Port Scan Detected
High
Open
ALR-00019 · 2026-05-22T01:50:51Z
Description
Sequential port scan (1-1024) detected targeting SW-CORE-01 from external IP. Email Gateway identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:50:51
Event ingested by SOC365 Engine
01:50:54
EmilyAI triage started — correlation enrichment
01:51:01
EmilyAI confidence: 88% — escalated to human analyst
01:51:12
Alert assigned to analyst: James Okonkwo
01:51:41
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00362 | 6h ago | Port Scan Detected | Low | Investigating | SRV-APP-01 |
| ALR-00464 | 14h ago | Pass-the-Hash Detected | Informational | False Positive | SW-CORE-01 |
| ALR-00315 | 15h ago | Port Scan Detected | Medium | Open | SRV-FILE-01 |
| ALR-00399 | 18h ago | Data Exfiltration Attempt | Medium | Investigating | SW-CORE-01 |
| ALR-00401 | 22h ago | Port Scan Detected | High | Escalated | SRV-BACKUP-01 |