Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:17:48 UTC

DLP Policy Violation

Informational Investigating
ALR-00496 · 2026-04-12T03:22:28Z

Description

DLP policy violation: user 'e.evans' attempted to email 3 files classified as 'Confidential' to external address from SRV-FILE-01.

Alert Metadata

Alert ID
ALR-00496
Timestamp
2026-04-12T03:22:28Z
Severity
Informational
Status
Investigating
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-FILE-01
User Account
e.evans
Source IP
45.157.148.128
Destination IP
10.2.202.11
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Exfiltration
Technique
T1048
Reference
attack.mitre.org/techniques/T1048

Investigation Timeline

03:22:28 Event ingested by SOC365 Engine
03:22:33 EmilyAI triage started — correlation enrichment
03:22:43 EmilyAI confidence: 84% — escalated to human analyst
03:22:52 Alert assigned to analyst: EmilyAI (auto)
03:24:18 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00123 13h ago DLP Policy Violation Low Investigating WS-PC-001
ALR-00216 14h ago DLP Policy Violation Low False Positive SW-CORE-01
ALR-00150 21h ago Data Exfiltration Attempt Low Escalated SRV-FILE-01
ALR-00092 1d ago DLP Policy Violation Low Resolved SRV-SQL-01
ALR-00206 1d ago Lateral Movement Detected Informational Open SRV-FILE-01