Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 21:06:03 UTC

Phishing Email Blocked

Low False Positive
ALR-00192 · 2026-05-25T00:26:31Z

Description

Phishing email targeting 'p.thomas@company.co.uk' blocked by SOC365 Engine. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00192
Timestamp
2026-05-25T00:26:31Z
Severity
Low
Status
False Positive
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-SQL-01
User Account
p.thomas
Source IP
185.100.220.207
Destination IP
10.0.190.250
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

00:26:31 Event ingested by SOC365 Engine
00:26:36 EmilyAI triage started — correlation enrichment
00:26:45 EmilyAI confidence: 96% — escalated to human analyst
00:27:05 Alert assigned to analyst: EmilyAI (auto)
00:29:18 Investigation started — querying SIEM and threat intelligence
00:29:57 Containment action taken — endpoint isolated
00:44:57 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00474 2h ago Tor Exit Node Connection Low Open SRV-SQL-01
ALR-00153 7h ago Phishing Email Blocked Low False Positive SRV-WEB-01
ALR-00484 8h ago Phishing Email Blocked Medium False Positive SRV-SQL-01
ALR-00223 10h ago Lateral Movement Detected High Investigating SRV-SQL-01
ALR-00003 11h ago Phishing Email Blocked Low Resolved WS-LAP-011