Privilege Escalation Attempt
Informational
Escalated
ALR-00205 · 2026-04-12T04:12:40Z
Description
User 'j.smith' on SW-CORE-01 attempted to escalate to SYSTEM via token manipulation. Email Gateway blocked the attempt.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:12:40
Event ingested by SOC365 Engine
04:12:45
EmilyAI triage started — correlation enrichment
04:12:46
EmilyAI confidence: 79% — escalated to human analyst
04:13:15
Alert assigned to analyst: EmilyAI (auto)
04:13:51
Investigation started — querying SIEM and threat intelligence
04:19:20
Containment action taken — endpoint isolated
04:27:21
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00019 | 8h ago | Privilege Escalation Attempt | Informational | Resolved | WS-PC-003 |
| ALR-00121 | 10h ago | Kerberoasting Attempt | Low | Open | SW-CORE-01 |
| ALR-00383 | 11h ago | Privilege Escalation Attempt | High | Escalated | WS-LAP-012 |
| ALR-00100 | 11h ago | Pass-the-Hash Detected | Informational | False Positive | SW-CORE-01 |
| ALR-00105 | 13h ago | Privilege Escalation Attempt | Low | False Positive | SRV-DC-01 |