Phishing Email Blocked
Low
Investigating
ALR-00364 · 2026-04-10T06:52:36Z
Description
Phishing email targeting 'l.johnson@company.co.uk' blocked by SOC365 Engine. Payload: credential harvesting link mimicking Microsoft 365 login.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
06:52:36
Event ingested by SOC365 Engine
06:52:38
EmilyAI triage started — correlation enrichment
06:52:45
EmilyAI confidence: 79% — escalated to human analyst
06:53:04
Alert assigned to analyst: EmilyAI (auto)
06:55:21
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00489 | 16m ago | Tor Exit Node Connection | Medium | Open | WS-PC-004 |
| ALR-00060 | 41m ago | Shadow IT Discovery | Low | Investigating | WS-PC-004 |
| ALR-00455 | 5h ago | Privilege Escalation Attempt | Informational | Escalated | WS-PC-004 |
| ALR-00310 | 1d ago | Phishing Email Blocked | Critical | Investigating | WS-PC-006 |
| ALR-00008 | 1d ago | Phishing Email Blocked | Low | Open | SRV-APP-01 |