Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:02:51 UTC

Privilege Escalation Attempt

Low Escalated
ALR-00200 · 2026-05-27T03:09:29Z

Description

User 'system' on SRV-WEB-01 attempted to escalate to SYSTEM via token manipulation. Network IDS blocked the attempt.

Alert Metadata

Alert ID
ALR-00200
Timestamp
2026-05-27T03:09:29Z
Severity
Low
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-WEB-01
User Account
system
Source IP
103.225.216.169
Destination IP
10.3.135.233
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Privilege Escalation
Technique
T1134
Reference
attack.mitre.org/techniques/T1134

Investigation Timeline

03:09:29 Event ingested by SOC365 Engine
03:09:32 EmilyAI triage started — correlation enrichment
03:09:34 EmilyAI confidence: 82% — escalated to human analyst
03:09:54 Alert assigned to analyst: EmilyAI (auto)
03:10:17 Investigation started — querying SIEM and threat intelligence
03:14:36 Containment action taken — endpoint isolated
03:26:30 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00406 11h ago Unusual Outbound Traffic Low False Positive SRV-WEB-01
ALR-00274 11h ago Suspicious PowerShell Execution Informational False Positive SRV-WEB-01
ALR-00032 1d ago Failed MFA Challenge High Open SRV-WEB-01
ALR-00078 1d ago Credential Stuffing Attempt Low Resolved SRV-WEB-01
ALR-00422 1d ago Privilege Escalation Attempt Informational Resolved SRV-FILE-01