Ransomware Behaviour Detected
High
Investigating
ALR-00261 · 2026-05-21T15:54:12Z
Description
File encryption behaviour detected on AP-WIFI-03. 142 files renamed with .locked extension in 30 seconds. Email Gateway isolated endpoint.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
15:54:12
Event ingested by SOC365 Engine
15:54:15
EmilyAI triage started — correlation enrichment
15:54:18
EmilyAI confidence: 92% — escalated to human analyst
15:54:46
Alert assigned to analyst: Anika Patel
15:56:46
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00288 | 12h ago | Suspicious PowerShell Execution | Low | Open | AP-WIFI-03 |
| ALR-00383 | 14h ago | C2 Beacon Activity | High | Open | AP-WIFI-03 |
| ALR-00473 | 15h ago | Tor Exit Node Connection | High | Escalated | AP-WIFI-03 |
| ALR-00404 | 19h ago | C2 Beacon Activity | Low | Investigating | AP-WIFI-03 |
| ALR-00425 | 19h ago | DLP Policy Violation | Medium | Investigating | AP-WIFI-03 |