Unusual Outbound Traffic
Informational
Open
ALR-00392 · 2026-04-09T06:45:17Z
Description
Unusual outbound traffic pattern from FW-EDGE-01 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Firewall.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
06:45:17
Event ingested by SOC365 Engine
06:45:22
EmilyAI triage started — correlation enrichment
06:45:26
EmilyAI confidence: 84% — escalated to human analyst
06:45:47
Alert assigned to analyst: EmilyAI (auto)
06:48:06
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00487 | 7h ago | Unusual Outbound Traffic | Low | Investigating | WS-PC-001 |
| ALR-00237 | 9h ago | Unusual Outbound Traffic | Medium | Investigating | SRV-FILE-01 |
| ALR-00047 | 13h ago | Unusual Outbound Traffic | High | Open | WS-PC-006 |
| ALR-00177 | 23h ago | Ransomware Behaviour Detected | Informational | False Positive | FW-EDGE-01 |
| ALR-00433 | 1d ago | Suspicious PowerShell Execution | Low | Escalated | FW-EDGE-01 |