Lateral Movement Detected
High
Escalated
ALR-00037 · 2026-04-08T02:34:12Z
Description
DecoyPulse detected lateral movement from WS-MAC-005 to SRV-DC-01 using user 'e.evans' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:34:12
Event ingested by SOC365 Engine
02:34:13
EmilyAI triage started — correlation enrichment
02:34:21
EmilyAI confidence: 85% — escalated to human analyst
02:34:40
Alert assigned to analyst: Marcus Webb
02:35:39
Investigation started — querying SIEM and threat intelligence
02:37:56
Containment action taken — endpoint isolated
02:47:36
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00140 | 16m ago | Lateral Movement Detected | Low | False Positive | SRV-APP-01 |
| ALR-00154 | 3h ago | Brute Force SSH | Informational | Resolved | WS-MAC-005 |
| ALR-00276 | 6h ago | Lateral Movement Detected | Low | Escalated | SRV-BACKUP-01 |
| ALR-00384 | 15h ago | Lateral Movement Detected | Medium | Investigating | FW-EDGE-01 |
| ALR-00220 | 18h ago | Insider Threat Indicator | Medium | Investigating | WS-MAC-005 |