Data Exfiltration Attempt
Low
Resolved
ALR-00235 · 2026-04-10T10:16:33Z
Description
Large data transfer (2.3GB) to cloud storage from AP-WIFI-03 by user 'd.walker'. Cloud Connector DLP policy triggered — sensitive documents detected.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
10:16:33
Event ingested by SOC365 Engine
10:16:35
EmilyAI triage started — correlation enrichment
10:16:42
EmilyAI confidence: 85% — escalated to human analyst
10:16:59
Alert assigned to analyst: EmilyAI (auto)
10:18:36
Investigation started — querying SIEM and threat intelligence
10:21:44
Containment action taken — endpoint isolated
10:32:02
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00336 | 13h ago | DLP Policy Violation | Medium | Open | AP-WIFI-03 |
| ALR-00236 | 17h ago | Ransomware Behaviour Detected | Low | False Positive | AP-WIFI-03 |
| ALR-00373 | 1d ago | C2 Beacon Activity | Medium | Investigating | AP-WIFI-03 |
| ALR-00157 | 1d ago | Pass-the-Hash Detected | Informational | Open | AP-WIFI-03 |
| ALR-00296 | 1d ago | Data Exfiltration Attempt | Low | False Positive | WS-MAC-005 |