Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:02:51 UTC

Insider Threat Indicator

Low Investigating
ALR-00424 · 2026-05-21T22:36:20Z

Description

Anomalous after-hours access by 'm.taylor' on VM-DEV-01. Accessed 847 files across 12 shares in 45 minutes. Pattern flagged by Dark Web Monitor.

Alert Metadata

Alert ID
ALR-00424
Timestamp
2026-05-21T22:36:20Z
Severity
Low
Status
Investigating
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
VM-DEV-01
User Account
m.taylor
Source IP
194.215.62.9
Destination IP
10.3.219.84
Origin Country
NG Nigeria

MITRE ATT&CK Mapping

Tactic
Collection
Technique
T1119
Reference
attack.mitre.org/techniques/T1119

Investigation Timeline

22:36:20 Event ingested by SOC365 Engine
22:36:25 EmilyAI triage started — correlation enrichment
22:36:30 EmilyAI confidence: 92% — escalated to human analyst
22:37:00 Alert assigned to analyst: EmilyAI (auto)
22:37:20 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00184 3h ago Insider Threat Indicator High Investigating WS-LAP-010
ALR-00379 12h ago Insider Threat Indicator High Investigating AP-WIFI-03
ALR-00342 17h ago Insider Threat Indicator Medium False Positive SRV-SQL-01
ALR-00127 20h ago Malware Signature Match Medium Escalated VM-DEV-01
ALR-00083 23h ago Insider Threat Indicator Low Escalated WS-PC-006