Sensitivity
RESTRICTED · tier 3
Records exposed
14,208 rows
External recipients
1 · personal gmail
Blast radius
contained · no fwd
Q2-Pricing-Forecast.xlsx
sharepoint://finance/fp&a/forecasting/2046/Q2/ · 4.1 MB · modified 11:42 PDT
RESTRICTED
PII · 3 types
financial
Rows · cols
14,208 × 42
Customer records
11,642
Revenue figures
Q2 + FY forecast
Classifier match
98.6% conf
Activity timeline
Activity timeline · incident ±2h window
12:08:41PDT · 2h 37m ago
VPN session established from Seattle · res ISP
ip 73.82.114.201dev MBP-DR-14auth sso+mfa
13:42:19PDT · 1h 03m ago
Accessed SharePoint path /finance/fp&a/forecasting/2046/Q2/
session 9a1f…e814 files listed2 opened
14:11:02PDT · 34m ago
Downloaded Q2-Pricing-Forecast.xlsx to local device
4.1 MBclassification RESTRICTEDpolicy allow · audit
14:19:47PDT · 26m ago
Renamed file to q2-forecast-personal.xlsx
local fs~/Downloads/removes classification tag
14:32:07PDT · 13m ago
Outbound email attempted · attachment blocked by DLP
to daniel.reyes.84@gmail.comsubj "weekend numbers"attach 1 · 4.1 MBpolicy DLP-R-019 · external-share-restricted
14:32:09PDT · 13m ago
User acknowledged policy prompt and retried with 2nd attempt via shared link
onedrive.share · anonymous-linkblocked by policyelapsed 2s after 1st block
14:33:54PDT · 11m ago
Opened browser tab · support article "how to share a file outside company"
intranet.northwind/help/s/2146s dwell
14:35:12PDT · 10m ago
Auto-quarantine q2-forecast-personal.xlsx on managed device
crowdstrike.mdmfile hash sha256:6f3c…a1user notified
14:38:20PDT · 7m ago
User opened Slack DM to manager S. Alvarez — draft not sent
typing 42sdeleted draft
14:42:11PDT · 3m ago
Incident triaged and assigned to M. Kwon by auto-router
priority HIGHsla 4hplaybook PB-DATA-019
showing 10 of 1,240 events in window