Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 16:53:14 UTC

DLP Policy Violation

Medium Open
ALR-00348 · 2026-04-12T03:15:24Z

Description

DLP policy violation: user 'k.brown' attempted to email 3 files classified as 'Confidential' to external address from SRV-BACKUP-01.

Alert Metadata

Alert ID
ALR-00348
Timestamp
2026-04-12T03:15:24Z
Severity
Medium
Status
Open
Detection Source
Attack Surface Scanner
Assigned Analyst
James Okonkwo

Endpoint Information

Hostname
SRV-BACKUP-01
User Account
k.brown
Source IP
45.119.148.131
Destination IP
10.3.247.242
Origin Country
RO Romania

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

03:15:24 Event ingested by SOC365 Engine
03:15:25 EmilyAI triage started — correlation enrichment
03:15:37 EmilyAI confidence: 89% — escalated to human analyst
03:15:53 Alert assigned to analyst: James Okonkwo
03:16:40 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00248 9h ago DLP Policy Violation Low Escalated SRV-APP-01
ALR-00197 10h ago Pass-the-Hash Detected Low Investigating SRV-BACKUP-01
ALR-00181 13h ago DLP Policy Violation Medium False Positive WS-PC-002
ALR-00399 14h ago Ransomware Behaviour Detected Low False Positive SRV-BACKUP-01
ALR-00221 1d ago DLP Policy Violation Low False Positive SRV-DC-01