Shadow IT Discovery
Low
Open
ALR-00473 · 2026-05-22T19:34:30Z
Description
Dark Web Monitor discovered unauthorised SaaS application (file sharing) used by 's.jones'. 14GB of company data synced to unapproved cloud storage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:34:30
Event ingested by SOC365 Engine
19:34:34
EmilyAI triage started — correlation enrichment
19:34:43
EmilyAI confidence: 89% — escalated to human analyst
19:34:53
Alert assigned to analyst: EmilyAI (auto)
19:36:54
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00295 | 4h ago | DLP Policy Violation | Medium | Investigating | SRV-APP-01 |
| ALR-00106 | 7h ago | Shadow IT Discovery | High | Open | SRV-WEB-01 |
| ALR-00107 | 13h ago | Unusual Outbound Traffic | Low | False Positive | SRV-APP-01 |
| ALR-00314 | 1d ago | Shadow IT Discovery | Medium | Open | WS-PC-006 |
| ALR-00012 | 1d ago | Shadow IT Discovery | Informational | Resolved | SRV-FILE-01 |