Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:03:34 UTC

DLP Policy Violation

High Open
ALR-00304 · 2026-05-21T01:14:40Z

Description

DLP policy violation: user 'c.williams' attempted to email 3 files classified as 'Confidential' to external address from SRV-FILE-01.

Alert Metadata

Alert ID
ALR-00304
Timestamp
2026-05-21T01:14:40Z
Severity
High
Status
Open
Detection Source
SOC365 Engine
Assigned Analyst
James Okonkwo

Endpoint Information

Hostname
SRV-FILE-01
User Account
c.williams
Source IP
194.158.62.6
Destination IP
10.0.76.28
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

01:14:40 Event ingested by SOC365 Engine
01:14:42 EmilyAI triage started — correlation enrichment
01:14:54 EmilyAI confidence: 79% — escalated to human analyst
01:15:04 Alert assigned to analyst: James Okonkwo
01:17:36 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00029 25m ago Brute Force SSH Low Escalated SRV-FILE-01
ALR-00414 14h ago DLP Policy Violation Informational Open WS-LAP-011
ALR-00068 15h ago DLP Policy Violation Medium Open SRV-DC-01
ALR-00126 17h ago DLP Policy Violation High Escalated WS-PC-002
ALR-00455 1d ago Shadow IT Discovery Informational Resolved SRV-FILE-01