DecoyPulse Honeypot Triggered
High
Open
ALR-00040 · 2026-05-26T05:01:31Z
Description
DecoyPulse honeypot on WS-PC-002 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
05:01:31
Event ingested by SOC365 Engine
05:01:32
EmilyAI triage started — correlation enrichment
05:01:42
EmilyAI confidence: 90% — escalated to human analyst
05:01:55
Alert assigned to analyst: Marcus Webb
05:03:28
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00202 | 3h ago | Certificate Anomaly | Low | Open | WS-PC-002 |
| ALR-00323 | 4h ago | DecoyPulse Honeypot Triggered | Medium | Escalated | WS-LAP-011 |
| ALR-00045 | 5h ago | Brute Force SSH | Informational | Investigating | WS-PC-002 |
| ALR-00126 | 14h ago | Rogue DHCP Server | Informational | False Positive | WS-PC-002 |
| ALR-00071 | 15h ago | Suspicious PowerShell Execution | Informational | Resolved | WS-PC-002 |