Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:03:35 UTC

Shadow IT Discovery

Informational Open
ALR-00431 · 2026-05-25T23:01:44Z

Description

EmilyAI Triage discovered unauthorised SaaS application (file sharing) used by 'd.walker'. 14GB of company data synced to unapproved cloud storage.

Alert Metadata

Alert ID
ALR-00431
Timestamp
2026-05-25T23:01:44Z
Severity
Informational
Status
Open
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-004
User Account
d.walker
Source IP
103.161.216.86
Destination IP
10.1.101.130
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567
Reference
attack.mitre.org/techniques/T1567

Investigation Timeline

23:01:44 Event ingested by SOC365 Engine
23:01:46 EmilyAI triage started — correlation enrichment
23:01:53 EmilyAI confidence: 92% — escalated to human analyst
23:02:07 Alert assigned to analyst: EmilyAI (auto)
23:03:53 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00349 1h ago Shadow IT Discovery High Open SRV-APP-01
ALR-00256 6h ago Shadow IT Discovery Low Escalated WS-PC-001
ALR-00137 14h ago DecoyPulse Honeypot Triggered Informational False Positive WS-PC-004
ALR-00281 18h ago Shadow IT Discovery Low Investigating WS-PC-004
ALR-00319 19h ago Privilege Escalation Attempt Low Investigating WS-PC-004