Malware Signature Match
Medium
False Positive
ALR-00259 · 2026-04-09T06:46:44Z
Description
Known malware signature (Emotet variant) detected in file on SRV-SQL-01. SOC365 Engine quarantined the file. User context: c.williams.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
06:46:44
Event ingested by SOC365 Engine
06:46:48
EmilyAI triage started — correlation enrichment
06:46:53
EmilyAI confidence: 84% — escalated to human analyst
06:47:10
Alert assigned to analyst: James Okonkwo
06:47:39
Investigation started — querying SIEM and threat intelligence
06:52:00
Containment action taken — endpoint isolated
06:59:58
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00391 | 9m ago | Malware Signature Match | Low | Investigating | WS-PC-003 |
| ALR-00079 | 14h ago | Brute Force SSH | Low | Resolved | SRV-SQL-01 |
| ALR-00487 | 14h ago | Unusual Outbound Traffic | Informational | Escalated | SRV-SQL-01 |
| ALR-00174 | 22h ago | Port Scan Detected | Medium | Open | SRV-SQL-01 |
| ALR-00401 | 1d ago | Malware Signature Match | Medium | False Positive | WS-PC-002 |