Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:26:11 UTC

Phishing Email Blocked

Informational Resolved
ALR-00388 · 2026-04-10T18:21:29Z

Description

Phishing email targeting 'c.williams@company.co.uk' blocked by SOC365 Engine. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00388
Timestamp
2026-04-10T18:21:29Z
Severity
Informational
Status
Resolved
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-WEB-01
User Account
c.williams
Source IP
185.99.220.118
Destination IP
10.0.96.135
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

18:21:29 Event ingested by SOC365 Engine
18:21:32 EmilyAI triage started — correlation enrichment
18:21:37 EmilyAI confidence: 94% — escalated to human analyst
18:22:03 Alert assigned to analyst: EmilyAI (auto)
18:22:26 Investigation started — querying SIEM and threat intelligence
18:27:50 Containment action taken — endpoint isolated
18:40:38 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00234 17h ago Port Scan Detected Medium Investigating SRV-WEB-01
ALR-00250 19h ago Shadow IT Discovery Informational Escalated SRV-WEB-01
ALR-00116 21h ago Credential Stuffing Attempt Medium Escalated SRV-WEB-01
ALR-00191 1d ago Phishing Email Blocked High Escalated VM-DEV-01
ALR-00352 2d ago Phishing Email Blocked Low Resolved SRV-BACKUP-01