Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:51:44 UTC

Shadow IT Discovery

Informational False Positive
ALR-00340 · 2026-04-11T12:22:04Z

Description

Dark Web Monitor discovered unauthorised SaaS application (file sharing) used by 'd.walker'. 14GB of company data synced to unapproved cloud storage.

Alert Metadata

Alert ID
ALR-00340
Timestamp
2026-04-11T12:22:04Z
Severity
Informational
Status
False Positive
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
d.walker
Source IP
194.208.62.124
Destination IP
10.3.140.41
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567
Reference
attack.mitre.org/techniques/T1567

Investigation Timeline

12:22:04 Event ingested by SOC365 Engine
12:22:09 EmilyAI triage started — correlation enrichment
12:22:18 EmilyAI confidence: 78% — escalated to human analyst
12:22:39 Alert assigned to analyst: EmilyAI (auto)
12:22:56 Investigation started — querying SIEM and threat intelligence
12:26:40 Containment action taken — endpoint isolated
12:38:59 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00232 5h ago Failed MFA Challenge Low Investigating SW-CORE-01
ALR-00271 9h ago Shadow IT Discovery Medium False Positive SRV-DC-01
ALR-00255 10h ago Failed MFA Challenge Low Open SW-CORE-01
ALR-00372 16h ago Shadow IT Discovery Low Resolved SRV-BACKUP-01
ALR-00470 16h ago Shadow IT Discovery Low Escalated SRV-APP-01