Shadow IT Discovery
Medium
Open
ALR-00217 · 2026-05-26T11:31:31Z
Description
Attack Surface Scanner discovered unauthorised SaaS application (file sharing) used by 'f.hall'. 14GB of company data synced to unapproved cloud storage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:31:31
Event ingested by SOC365 Engine
11:31:34
EmilyAI triage started — correlation enrichment
11:31:44
EmilyAI confidence: 82% — escalated to human analyst
11:32:01
Alert assigned to analyst: Sarah Chen
11:32:34
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00037 | 3h ago | Suspicious Scheduled Task | Informational | False Positive | WS-MAC-005 |
| ALR-00187 | 4h ago | Lateral Movement Detected | Low | False Positive | WS-MAC-005 |
| ALR-00289 | 5h ago | Shadow IT Discovery | Low | Escalated | SRV-DC-01 |
| ALR-00438 | 15h ago | DecoyPulse Honeypot Triggered | Informational | Escalated | WS-MAC-005 |
| ALR-00285 | 15h ago | Shadow IT Discovery | High | Investigating | SRV-WEB-01 |