Tor Exit Node Connection
Low
Escalated
ALR-00219 · 2026-05-24T19:12:38Z
Description
Connection from WS-LAP-011 to known Tor exit node detected by EmilyAI Triage. User 'e.evans' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:12:38
Event ingested by SOC365 Engine
19:12:43
EmilyAI triage started — correlation enrichment
19:12:44
EmilyAI confidence: 91% — escalated to human analyst
19:13:16
Alert assigned to analyst: EmilyAI (auto)
19:15:03
Investigation started — querying SIEM and threat intelligence
19:18:16
Containment action taken — endpoint isolated
19:26:47
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00020 | 2h ago | Failed MFA Challenge | Informational | False Positive | WS-LAP-011 |
| ALR-00019 | 2h ago | Tor Exit Node Connection | Medium | Open | FW-EDGE-01 |
| ALR-00352 | 4h ago | Anomalous DNS Query | Low | False Positive | WS-LAP-011 |
| ALR-00260 | 7h ago | Tor Exit Node Connection | Informational | Resolved | WS-LAP-011 |
| ALR-00283 | 12h ago | Malware Signature Match | Low | Resolved | WS-LAP-011 |