Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:24:13 UTC

Lateral Movement Detected

Informational False Positive
ALR-00233 · 2026-04-12T02:42:15Z

Description

Firewall detected lateral movement from WS-PC-001 to SRV-DC-01 using user 'h.roberts' credentials. SMB admin shares accessed.

Alert Metadata

Alert ID
ALR-00233
Timestamp
2026-04-12T02:42:15Z
Severity
Informational
Status
False Positive
Detection Source
Firewall
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-001
User Account
h.roberts
Source IP
185.135.220.241
Destination IP
10.0.63.22
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1021.002
Reference
attack.mitre.org/techniques/T1021.002

Investigation Timeline

02:42:15 Event ingested by SOC365 Engine
02:42:18 EmilyAI triage started — correlation enrichment
02:42:22 EmilyAI confidence: 90% — escalated to human analyst
02:42:59 Alert assigned to analyst: EmilyAI (auto)
02:44:55 Investigation started — querying SIEM and threat intelligence
02:45:22 Containment action taken — endpoint isolated
02:59:35 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00171 4h ago Lateral Movement Detected Medium Open SRV-MAIL-01
ALR-00487 5h ago DecoyPulse Honeypot Triggered Informational Resolved WS-PC-001
ALR-00316 9h ago Lateral Movement Detected High Open SRV-MAIL-01
ALR-00263 14h ago Lateral Movement Detected Medium Investigating WS-PC-001
ALR-00060 16h ago Phishing Email Blocked Medium False Positive WS-PC-001