Lateral Movement Detected
High
Investigating
ALR-00286 · 2026-05-23T02:11:00Z
Description
DecoyPulse detected lateral movement from WS-PC-006 to SRV-DC-01 using user 'k.brown' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:11:00
Event ingested by SOC365 Engine
02:11:03
EmilyAI triage started — correlation enrichment
02:11:05
EmilyAI confidence: 92% — escalated to human analyst
02:11:24
Alert assigned to analyst: Sarah Chen
02:13:18
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00405 | 2h ago | Brute Force SSH | Medium | Open | WS-PC-006 |
| ALR-00283 | 13h ago | Port Scan Detected | Medium | Resolved | WS-PC-006 |
| ALR-00033 | 22h ago | Unauthorised USB Device | High | Investigating | WS-PC-006 |
| ALR-00232 | 1d ago | Shadow IT Discovery | Medium | Escalated | WS-PC-006 |
| ALR-00289 | 1d ago | Pass-the-Hash Detected | Informational | Investigating | WS-PC-006 |