Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:20:18 UTC

Unusual Outbound Traffic

Low Investigating
ALR-00330 · 2026-04-06T14:13:01Z

Description

Unusual outbound traffic pattern from WS-LAP-012 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by DecoyPulse.

Alert Metadata

Alert ID
ALR-00330
Timestamp
2026-04-06T14:13:01Z
Severity
Low
Status
Investigating
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-012
User Account
l.johnson
Source IP
45.31.148.169
Destination IP
10.0.172.16
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1041
Reference
attack.mitre.org/techniques/T1041

Investigation Timeline

14:13:01 Event ingested by SOC365 Engine
14:13:06 EmilyAI triage started — correlation enrichment
14:13:12 EmilyAI confidence: 98% — escalated to human analyst
14:13:36 Alert assigned to analyst: EmilyAI (auto)
14:14:23 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00143 12m ago Unusual Outbound Traffic Medium Investigating SRV-SQL-01
ALR-00368 3h ago Shadow IT Discovery Low Resolved WS-LAP-012
ALR-00023 4h ago Pass-the-Hash Detected Low Escalated WS-LAP-012
ALR-00302 5h ago Unusual Outbound Traffic Medium Resolved WS-MAC-005
ALR-00392 7h ago Unusual Outbound Traffic Low Resolved SRV-MAIL-01