Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:30 UTC

Shadow IT Discovery

Low Open
ALR-00473 · 2026-05-22T19:34:30Z

Description

Dark Web Monitor discovered unauthorised SaaS application (file sharing) used by 's.jones'. 14GB of company data synced to unapproved cloud storage.

Alert Metadata

Alert ID
ALR-00473
Timestamp
2026-05-22T19:34:30Z
Severity
Low
Status
Open
Detection Source
Dark Web Monitor
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-APP-01
User Account
s.jones
Source IP
45.205.148.5
Destination IP
10.1.240.201
Origin Country
BR Brazil

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1567
Reference
attack.mitre.org/techniques/T1567

Investigation Timeline

19:34:30 Event ingested by SOC365 Engine
19:34:34 EmilyAI triage started — correlation enrichment
19:34:43 EmilyAI confidence: 89% — escalated to human analyst
19:34:53 Alert assigned to analyst: EmilyAI (auto)
19:36:54 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00295 4h ago DLP Policy Violation Medium Investigating SRV-APP-01
ALR-00106 7h ago Shadow IT Discovery High Open SRV-WEB-01
ALR-00107 13h ago Unusual Outbound Traffic Low False Positive SRV-APP-01
ALR-00314 1d ago Shadow IT Discovery Medium Open WS-PC-006
ALR-00012 1d ago Shadow IT Discovery Informational Resolved SRV-FILE-01