Tor Exit Node Connection
Medium
Open
ALR-00410 · 2026-05-24T02:45:34Z
Description
Connection from WS-PC-003 to known Tor exit node detected by Cloud Connector. User 'p.thomas' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:45:34
Event ingested by SOC365 Engine
02:45:39
EmilyAI triage started — correlation enrichment
02:45:45
EmilyAI confidence: 91% — escalated to human analyst
02:45:54
Alert assigned to analyst: Anika Patel
02:47:50
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00383 | 2h ago | Credential Stuffing Attempt | High | Open | WS-PC-003 |
| ALR-00107 | 5h ago | Tor Exit Node Connection | High | Investigating | WS-LAP-010 |
| ALR-00454 | 9h ago | Credential Stuffing Attempt | Medium | Investigating | WS-PC-003 |
| ALR-00317 | 15h ago | Tor Exit Node Connection | Low | Open | SRV-APP-01 |
| ALR-00025 | 18h ago | Unusual Outbound Traffic | High | Escalated | WS-PC-003 |