Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:04:24 UTC

Phishing Email Blocked

Low Open
ALR-00494 · 2026-04-08T20:26:29Z

Description

Phishing email targeting 'r.davies@company.co.uk' blocked by Firewall. Payload: credential harvesting link mimicking Microsoft 365 login.

Alert Metadata

Alert ID
ALR-00494
Timestamp
2026-04-08T20:26:29Z
Severity
Low
Status
Open
Detection Source
Firewall
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-FILE-01
User Account
r.davies
Source IP
194.181.62.189
Destination IP
10.0.108.237
Origin Country
KP North Korea

MITRE ATT&CK Mapping

Tactic
Initial Access
Technique
T1566.001
Reference
attack.mitre.org/techniques/T1566.001

Investigation Timeline

20:26:29 Event ingested by SOC365 Engine
20:26:31 EmilyAI triage started — correlation enrichment
20:26:35 EmilyAI confidence: 81% — escalated to human analyst
20:27:04 Alert assigned to analyst: EmilyAI (auto)
20:27:18 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00020 52m ago Certificate Anomaly Informational Investigating SRV-FILE-01
ALR-00372 8h ago Rogue DHCP Server Low Open SRV-FILE-01
ALR-00226 18h ago Pass-the-Hash Detected Medium Investigating SRV-FILE-01
ALR-00323 1d ago Phishing Email Blocked Medium False Positive SRV-DC-01
ALR-00245 1d ago Phishing Email Blocked High Open WS-PC-003