DecoyPulse Honeypot Triggered
Medium
Open
ALR-00081 · 2026-05-24T17:33:42Z
Description
DecoyPulse honeypot on FW-EDGE-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
17:33:42
Event ingested by SOC365 Engine
17:33:43
EmilyAI triage started — correlation enrichment
17:33:56
EmilyAI confidence: 92% — escalated to human analyst
17:34:11
Alert assigned to analyst: Sarah Chen
17:34:31
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00008 | 8h ago | DecoyPulse Honeypot Triggered | Low | Open | WS-LAP-012 |
| ALR-00260 | 23h ago | Insider Threat Indicator | Low | Open | FW-EDGE-01 |
| ALR-00450 | 1d ago | DecoyPulse Honeypot Triggered | Low | False Positive | WS-PC-004 |
| ALR-00344 | 1d ago | DecoyPulse Honeypot Triggered | Low | False Positive | SRV-WEB-01 |
| ALR-00277 | 1d ago | Suspicious PowerShell Execution | High | Escalated | FW-EDGE-01 |