Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:56:33 UTC

Pass-the-Hash Detected

Low Escalated
ALR-00018 · 2026-05-23T11:00:23Z

Description

Pass-the-Hash technique detected on WS-PC-002. NTLM authentication from 'p.thomas' without standard Kerberos ticket. Network IDS flagged.

Alert Metadata

Alert ID
ALR-00018
Timestamp
2026-05-23T11:00:23Z
Severity
Low
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-002
User Account
p.thomas
Source IP
91.208.195.118
Destination IP
10.0.30.125
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1550.002
Reference
attack.mitre.org/techniques/T1550.002

Investigation Timeline

11:00:23 Event ingested by SOC365 Engine
11:00:27 EmilyAI triage started — correlation enrichment
11:00:38 EmilyAI confidence: 83% — escalated to human analyst
11:01:02 Alert assigned to analyst: EmilyAI (auto)
11:02:43 Investigation started — querying SIEM and threat intelligence
11:07:31 Containment action taken — endpoint isolated
11:11:46 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00375 3h ago Pass-the-Hash Detected Medium Resolved SRV-MAIL-01
ALR-00074 5h ago Pass-the-Hash Detected Medium Open WS-LAP-011
ALR-00359 10h ago Rogue DHCP Server Medium Open WS-PC-002
ALR-00373 18h ago Pass-the-Hash Detected Low False Positive SRV-SQL-01
ALR-00040 18h ago Pass-the-Hash Detected Low False Positive AP-WIFI-03