Lateral Movement Detected
Low
Escalated
ALR-00245 · 2026-04-12T01:03:18Z
Description
SOC365 Engine detected lateral movement from WS-LAP-011 to SRV-DC-01 using user 's.jones' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:03:18
Event ingested by SOC365 Engine
01:03:22
EmilyAI triage started — correlation enrichment
01:03:27
EmilyAI confidence: 82% — escalated to human analyst
01:03:47
Alert assigned to analyst: EmilyAI (auto)
01:06:15
Investigation started — querying SIEM and threat intelligence
01:10:51
Containment action taken — endpoint isolated
01:14:58
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00035 | 59m ago | Kerberoasting Attempt | Low | Escalated | WS-LAP-011 |
| ALR-00385 | 20h ago | Phishing Email Blocked | Low | Escalated | WS-LAP-011 |
| ALR-00426 | 20h ago | Port Scan Detected | Low | False Positive | WS-LAP-011 |
| ALR-00368 | 21h ago | Lateral Movement Detected | Low | False Positive | WS-LAP-011 |
| ALR-00384 | 23h ago | Lateral Movement Detected | Informational | Investigating | SRV-SQL-01 |