Malware Signature Match
Informational
False Positive
ALR-00406 · 2026-04-09T09:50:49Z
Description
Known malware signature (Emotet variant) detected in file on SRV-FILE-01. SOC365 Engine quarantined the file. User context: h.roberts.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:50:49
Event ingested by SOC365 Engine
09:50:51
EmilyAI triage started — correlation enrichment
09:51:02
EmilyAI confidence: 81% — escalated to human analyst
09:51:24
Alert assigned to analyst: EmilyAI (auto)
09:52:53
Investigation started — querying SIEM and threat intelligence
09:59:17
Containment action taken — endpoint isolated
10:02:22
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00275 | 3h ago | Unauthorised USB Device | Medium | Investigating | SRV-FILE-01 |
| ALR-00222 | 7h ago | Malware Signature Match | Low | Investigating | SRV-FILE-01 |
| ALR-00237 | 9h ago | Unusual Outbound Traffic | Medium | Investigating | SRV-FILE-01 |
| ALR-00264 | 18h ago | Malware Signature Match | Informational | Resolved | SRV-BACKUP-01 |
| ALR-00466 | 20h ago | Privilege Escalation Attempt | Informational | Open | SRV-FILE-01 |