DecoyPulse Honeypot Triggered
Medium
Open
ALR-00274 · 2026-05-22T17:34:21Z
Description
DecoyPulse honeypot on WS-LAP-010 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
17:34:21
Event ingested by SOC365 Engine
17:34:22
EmilyAI triage started — correlation enrichment
17:34:35
EmilyAI confidence: 80% — escalated to human analyst
17:34:37
Alert assigned to analyst: Anika Patel
17:36:27
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00166 | 6h ago | DecoyPulse Honeypot Triggered | Medium | False Positive | SRV-DC-01 |
| ALR-00463 | 15h ago | DLP Policy Violation | Informational | Investigating | WS-LAP-010 |
| ALR-00388 | 20h ago | C2 Beacon Activity | Medium | False Positive | WS-LAP-010 |
| ALR-00297 | 21h ago | Rogue DHCP Server | Medium | Escalated | WS-LAP-010 |
| ALR-00343 | 1d ago | DecoyPulse Honeypot Triggered | Informational | Escalated | FW-EDGE-01 |