Tor Exit Node Connection
Low
Investigating
ALR-00392 · 2026-05-23T16:49:46Z
Description
Connection from SW-CORE-01 to known Tor exit node detected by Cloud Connector. User 'j.smith' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:49:46
Event ingested by SOC365 Engine
16:49:47
EmilyAI triage started — correlation enrichment
16:49:57
EmilyAI confidence: 89% — escalated to human analyst
16:50:09
Alert assigned to analyst: EmilyAI (auto)
16:51:30
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00004 | 1h ago | Anomalous DNS Query | Low | False Positive | SW-CORE-01 |
| ALR-00029 | 4h ago | Tor Exit Node Connection | Informational | Resolved | FW-EDGE-01 |
| ALR-00477 | 9h ago | Tor Exit Node Connection | Low | Open | WS-LAP-012 |
| ALR-00364 | 10h ago | Data Exfiltration Attempt | Low | Open | SW-CORE-01 |
| ALR-00337 | 11h ago | Certificate Anomaly | High | Investigating | SW-CORE-01 |