Tor Exit Node Connection
High
Investigating
ALR-00234 · 2026-05-27T04:38:29Z
Description
Connection from WS-PC-004 to known Tor exit node detected by DLP Module. User 'c.williams' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:38:29
Event ingested by SOC365 Engine
04:38:31
EmilyAI triage started — correlation enrichment
04:38:41
EmilyAI confidence: 94% — escalated to human analyst
04:39:11
Alert assigned to analyst: Marcus Webb
04:40:51
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00079 | 1h ago | Privilege Escalation Attempt | Informational | False Positive | WS-PC-004 |
| ALR-00203 | 10h ago | Tor Exit Node Connection | Informational | False Positive | WS-PC-001 |
| ALR-00345 | 12h ago | C2 Beacon Activity | Medium | Open | WS-PC-004 |
| ALR-00379 | 20h ago | Tor Exit Node Connection | Informational | False Positive | SW-CORE-01 |
| ALR-00111 | 22h ago | Tor Exit Node Connection | Informational | Resolved | WS-PC-002 |