
11:36:16
EmilyAI triage started — correlation enrichment
11:36:20
EmilyAI confidence: 87% — escalated to human analyst
11:36:59
Alert assigned to analyst: Marcus Webb
11:38:19
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00018 | 1h ago | Insider Threat Indicator | Medium | False Positive | WS-PC-006 |
| ALR-00054 | 4h ago | DLP Policy Violation | Critical | Open | FW-EDGE-01 |
| ALR-00071 | 6h ago | Pass-the-Hash Detected | Informational | Investigating | FW-EDGE-01 |
| ALR-00170 | 8h ago | Anomalous DNS Query | Medium | Resolved | FW-EDGE-01 |
| ALR-00067 | 13h ago | Insider Threat Indicator | Low | Resolved | VM-DEV-01 |