DecoyPulse Honeypot Triggered
Informational
Open
ALR-00281 · 2026-05-25T05:19:47Z
Description
DecoyPulse honeypot on WS-PC-006 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
05:19:47
Event ingested by SOC365 Engine
05:19:48
EmilyAI triage started — correlation enrichment
05:20:02
EmilyAI confidence: 97% — escalated to human analyst
05:20:32
Alert assigned to analyst: EmilyAI (auto)
05:21:28
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00447 | 1h ago | DecoyPulse Honeypot Triggered | Informational | False Positive | SRV-BACKUP-01 |
| ALR-00053 | 1h ago | C2 Beacon Activity | Low | Resolved | WS-PC-006 |
| ALR-00056 | 6h ago | Insider Threat Indicator | High | Escalated | WS-PC-006 |
| ALR-00033 | 9h ago | C2 Beacon Activity | High | Escalated | WS-PC-006 |
| ALR-00069 | 13h ago | Tor Exit Node Connection | Low | Open | WS-PC-006 |