Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:26:20 UTC

DecoyPulse Honeypot Triggered

Medium False Positive
ALR-00164 · 2026-04-08T18:07:59Z

Description

DecoyPulse honeypot on SRV-WEB-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.

Alert Metadata

Alert ID
ALR-00164
Timestamp
2026-04-08T18:07:59Z
Severity
Medium
Status
False Positive
Detection Source
Network IDS
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
SRV-WEB-01
User Account
c.williams
Source IP
185.40.220.80
Destination IP
10.0.16.18
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Discovery
Technique
T1018
Reference
attack.mitre.org/techniques/T1018

Investigation Timeline

18:07:59 Event ingested by SOC365 Engine
18:08:04 EmilyAI triage started — correlation enrichment
18:08:14 EmilyAI confidence: 95% — escalated to human analyst
18:08:39 Alert assigned to analyst: Emma Richardson
18:10:42 Investigation started — querying SIEM and threat intelligence
18:14:04 Containment action taken — endpoint isolated
18:23:44 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00047 4h ago DecoyPulse Honeypot Triggered Informational Escalated WS-PC-004
ALR-00440 4h ago DecoyPulse Honeypot Triggered Medium Investigating WS-LAP-011
ALR-00270 6h ago DecoyPulse Honeypot Triggered Medium Open SRV-APP-01
ALR-00003 10h ago DecoyPulse Honeypot Triggered Informational False Positive WS-PC-004
ALR-00234 17h ago Port Scan Detected Medium Investigating SRV-WEB-01