Phishing Email Blocked
Low
Open
ALR-00494 · 2026-04-08T20:26:29Z
Description
Phishing email targeting 'r.davies@company.co.uk' blocked by Firewall. Payload: credential harvesting link mimicking Microsoft 365 login.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:26:29
Event ingested by SOC365 Engine
20:26:31
EmilyAI triage started — correlation enrichment
20:26:35
EmilyAI confidence: 81% — escalated to human analyst
20:27:04
Alert assigned to analyst: EmilyAI (auto)
20:27:18
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00020 | 52m ago | Certificate Anomaly | Informational | Investigating | SRV-FILE-01 |
| ALR-00372 | 8h ago | Rogue DHCP Server | Low | Open | SRV-FILE-01 |
| ALR-00226 | 18h ago | Pass-the-Hash Detected | Medium | Investigating | SRV-FILE-01 |
| ALR-00323 | 1d ago | Phishing Email Blocked | Medium | False Positive | SRV-DC-01 |
| ALR-00245 | 1d ago | Phishing Email Blocked | High | Open | WS-PC-003 |