Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:19:11 UTC

Phishing Email Blocked

High Escalated
ALR-00477 · 2026-04-09T16:25:14Z

Description

Phishing email targeting 'r.davies@company.co.uk' blocked by Network IDS. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00477
Timestamp
2026-04-09T16:25:14Z
Severity
High
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
James Okonkwo

Endpoint Information

Hostname
SRV-WEB-01
User Account
r.davies
Source IP
45.175.148.141
Destination IP
10.3.195.200
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

16:25:14 Event ingested by SOC365 Engine
16:25:16 EmilyAI triage started — correlation enrichment
16:25:20 EmilyAI confidence: 94% — escalated to human analyst
16:25:55 Alert assigned to analyst: James Okonkwo
16:26:36 Investigation started — querying SIEM and threat intelligence
16:32:03 Containment action taken — endpoint isolated
16:44:18 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00404 2h ago Tor Exit Node Connection Medium False Positive SRV-WEB-01
ALR-00396 8h ago Certificate Anomaly Medium Resolved SRV-WEB-01
ALR-00046 10h ago Phishing Email Blocked Informational Resolved WS-LAP-010
ALR-00417 11h ago Phishing Email Blocked Medium Open SRV-FILE-01
ALR-00044 22h ago Phishing Email Blocked Medium Escalated WS-LAP-011