Lateral Movement Detected
Critical
Escalated
ALR-00166 · 2026-05-26T10:44:50Z
Description
DecoyPulse detected lateral movement from WS-PC-002 to SRV-DC-01 using user 's.jones' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
10:44:50
Event ingested by SOC365 Engine
10:44:55
EmilyAI triage started — correlation enrichment
10:44:55
EmilyAI confidence: 94% — escalated to human analyst
10:45:25
Alert assigned to analyst: James Okonkwo
10:47:17
Investigation started — querying SIEM and threat intelligence
10:51:00
Containment action taken — endpoint isolated
11:02:36
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00302 | 16h ago | Lateral Movement Detected | Low | False Positive | WS-PC-006 |
| ALR-00187 | 20h ago | Privilege Escalation Attempt | Critical | Investigating | WS-PC-002 |
| ALR-00006 | 1d ago | Lateral Movement Detected | Low | False Positive | SRV-SQL-01 |
| ALR-00128 | 1d ago | Credential Stuffing Attempt | Low | False Positive | WS-PC-002 |
| ALR-00141 | 1d ago | Lateral Movement Detected | Low | Investigating | WS-PC-006 |