Pass-the-Hash Detected
Low
Escalated
ALR-00018 · 2026-05-23T11:00:23Z
Description
Pass-the-Hash technique detected on WS-PC-002. NTLM authentication from 'p.thomas' without standard Kerberos ticket. Network IDS flagged.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:00:23
Event ingested by SOC365 Engine
11:00:27
EmilyAI triage started — correlation enrichment
11:00:38
EmilyAI confidence: 83% — escalated to human analyst
11:01:02
Alert assigned to analyst: EmilyAI (auto)
11:02:43
Investigation started — querying SIEM and threat intelligence
11:07:31
Containment action taken — endpoint isolated
11:11:46
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00375 | 3h ago | Pass-the-Hash Detected | Medium | Resolved | SRV-MAIL-01 |
| ALR-00074 | 5h ago | Pass-the-Hash Detected | Medium | Open | WS-LAP-011 |
| ALR-00359 | 10h ago | Rogue DHCP Server | Medium | Open | WS-PC-002 |
| ALR-00373 | 18h ago | Pass-the-Hash Detected | Low | False Positive | SRV-SQL-01 |
| ALR-00040 | 18h ago | Pass-the-Hash Detected | Low | False Positive | AP-WIFI-03 |