Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:02:52 UTC

Phishing Email Blocked

Informational Open
ALR-00339 · 2026-05-23T23:50:27Z

Description

Phishing email targeting 'r.davies@company.co.uk' blocked by Dark Web Monitor. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00339
Timestamp
2026-05-23T23:50:27Z
Severity
Informational
Status
Open
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-WEB-01
User Account
r.davies
Source IP
185.232.220.129
Destination IP
10.3.128.54
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

23:50:27 Event ingested by SOC365 Engine
23:50:31 EmilyAI triage started — correlation enrichment
23:50:38 EmilyAI confidence: 90% — escalated to human analyst
23:51:03 Alert assigned to analyst: EmilyAI (auto)
23:52:02 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00406 11h ago Unusual Outbound Traffic Low False Positive SRV-WEB-01
ALR-00274 11h ago Suspicious PowerShell Execution Informational False Positive SRV-WEB-01
ALR-00200 14h ago Privilege Escalation Attempt Low Escalated SRV-WEB-01
ALR-00014 23h ago Phishing Email Blocked Medium Investigating WS-LAP-012
ALR-00234 23h ago Phishing Email Blocked Low Resolved WS-LAP-011