DLP Policy Violation
High
Open
ALR-00389 · 2026-05-20T23:45:44Z
Description
DLP policy violation: user 'l.johnson' attempted to email 3 files classified as 'Confidential' to external address from FW-EDGE-01.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:45:44
Event ingested by SOC365 Engine
23:45:49
EmilyAI triage started — correlation enrichment
23:45:53
EmilyAI confidence: 95% — escalated to human analyst
23:46:05
Alert assigned to analyst: Emma Richardson
23:47:57
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00222 | 8h ago | Pass-the-Hash Detected | High | Open | FW-EDGE-01 |
| ALR-00073 | 17h ago | Lateral Movement Detected | Informational | Resolved | FW-EDGE-01 |
| ALR-00274 | 18h ago | Certificate Anomaly | Informational | Resolved | FW-EDGE-01 |
| ALR-00024 | 19h ago | DLP Policy Violation | Medium | Escalated | WS-PC-006 |
| ALR-00014 | 19h ago | Credential Stuffing Attempt | Medium | Investigating | FW-EDGE-01 |