Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:21:31 UTC

Privilege Escalation Attempt

Medium Open
ALR-00181 · 2026-04-12T10:50:42Z

Description

User 'system' on SRV-APP-01 attempted to escalate to SYSTEM via token manipulation. Firewall blocked the attempt.

Alert Metadata

Alert ID
ALR-00181
Timestamp
2026-04-12T10:50:42Z
Severity
Medium
Status
Open
Detection Source
Firewall
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
SRV-APP-01
User Account
system
Source IP
45.208.148.152
Destination IP
10.2.61.28
Origin Country
IR Iran

MITRE ATT&CK Mapping

Tactic
Privilege Escalation
Technique
T1134
Reference
attack.mitre.org/techniques/T1134

Investigation Timeline

10:50:42 Event ingested by SOC365 Engine
10:50:46 EmilyAI triage started — correlation enrichment
10:50:52 EmilyAI confidence: 79% — escalated to human analyst
10:51:05 Alert assigned to analyst: Emma Richardson
10:53:33 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00290 48m ago Port Scan Detected Informational Resolved SRV-APP-01
ALR-00078 11h ago DecoyPulse Honeypot Triggered Informational Investigating SRV-APP-01
ALR-00170 12h ago Unusual Outbound Traffic Medium Escalated SRV-APP-01
ALR-00415 17h ago Privilege Escalation Attempt Low Open WS-LAP-010
ALR-00145 17h ago Pass-the-Hash Detected Medium Escalated SRV-APP-01