Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 21:04:42 UTC

Lateral Movement Detected

Low False Positive
ALR-00194 · 2026-05-24T23:20:53Z

Description

Attack Surface Scanner detected lateral movement from SRV-WEB-01 to SRV-DC-01 using user 'r.davies' credentials. SMB admin shares accessed.

Alert Metadata

Alert ID
ALR-00194
Timestamp
2026-05-24T23:20:53Z
Severity
Low
Status
False Positive
Detection Source
Attack Surface Scanner
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-WEB-01
User Account
r.davies
Source IP
103.245.216.224
Destination IP
10.0.32.15
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1021.002
Reference
attack.mitre.org/techniques/T1021.002

Investigation Timeline

23:20:53 Event ingested by SOC365 Engine
23:20:57 EmilyAI triage started — correlation enrichment
23:20:59 EmilyAI confidence: 88% — escalated to human analyst
23:21:17 Alert assigned to analyst: EmilyAI (auto)
23:23:03 Investigation started — querying SIEM and threat intelligence
23:29:53 Containment action taken — endpoint isolated
23:33:22 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00437 10h ago Lateral Movement Detected Low Resolved WS-LAP-012
ALR-00235 10h ago Lateral Movement Detected Low Resolved WS-PC-002
ALR-00451 12h ago Lateral Movement Detected Critical Investigating VM-DEV-01
ALR-00200 1d ago DecoyPulse Honeypot Triggered Informational Escalated SRV-WEB-01
ALR-00272 1d ago Privilege Escalation Attempt Medium Resolved SRV-WEB-01