Insider Threat Indicator
Low
Investigating
ALR-00424 · 2026-05-21T22:36:20Z
Description
Anomalous after-hours access by 'm.taylor' on VM-DEV-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Dark Web Monitor.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:36:20
Event ingested by SOC365 Engine
22:36:25
EmilyAI triage started — correlation enrichment
22:36:30
EmilyAI confidence: 92% — escalated to human analyst
22:37:00
Alert assigned to analyst: EmilyAI (auto)
22:37:20
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00184 | 3h ago | Insider Threat Indicator | High | Investigating | WS-LAP-010 |
| ALR-00379 | 12h ago | Insider Threat Indicator | High | Investigating | AP-WIFI-03 |
| ALR-00342 | 17h ago | Insider Threat Indicator | Medium | False Positive | SRV-SQL-01 |
| ALR-00127 | 20h ago | Malware Signature Match | Medium | Escalated | VM-DEV-01 |
| ALR-00083 | 23h ago | Insider Threat Indicator | Low | Escalated | WS-PC-006 |