Lateral Movement Detected
Medium
Open
ALR-00064 · 2026-05-23T21:59:56Z
Description
Attack Surface Scanner detected lateral movement from SW-CORE-01 to SRV-DC-01 using user 'n.clark' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:59:56
Event ingested by SOC365 Engine
22:00:01
EmilyAI triage started — correlation enrichment
22:00:04
EmilyAI confidence: 93% — escalated to human analyst
22:00:39
Alert assigned to analyst: Emma Richardson
22:00:41
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00416 | 6h ago | Suspicious PowerShell Execution | Medium | Investigating | SW-CORE-01 |
| ALR-00206 | 10h ago | Data Exfiltration Attempt | Low | Investigating | SW-CORE-01 |
| ALR-00282 | 1d ago | Ransomware Behaviour Detected | Informational | Escalated | SW-CORE-01 |
| ALR-00446 | 1d ago | Lateral Movement Detected | Informational | Open | WS-LAP-012 |
| ALR-00272 | 1d ago | Failed MFA Challenge | Medium | Investigating | SW-CORE-01 |