DecoyPulse Honeypot Triggered
Medium
Open
ALR-00142 · 2026-05-24T21:08:00Z
Description
DecoyPulse honeypot on WS-PC-006 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:08:00
Event ingested by SOC365 Engine
21:08:05
EmilyAI triage started — correlation enrichment
21:08:14
EmilyAI confidence: 90% — escalated to human analyst
21:08:32
Alert assigned to analyst: Emma Richardson
21:09:53
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00018 | 1h ago | Insider Threat Indicator | Medium | False Positive | WS-PC-006 |
| ALR-00220 | 2h ago | Kerberoasting Attempt | Medium | Resolved | WS-PC-006 |
| ALR-00449 | 5h ago | DecoyPulse Honeypot Triggered | Medium | Open | SW-CORE-01 |
| ALR-00169 | 7h ago | Tor Exit Node Connection | Low | Resolved | WS-PC-006 |
| ALR-00454 | 8h ago | Lateral Movement Detected | Informational | Open | WS-PC-006 |