Shadow IT Discovery
Informational
Resolved
ALR-00263 · 2026-04-09T19:17:03Z
Description
DLP Module discovered unauthorised SaaS application (file sharing) used by 'j.smith'. 14GB of company data synced to unapproved cloud storage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:17:03
Event ingested by SOC365 Engine
19:17:08
EmilyAI triage started — correlation enrichment
19:17:15
EmilyAI confidence: 86% — escalated to human analyst
19:17:48
Alert assigned to analyst: EmilyAI (auto)
19:18:45
Investigation started — querying SIEM and threat intelligence
19:22:51
Containment action taken — endpoint isolated
19:35:22
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00489 | 5h ago | Shadow IT Discovery | Low | Investigating | SRV-SQL-01 |
| ALR-00090 | 5h ago | Pass-the-Hash Detected | Medium | False Positive | VM-DEV-01 |
| ALR-00254 | 13h ago | Credential Stuffing Attempt | Informational | False Positive | VM-DEV-01 |
| ALR-00408 | 17h ago | Shadow IT Discovery | Low | Escalated | SRV-MAIL-01 |
| ALR-00288 | 18h ago | Certificate Anomaly | Informational | Resolved | VM-DEV-01 |