Unusual Outbound Traffic
High
Investigating
ALR-00429 · 2026-04-10T19:14:13Z
Description
Unusual outbound traffic pattern from WS-LAP-010 to IP in Eastern Europe. 450MB transferred over non-standard port. Flagged by Network IDS.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:14:13
Event ingested by SOC365 Engine
19:14:15
EmilyAI triage started — correlation enrichment
19:14:25
EmilyAI confidence: 86% — escalated to human analyst
19:14:58
Alert assigned to analyst: Marcus Webb
19:16:26
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00027 | 3h ago | Unusual Outbound Traffic | Medium | False Positive | WS-LAP-011 |
| ALR-00166 | 4h ago | Privilege Escalation Attempt | Low | Investigating | WS-LAP-010 |
| ALR-00093 | 11h ago | Unusual Outbound Traffic | High | Open | WS-PC-002 |
| ALR-00414 | 12h ago | Unusual Outbound Traffic | High | Investigating | AP-WIFI-03 |
| ALR-00475 | 16h ago | Unusual Outbound Traffic | High | Investigating | SW-CORE-01 |