Port Scan Detected
Informational
False Positive
ALR-00113 · 2026-04-05T19:53:26Z
Description
Sequential port scan (1-1024) detected targeting VM-DEV-01 from external IP. Cloud Connector identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
19:53:26
Event ingested by SOC365 Engine
19:53:28
EmilyAI triage started — correlation enrichment
19:53:34
EmilyAI confidence: 87% — escalated to human analyst
19:53:44
Alert assigned to analyst: EmilyAI (auto)
19:56:17
Investigation started — querying SIEM and threat intelligence
20:00:56
Containment action taken — endpoint isolated
20:12:53
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00388 | 2h ago | Port Scan Detected | Informational | Investigating | SW-CORE-01 |
| ALR-00097 | 2h ago | Data Exfiltration Attempt | Medium | Escalated | VM-DEV-01 |
| ALR-00376 | 16h ago | Port Scan Detected | Informational | Investigating | SW-CORE-01 |
| ALR-00286 | 20h ago | Port Scan Detected | Medium | Open | SRV-BACKUP-01 |
| ALR-00073 | 21h ago | Port Scan Detected | Low | Escalated | SW-CORE-01 |