Tor Exit Node Connection
Informational
Escalated
ALR-00461 · 2026-05-24T02:01:39Z
Description
Connection from SRV-MAIL-01 to known Tor exit node detected by Firewall. User 'system' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:01:39
Event ingested by SOC365 Engine
02:01:40
EmilyAI triage started — correlation enrichment
02:01:49
EmilyAI confidence: 96% — escalated to human analyst
02:02:02
Alert assigned to analyst: EmilyAI (auto)
02:03:05
Investigation started — querying SIEM and threat intelligence
02:09:02
Containment action taken — endpoint isolated
02:21:30
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00453 | 7h ago | Tor Exit Node Connection | Low | Investigating | SRV-MAIL-01 |
| ALR-00222 | 11h ago | Tor Exit Node Connection | Low | Investigating | FW-EDGE-01 |
| ALR-00473 | 18h ago | Tor Exit Node Connection | Medium | False Positive | WS-PC-002 |
| ALR-00279 | 21h ago | Tor Exit Node Connection | Critical | Escalated | SRV-APP-01 |
| ALR-00500 | 1d ago | Phishing Email Blocked | Medium | Escalated | SRV-MAIL-01 |