Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:07:30 UTC

DLP Policy Violation

Informational Investigating
ALR-00199 · 2026-05-22T08:15:48Z

Description

DLP policy violation: user 'system' attempted to email 3 files classified as 'Confidential' to external address from WS-PC-001.

Alert Metadata

Alert ID
ALR-00199
Timestamp
2026-05-22T08:15:48Z
Severity
Informational
Status
Investigating
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-001
User Account
system
Source IP
185.135.220.145
Destination IP
10.1.151.4
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

08:15:48 Event ingested by SOC365 Engine
08:15:53 EmilyAI triage started — correlation enrichment
08:15:55 EmilyAI confidence: 82% — escalated to human analyst
08:16:19 Alert assigned to analyst: EmilyAI (auto)
08:18:29 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00339 38m ago Suspicious PowerShell Execution Low Investigating WS-PC-001
ALR-00101 8h ago DLP Policy Violation Informational Investigating WS-MAC-005
ALR-00132 8h ago Anomalous DNS Query Low Resolved WS-PC-001
ALR-00067 17h ago Privilege Escalation Attempt Low Escalated WS-PC-001
ALR-00443 19h ago Shadow IT Discovery Informational Resolved WS-PC-001