Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:08:19 UTC

Shadow IT Discovery

High Escalated
ALR-00422 · 2026-05-24T22:07:19Z

Description

Endpoint Agent discovered unauthorised SaaS application (file sharing) used by 'k.brown'. 14GB of company data synced to unapproved cloud storage.

Alert Metadata

Alert ID
ALR-00422
Timestamp
2026-05-24T22:07:19Z
Severity
High
Status
Escalated
Detection Source
Endpoint Agent
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-PC-004
User Account
k.brown
Source IP
185.89.220.199
Destination IP
10.3.236.127
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567
Reference
attack.mitre.org/techniques/T1567

Investigation Timeline

22:07:19 Event ingested by SOC365 Engine
22:07:23 EmilyAI triage started — correlation enrichment
22:07:26 EmilyAI confidence: 86% — escalated to human analyst
22:07:51 Alert assigned to analyst: Emma Richardson
22:08:39 Investigation started — querying SIEM and threat intelligence
22:16:15 Containment action taken — endpoint isolated
22:27:14 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00392 3h ago Kerberoasting Attempt Medium Investigating WS-PC-004
ALR-00266 4h ago Unusual Outbound Traffic Critical Open WS-PC-004
ALR-00247 5h ago Unauthorised USB Device Low False Positive WS-PC-004
ALR-00426 9h ago Port Scan Detected Medium Resolved WS-PC-004
ALR-00102 17h ago Shadow IT Discovery Low Open WS-LAP-010