DLP Policy Violation
High
Open
ALR-00304 · 2026-05-21T01:14:40Z
Description
DLP policy violation: user 'c.williams' attempted to email 3 files classified as 'Confidential' to external address from SRV-FILE-01.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:14:40
Event ingested by SOC365 Engine
01:14:42
EmilyAI triage started — correlation enrichment
01:14:54
EmilyAI confidence: 79% — escalated to human analyst
01:15:04
Alert assigned to analyst: James Okonkwo
01:17:36
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00029 | 25m ago | Brute Force SSH | Low | Escalated | SRV-FILE-01 |
| ALR-00414 | 14h ago | DLP Policy Violation | Informational | Open | WS-LAP-011 |
| ALR-00068 | 15h ago | DLP Policy Violation | Medium | Open | SRV-DC-01 |
| ALR-00126 | 17h ago | DLP Policy Violation | High | Escalated | WS-PC-002 |
| ALR-00455 | 1d ago | Shadow IT Discovery | Informational | Resolved | SRV-FILE-01 |