Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:10:15 UTC

Data Exfiltration Attempt

Low Open
ALR-00204 · 2026-05-24T14:15:26Z

Description

Large data transfer (2.3GB) to cloud storage from WS-PC-002 by user 'a.wilson'. SOC365 Engine DLP policy triggered — sensitive documents detected.

Alert Metadata

Alert ID
ALR-00204
Timestamp
2026-05-24T14:15:26Z
Severity
Low
Status
Open
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
a.wilson
Source IP
194.79.62.74
Destination IP
10.0.10.68
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567.002
Reference
attack.mitre.org/techniques/T1567.002

Investigation Timeline

14:15:26 Event ingested by SOC365 Engine
14:15:30 EmilyAI triage started — correlation enrichment
14:15:33 EmilyAI confidence: 97% — escalated to human analyst
14:15:48 Alert assigned to analyst: EmilyAI (auto)
14:18:18 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00147 2h ago Port Scan Detected Low Escalated WS-PC-002
ALR-00142 7h ago Ransomware Behaviour Detected Low Open WS-PC-002
ALR-00108 14h ago Lateral Movement Detected Informational Escalated WS-PC-002
ALR-00197 21h ago Data Exfiltration Attempt Informational Resolved AP-WIFI-03
ALR-00111 22h ago Tor Exit Node Connection Informational Resolved WS-PC-002