Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:08:56 UTC

Insider Threat Indicator

Low Open
ALR-00357 · 2026-05-24T03:18:20Z

Description

Anomalous after-hours access by 'l.johnson' on WS-PC-004. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by DecoyPulse.

Alert Metadata

Alert ID
ALR-00357
Timestamp
2026-05-24T03:18:20Z
Severity
Low
Status
Open
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-004
User Account
l.johnson
Source IP
91.234.195.154
Destination IP
10.1.66.189
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Collection
Technique
T1119
Reference
attack.mitre.org/techniques/T1119

Investigation Timeline

03:18:20 Event ingested by SOC365 Engine
03:18:22 EmilyAI triage started — correlation enrichment
03:18:25 EmilyAI confidence: 96% — escalated to human analyst
03:18:58 Alert assigned to analyst: EmilyAI (auto)
03:20:27 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00044 6h ago Insider Threat Indicator Informational Escalated WS-LAP-011
ALR-00282 17h ago Insider Threat Indicator Medium Escalated WS-MAC-005
ALR-00094 1d ago Insider Threat Indicator Medium Escalated SRV-WEB-01
ALR-00418 1d ago Port Scan Detected Critical Escalated WS-PC-004
ALR-00011 1d ago Insider Threat Indicator Medium False Positive WS-LAP-011