Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:09:57 UTC

Lateral Movement Detected

Low Open
ALR-00182 · 2026-05-22T15:47:21Z

Description

SOC365 Engine detected lateral movement from SRV-MAIL-01 to SRV-DC-01 using user 'h.roberts' credentials. SMB admin shares accessed.

Alert Metadata

Alert ID
ALR-00182
Timestamp
2026-05-22T15:47:21Z
Severity
Low
Status
Open
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-MAIL-01
User Account
h.roberts
Source IP
45.221.148.229
Destination IP
10.3.190.145
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1021.002
Reference
attack.mitre.org/techniques/T1021.002

Investigation Timeline

15:47:21 Event ingested by SOC365 Engine
15:47:22 EmilyAI triage started — correlation enrichment
15:47:26 EmilyAI confidence: 94% — escalated to human analyst
15:47:55 Alert assigned to analyst: EmilyAI (auto)
15:49:04 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00412 46m ago DLP Policy Violation Low Open SRV-MAIL-01
ALR-00331 3h ago Lateral Movement Detected Informational Investigating SRV-MAIL-01
ALR-00333 11h ago Phishing Email Blocked Medium Open SRV-MAIL-01
ALR-00079 13h ago Lateral Movement Detected Informational Open WS-PC-002
ALR-00322 17h ago Port Scan Detected Low Open SRV-MAIL-01