Tor Exit Node Connection
Low
Investigating
ALR-00456 · 2026-05-23T01:12:06Z
Description
Connection from SW-CORE-01 to known Tor exit node detected by DecoyPulse. User 'k.brown' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:12:06
Event ingested by SOC365 Engine
01:12:10
EmilyAI triage started — correlation enrichment
01:12:15
EmilyAI confidence: 97% — escalated to human analyst
01:12:31
Alert assigned to analyst: EmilyAI (auto)
01:13:41
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00371 | 5h ago | Rogue DHCP Server | Low | False Positive | SW-CORE-01 |
| ALR-00117 | 7h ago | Lateral Movement Detected | Medium | Investigating | SW-CORE-01 |
| ALR-00203 | 10h ago | Tor Exit Node Connection | Informational | False Positive | WS-PC-001 |
| ALR-00234 | 12h ago | Tor Exit Node Connection | High | Investigating | WS-PC-004 |
| ALR-00379 | 20h ago | Tor Exit Node Connection | Informational | False Positive | SW-CORE-01 |