Unusual Outbound Traffic
High
Investigating
ALR-00234 · 2026-04-12T01:15:47Z
Description
Unusual outbound traffic pattern from WS-PC-002 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by SOC365 Engine.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:15:47
Event ingested by SOC365 Engine
01:15:49
EmilyAI triage started — correlation enrichment
01:15:59
EmilyAI confidence: 88% — escalated to human analyst
01:16:10
Alert assigned to analyst: Marcus Webb
01:17:20
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00077 | 3h ago | C2 Beacon Activity | Medium | Open | WS-PC-002 |
| ALR-00328 | 4h ago | C2 Beacon Activity | Low | Investigating | WS-PC-002 |
| ALR-00329 | 6h ago | Unusual Outbound Traffic | Critical | Investigating | VM-DEV-01 |
| ALR-00451 | 6h ago | Unusual Outbound Traffic | High | Investigating | SRV-MAIL-01 |
| ALR-00108 | 6h ago | Unusual Outbound Traffic | Medium | Open | SRV-BACKUP-01 |