DecoyPulse Honeypot Triggered
Informational
Resolved
ALR-00072 · 2026-04-11T23:56:50Z
Description
DecoyPulse honeypot on VM-DEV-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:56:50
Event ingested by SOC365 Engine
23:56:55
EmilyAI triage started — correlation enrichment
23:56:57
EmilyAI confidence: 79% — escalated to human analyst
23:57:34
Alert assigned to analyst: EmilyAI (auto)
23:58:37
Investigation started — querying SIEM and threat intelligence
00:04:11
Containment action taken — endpoint isolated
00:12:04
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00247 | 6h ago | Lateral Movement Detected | Low | Investigating | VM-DEV-01 |
| ALR-00398 | 14h ago | DecoyPulse Honeypot Triggered | Informational | Resolved | SRV-FILE-01 |
| ALR-00129 | 1d ago | Tor Exit Node Connection | Low | Investigating | VM-DEV-01 |
| ALR-00453 | 1d ago | DecoyPulse Honeypot Triggered | Low | Investigating | FW-EDGE-01 |
| ALR-00006 | 1d ago | DecoyPulse Honeypot Triggered | Medium | Open | SRV-APP-01 |