Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:19:11 UTC

Phishing Email Blocked

Medium Escalated
ALR-00317 · 2026-04-11T07:37:38Z

Description

Phishing email targeting 'n.clark@company.co.uk' blocked by Dark Web Monitor. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00317
Timestamp
2026-04-11T07:37:38Z
Severity
Medium
Status
Escalated
Detection Source
Dark Web Monitor
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
FW-EDGE-01
User Account
n.clark
Source IP
91.85.195.253
Destination IP
10.1.84.17
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

07:37:38 Event ingested by SOC365 Engine
07:37:42 EmilyAI triage started — correlation enrichment
07:37:48 EmilyAI confidence: 92% — escalated to human analyst
07:38:02 Alert assigned to analyst: Emma Richardson
07:38:29 Investigation started — querying SIEM and threat intelligence
07:46:23 Containment action taken — endpoint isolated
07:54:52 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00349 7h ago Credential Stuffing Attempt Medium Resolved FW-EDGE-01
ALR-00046 10h ago Phishing Email Blocked Informational Resolved WS-LAP-010
ALR-00417 11h ago Phishing Email Blocked Medium Open SRV-FILE-01
ALR-00461 14h ago Suspicious PowerShell Execution Informational Escalated FW-EDGE-01
ALR-00044 22h ago Phishing Email Blocked Medium Escalated WS-LAP-011