DecoyPulse Honeypot Triggered
High
Escalated
ALR-00064 · 2026-04-12T02:10:25Z
Description
DecoyPulse honeypot on SRV-FILE-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:10:25
Event ingested by SOC365 Engine
02:10:26
EmilyAI triage started — correlation enrichment
02:10:37
EmilyAI confidence: 81% — escalated to human analyst
02:10:52
Alert assigned to analyst: Emma Richardson
02:12:24
Investigation started — querying SIEM and threat intelligence
02:14:45
Containment action taken — endpoint isolated
02:24:25
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00256 | 36m ago | Port Scan Detected | Low | Resolved | SRV-FILE-01 |
| ALR-00373 | 38m ago | DecoyPulse Honeypot Triggered | Low | Open | WS-PC-006 |
| ALR-00209 | 1h ago | DecoyPulse Honeypot Triggered | Low | Resolved | SRV-APP-01 |
| ALR-00428 | 7h ago | Data Exfiltration Attempt | High | Investigating | SRV-FILE-01 |
| ALR-00493 | 7h ago | DecoyPulse Honeypot Triggered | High | Investigating | SRV-DC-01 |