DLP Policy Violation
Informational
Resolved
ALR-00291 · 2026-04-10T08:13:03Z
Description
DLP policy violation: user 'k.brown' attempted to email 3 files classified as 'Confidential' to external address from WS-PC-001.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
08:13:03
Event ingested by SOC365 Engine
08:13:04
EmilyAI triage started — correlation enrichment
08:13:11
EmilyAI confidence: 84% — escalated to human analyst
08:13:36
Alert assigned to analyst: EmilyAI (auto)
08:15:40
Investigation started — querying SIEM and threat intelligence
08:16:40
Containment action taken — endpoint isolated
08:29:36
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00112 | 3h ago | DLP Policy Violation | High | Escalated | WS-MAC-005 |
| ALR-00487 | 5h ago | DecoyPulse Honeypot Triggered | Informational | Resolved | WS-PC-001 |
| ALR-00233 | 12h ago | Lateral Movement Detected | Informational | False Positive | WS-PC-001 |
| ALR-00263 | 14h ago | Lateral Movement Detected | Medium | Investigating | WS-PC-001 |
| ALR-00060 | 16h ago | Phishing Email Blocked | Medium | False Positive | WS-PC-001 |