Port Scan Detected
Informational
Resolved
ALR-00075 · 2026-04-06T00:19:53Z
Description
Sequential port scan (1-1024) detected targeting WS-PC-004 from external IP. Cloud Connector identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
00:19:53
Event ingested by SOC365 Engine
00:19:55
EmilyAI triage started — correlation enrichment
00:20:00
EmilyAI confidence: 93% — escalated to human analyst
00:20:17
Alert assigned to analyst: EmilyAI (auto)
00:21:52
Investigation started — querying SIEM and threat intelligence
00:27:23
Containment action taken — endpoint isolated
00:37:37
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00384 | 22m ago | Port Scan Detected | Informational | Open | SRV-APP-01 |
| ALR-00391 | 2h ago | Port Scan Detected | Low | False Positive | SRV-BACKUP-01 |
| ALR-00255 | 2h ago | Brute Force SSH | Medium | False Positive | WS-PC-004 |
| ALR-00227 | 2h ago | Port Scan Detected | High | Open | WS-PC-002 |
| ALR-00249 | 4h ago | Certificate Anomaly | Low | Resolved | WS-PC-004 |