Lateral Movement Detected
Critical
Investigating
ALR-00166 · 2026-04-11T13:15:13Z
Description
Email Gateway detected lateral movement from VM-DEV-01 to SRV-DC-01 using user 'm.taylor' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
13:15:13
Event ingested by SOC365 Engine
13:15:18
EmilyAI triage started — correlation enrichment
13:15:23
EmilyAI confidence: 88% — escalated to human analyst
13:15:37
Alert assigned to analyst: Anika Patel
13:16:24
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00030 | 2h ago | Lateral Movement Detected | Medium | Open | WS-LAP-010 |
| ALR-00202 | 4h ago | Lateral Movement Detected | Low | Open | SRV-BACKUP-01 |
| ALR-00253 | 10h ago | Kerberoasting Attempt | Low | Resolved | VM-DEV-01 |
| ALR-00350 | 14h ago | Tor Exit Node Connection | Medium | Escalated | VM-DEV-01 |
| ALR-00471 | 21h ago | Port Scan Detected | Low | Escalated | VM-DEV-01 |