Lateral Movement Detected
High
Escalated
ALR-00256 · 2026-04-07T07:51:56Z
Description
Cloud Connector detected lateral movement from WS-LAP-012 to SRV-DC-01 using user 'l.johnson' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:51:56
Event ingested by SOC365 Engine
07:52:01
EmilyAI triage started — correlation enrichment
07:52:11
EmilyAI confidence: 78% — escalated to human analyst
07:52:37
Alert assigned to analyst: Emma Richardson
07:54:23
Investigation started — querying SIEM and threat intelligence
07:59:27
Containment action taken — endpoint isolated
08:03:17
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00153 | 17m ago | Lateral Movement Detected | Informational | Open | SRV-MAIL-01 |
| ALR-00493 | 2h ago | DLP Policy Violation | Informational | Investigating | WS-LAP-012 |
| ALR-00122 | 3h ago | Kerberoasting Attempt | Low | Resolved | WS-LAP-012 |
| ALR-00344 | 5h ago | Unauthorised USB Device | Low | Escalated | WS-LAP-012 |
| ALR-00290 | 15h ago | Privilege Escalation Attempt | Medium | Investigating | WS-LAP-012 |