Tor Exit Node Connection
Medium
False Positive
ALR-00488 · 2026-04-06T16:31:54Z
Description
Connection from WS-LAP-012 to known Tor exit node detected by DLP Module. User 'k.brown' was active at the time.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:31:54
Event ingested by SOC365 Engine
16:31:57
EmilyAI triage started — correlation enrichment
16:32:04
EmilyAI confidence: 93% — escalated to human analyst
16:32:11
Alert assigned to analyst: Emma Richardson
16:34:44
Investigation started — querying SIEM and threat intelligence
16:39:59
Containment action taken — endpoint isolated
16:50:57
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00368 | 3h ago | Shadow IT Discovery | Low | Resolved | WS-LAP-012 |
| ALR-00023 | 4h ago | Pass-the-Hash Detected | Low | Escalated | WS-LAP-012 |
| ALR-00013 | 10h ago | Tor Exit Node Connection | Low | Escalated | WS-PC-003 |
| ALR-00344 | 10h ago | Malware Signature Match | Low | Resolved | WS-LAP-012 |
| ALR-00383 | 11h ago | Privilege Escalation Attempt | High | Escalated | WS-LAP-012 |