Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 20:15:32 UTC

Privilege Escalation Attempt

Medium Resolved
ALR-00158 · 2026-05-23T07:54:37Z

Description

User 'a.wilson' on AP-WIFI-03 attempted to escalate to SYSTEM via token manipulation. DecoyPulse blocked the attempt.

Alert Metadata

Alert ID
ALR-00158
Timestamp
2026-05-23T07:54:37Z
Severity
Medium
Status
Resolved
Detection Source
DecoyPulse
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
AP-WIFI-03
User Account
a.wilson
Source IP
194.218.62.193
Destination IP
10.3.219.90
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Privilege Escalation
Technique
T1134
Reference
attack.mitre.org/techniques/T1134

Investigation Timeline

07:54:37 Event ingested by SOC365 Engine
07:54:42 EmilyAI triage started — correlation enrichment
07:54:45 EmilyAI confidence: 80% — escalated to human analyst
07:55:19 Alert assigned to analyst: Marcus Webb
07:56:55 Investigation started — querying SIEM and threat intelligence
07:59:11 Containment action taken — endpoint isolated
08:10:06 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00217 3h ago Unauthorised USB Device Medium Resolved AP-WIFI-03
ALR-00114 6h ago Lateral Movement Detected Low Open AP-WIFI-03
ALR-00234 8h ago Privilege Escalation Attempt Medium Resolved WS-LAP-012
ALR-00099 8h ago C2 Beacon Activity Low Investigating AP-WIFI-03
ALR-00095 16h ago Privilege Escalation Attempt Medium Open WS-PC-004