Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:02:52 UTC

Data Exfiltration Attempt

Medium False Positive
ALR-00211 · 2026-05-26T03:42:46Z

Description

Large data transfer (2.3GB) to cloud storage from SRV-BACKUP-01 by user 'r.davies'. Cloud Connector DLP policy triggered — sensitive documents detected.

Alert Metadata

Alert ID
ALR-00211
Timestamp
2026-05-26T03:42:46Z
Severity
Medium
Status
False Positive
Detection Source
Cloud Connector
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
SRV-BACKUP-01
User Account
r.davies
Source IP
91.93.195.220
Destination IP
10.2.156.55
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567.002
Reference
attack.mitre.org/techniques/T1567.002

Investigation Timeline

03:42:46 Event ingested by SOC365 Engine
03:42:48 EmilyAI triage started — correlation enrichment
03:42:58 EmilyAI confidence: 97% — escalated to human analyst
03:43:06 Alert assigned to analyst: Anika Patel
03:45:41 Investigation started — querying SIEM and threat intelligence
03:49:50 Containment action taken — endpoint isolated
04:01:32 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00086 1h ago Ransomware Behaviour Detected Informational False Positive SRV-BACKUP-01
ALR-00030 5h ago Data Exfiltration Attempt Low Resolved SRV-DC-01
ALR-00210 6h ago Lateral Movement Detected Low Open SRV-BACKUP-01
ALR-00309 6h ago Unauthorised USB Device High Escalated SRV-BACKUP-01
ALR-00196 14h ago Pass-the-Hash Detected Informational Resolved SRV-BACKUP-01