Shadow IT Discovery
Medium
Investigating
ALR-00449 · 2026-04-06T19:13:11Z
Description
Email Gateway discovered unauthorised SaaS application (file sharing) used by 'n.clark'. 14GB of company data synced to unapproved cloud storage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:13:11
Event ingested by SOC365 Engine
19:13:13
EmilyAI triage started — correlation enrichment
19:13:20
EmilyAI confidence: 90% — escalated to human analyst
19:13:45
Alert assigned to analyst: Emma Richardson
19:14:23
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00398 | 28m ago | Shadow IT Discovery | Critical | Investigating | WS-LAP-011 |
| ALR-00144 | 2h ago | Ransomware Behaviour Detected | Medium | Investigating | WS-LAP-011 |
| ALR-00114 | 2h ago | Certificate Anomaly | Medium | Investigating | WS-LAP-011 |
| ALR-00368 | 3h ago | Shadow IT Discovery | Low | Resolved | WS-LAP-012 |
| ALR-00382 | 11h ago | Shadow IT Discovery | Informational | False Positive | WS-PC-003 |