Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:11:15 UTC

Unusual Outbound Traffic

High Investigating
ALR-00371 · 2026-04-11T11:24:24Z

Description

Unusual outbound traffic pattern from SRV-APP-01 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Endpoint Agent.

Alert Metadata

Alert ID
ALR-00371
Timestamp
2026-04-11T11:24:24Z
Severity
High
Status
Investigating
Detection Source
Endpoint Agent
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
SRV-APP-01
User Account
f.hall
Source IP
103.33.216.188
Destination IP
10.3.214.75
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1041
Reference
attack.mitre.org/techniques/T1041

Investigation Timeline

11:24:24 Event ingested by SOC365 Engine
11:24:25 EmilyAI triage started — correlation enrichment
11:24:32 EmilyAI confidence: 89% — escalated to human analyst
11:24:58 Alert assigned to analyst: Sarah Chen
11:26:31 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00367 6m ago Suspicious Scheduled Task Low False Positive SRV-APP-01
ALR-00479 6h ago Credential Stuffing Attempt Medium Resolved SRV-APP-01
ALR-00118 7h ago Unusual Outbound Traffic Low Investigating SRV-FILE-01
ALR-00495 10h ago Pass-the-Hash Detected High Open SRV-APP-01
ALR-00031 12h ago Malware Signature Match Low Escalated SRV-APP-01