Unusual Outbound Traffic
Low
Investigating
ALR-00330 · 2026-04-06T14:13:01Z
Description
Unusual outbound traffic pattern from WS-LAP-012 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by DecoyPulse.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
14:13:01
Event ingested by SOC365 Engine
14:13:06
EmilyAI triage started — correlation enrichment
14:13:12
EmilyAI confidence: 98% — escalated to human analyst
14:13:36
Alert assigned to analyst: EmilyAI (auto)
14:14:23
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00143 | 12m ago | Unusual Outbound Traffic | Medium | Investigating | SRV-SQL-01 |
| ALR-00368 | 3h ago | Shadow IT Discovery | Low | Resolved | WS-LAP-012 |
| ALR-00023 | 4h ago | Pass-the-Hash Detected | Low | Escalated | WS-LAP-012 |
| ALR-00302 | 5h ago | Unusual Outbound Traffic | Medium | Resolved | WS-MAC-005 |
| ALR-00392 | 7h ago | Unusual Outbound Traffic | Low | Resolved | SRV-MAIL-01 |