Pass-the-Hash Detected
Medium
Resolved
ALR-00091 · 2026-04-07T11:28:15Z
Description
Pass-the-Hash technique detected on SRV-DC-01. NTLM authentication from 'h.roberts' without standard Kerberos ticket. Endpoint Agent flagged.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:28:15
Event ingested by SOC365 Engine
11:28:17
EmilyAI triage started — correlation enrichment
11:28:28
EmilyAI confidence: 84% — escalated to human analyst
11:28:39
Alert assigned to analyst: James Okonkwo
11:31:14
Investigation started — querying SIEM and threat intelligence
11:35:50
Containment action taken — endpoint isolated
11:42:01
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00400 | 5h ago | Suspicious Scheduled Task | Medium | False Positive | SRV-DC-01 |
| ALR-00057 | 8h ago | Certificate Anomaly | Informational | Investigating | SRV-DC-01 |
| ALR-00443 | 9h ago | Malware Signature Match | Low | False Positive | SRV-DC-01 |
| ALR-00334 | 9h ago | Privilege Escalation Attempt | Medium | Investigating | SRV-DC-01 |
| ALR-00061 | 9h ago | Malware Signature Match | Informational | Open | SRV-DC-01 |