Lateral Movement Detected
Low
False Positive
ALR-00194 · 2026-05-24T23:20:53Z
Description
Attack Surface Scanner detected lateral movement from SRV-WEB-01 to SRV-DC-01 using user 'r.davies' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:20:53
Event ingested by SOC365 Engine
23:20:57
EmilyAI triage started — correlation enrichment
23:20:59
EmilyAI confidence: 88% — escalated to human analyst
23:21:17
Alert assigned to analyst: EmilyAI (auto)
23:23:03
Investigation started — querying SIEM and threat intelligence
23:29:53
Containment action taken — endpoint isolated
23:33:22
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00437 | 10h ago | Lateral Movement Detected | Low | Resolved | WS-LAP-012 |
| ALR-00235 | 10h ago | Lateral Movement Detected | Low | Resolved | WS-PC-002 |
| ALR-00451 | 12h ago | Lateral Movement Detected | Critical | Investigating | VM-DEV-01 |
| ALR-00200 | 1d ago | DecoyPulse Honeypot Triggered | Informational | Escalated | SRV-WEB-01 |
| ALR-00272 | 1d ago | Privilege Escalation Attempt | Medium | Resolved | SRV-WEB-01 |