Insider Threat Indicator
Medium
Escalated
ALR-00344 · 2026-05-25T03:29:42Z
Description
Anomalous after-hours access by 'm.taylor' on WS-LAP-010. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Endpoint Agent.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
03:29:42
Event ingested by SOC365 Engine
03:29:47
EmilyAI triage started — correlation enrichment
03:29:57
EmilyAI confidence: 82% — escalated to human analyst
03:30:23
Alert assigned to analyst: Sarah Chen
03:31:26
Investigation started — querying SIEM and threat intelligence
03:33:07
Containment action taken — endpoint isolated
03:48:57
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00102 | 15m ago | Credential Stuffing Attempt | Low | Resolved | WS-LAP-010 |
| ALR-00165 | 6h ago | Anomalous DNS Query | Medium | Resolved | WS-LAP-010 |
| ALR-00187 | 8h ago | Phishing Email Blocked | Medium | Open | WS-LAP-010 |
| ALR-00341 | 12h ago | Failed MFA Challenge | Informational | Investigating | WS-LAP-010 |
| ALR-00225 | 13h ago | DLP Policy Violation | Medium | Open | WS-LAP-010 |