Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:50:54 UTC

Insider Threat Indicator

Informational False Positive
ALR-00393 · 2026-04-08T06:06:27Z

Description

Anomalous after-hours access by 'd.walker' on VM-DEV-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by EmilyAI Triage.

Alert Metadata

Alert ID
ALR-00393
Timestamp
2026-04-08T06:06:27Z
Severity
Informational
Status
False Positive
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
VM-DEV-01
User Account
d.walker
Source IP
91.206.195.106
Destination IP
10.0.146.86
Origin Country
RO Romania

MITRE ATT&CK Mapping

Tactic
Collection
Technique
T1119
Reference
attack.mitre.org/techniques/T1119

Investigation Timeline

06:06:27 Event ingested by SOC365 Engine
06:06:28 EmilyAI triage started — correlation enrichment
06:06:36 EmilyAI confidence: 98% — escalated to human analyst
06:06:49 Alert assigned to analyst: EmilyAI (auto)
06:07:33 Investigation started — querying SIEM and threat intelligence
06:11:29 Containment action taken — endpoint isolated
06:26:25 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00126 27m ago Data Exfiltration Attempt High Open VM-DEV-01
ALR-00069 2h ago Insider Threat Indicator Medium Open WS-LAP-011
ALR-00222 2h ago Credential Stuffing Attempt Low Resolved VM-DEV-01
ALR-00112 5h ago Port Scan Detected Medium False Positive VM-DEV-01
ALR-00306 11h ago Insider Threat Indicator Low Investigating SW-CORE-01