Tor Exit Node Connection
Informational
Escalated
ALR-00408 · 2026-04-12T09:01:38Z
Description
Connection from WS-PC-003 to known Tor exit node detected by Attack Surface Scanner. User 'd.walker' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:01:38
Event ingested by SOC365 Engine
09:01:43
EmilyAI triage started — correlation enrichment
09:01:49
EmilyAI confidence: 90% — escalated to human analyst
09:02:15
Alert assigned to analyst: EmilyAI (auto)
09:03:36
Investigation started — querying SIEM and threat intelligence
09:11:17
Containment action taken — endpoint isolated
09:12:31
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00243 | 11m ago | Tor Exit Node Connection | Medium | Investigating | SRV-FILE-01 |
| ALR-00235 | 2h ago | Suspicious Scheduled Task | High | Open | WS-PC-003 |
| ALR-00401 | 4h ago | Tor Exit Node Connection | High | Open | WS-PC-001 |
| ALR-00103 | 5h ago | Data Exfiltration Attempt | Low | Open | WS-PC-003 |
| ALR-00105 | 19h ago | Tor Exit Node Connection | Low | Investigating | SRV-APP-01 |