Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:04:50 UTC

Lateral Movement Detected

Informational False Positive
ALR-00321 · 2026-05-21T20:25:48Z

Description

EmilyAI Triage detected lateral movement from FW-EDGE-01 to SRV-DC-01 using user 'a.wilson' credentials. SMB admin shares accessed.

Alert Metadata

Alert ID
ALR-00321
Timestamp
2026-05-21T20:25:48Z
Severity
Informational
Status
False Positive
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
FW-EDGE-01
User Account
a.wilson
Source IP
91.145.195.226
Destination IP
10.2.143.73
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1021.002
Reference
attack.mitre.org/techniques/T1021.002

Investigation Timeline

20:25:48 Event ingested by SOC365 Engine
20:25:51 EmilyAI triage started — correlation enrichment
20:25:54 EmilyAI confidence: 95% — escalated to human analyst
20:26:29 Alert assigned to analyst: EmilyAI (auto)
20:28:23 Investigation started — querying SIEM and threat intelligence
20:35:00 Containment action taken — endpoint isolated
20:36:27 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00368 2h ago Lateral Movement Detected Low False Positive WS-LAP-010
ALR-00296 3h ago Certificate Anomaly Low False Positive FW-EDGE-01
ALR-00365 10h ago Lateral Movement Detected Informational Open SRV-MAIL-01
ALR-00436 10h ago Privilege Escalation Attempt Medium Escalated FW-EDGE-01
ALR-00245 15h ago Privilege Escalation Attempt Low Escalated FW-EDGE-01