Unusual Outbound Traffic
Informational
Escalated
ALR-00346 · 2026-05-27T08:20:55Z
Description
Unusual outbound traffic pattern from AP-WIFI-03 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Firewall.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
08:20:55
Event ingested by SOC365 Engine
08:20:56
EmilyAI triage started — correlation enrichment
08:21:00
EmilyAI confidence: 78% — escalated to human analyst
08:21:24
Alert assigned to analyst: EmilyAI (auto)
08:21:42
Investigation started — querying SIEM and threat intelligence
08:27:08
Containment action taken — endpoint isolated
08:32:28
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00287 | 1h ago | Brute Force SSH | Low | Resolved | AP-WIFI-03 |
| ALR-00227 | 9h ago | Port Scan Detected | Medium | Open | AP-WIFI-03 |
| ALR-00267 | 9h ago | Unusual Outbound Traffic | High | Open | WS-PC-004 |
| ALR-00459 | 10h ago | Unusual Outbound Traffic | Medium | Resolved | SRV-FILE-01 |
| ALR-00262 | 12h ago | Tor Exit Node Connection | Low | Escalated | AP-WIFI-03 |