Port Scan Detected
Medium
Escalated
ALR-00009 · 2026-05-24T07:15:11Z
Description
Sequential port scan (1-1024) detected targeting WS-MAC-005 from external IP. Firewall identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:15:11
Event ingested by SOC365 Engine
07:15:16
EmilyAI triage started — correlation enrichment
07:15:23
EmilyAI confidence: 96% — escalated to human analyst
07:15:44
Alert assigned to analyst: Marcus Webb
07:16:17
Investigation started — querying SIEM and threat intelligence
07:25:03
Containment action taken — endpoint isolated
07:28:23
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00285 | 6h ago | Privilege Escalation Attempt | Informational | Escalated | WS-MAC-005 |
| ALR-00381 | 7h ago | Port Scan Detected | Informational | Escalated | WS-PC-006 |
| ALR-00181 | 7h ago | Data Exfiltration Attempt | Low | False Positive | WS-MAC-005 |
| ALR-00375 | 9h ago | Brute Force SSH | Low | Investigating | WS-MAC-005 |
| ALR-00157 | 11h ago | Port Scan Detected | Informational | False Positive | SRV-DC-01 |