Pass-the-Hash Detected
Medium
Resolved
ALR-00341 · 2026-04-09T07:52:16Z
Description
Pass-the-Hash technique detected on SRV-MAIL-01. NTLM authentication from 'h.roberts' without standard Kerberos ticket. Dark Web Monitor flagged.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:52:16
Event ingested by SOC365 Engine
07:52:17
EmilyAI triage started — correlation enrichment
07:52:23
EmilyAI confidence: 88% — escalated to human analyst
07:52:54
Alert assigned to analyst: James Okonkwo
07:54:30
Investigation started — querying SIEM and threat intelligence
08:00:56
Containment action taken — endpoint isolated
08:05:21
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00023 | 4h ago | Pass-the-Hash Detected | Low | Escalated | WS-LAP-012 |
| ALR-00392 | 7h ago | Unusual Outbound Traffic | Low | Resolved | SRV-MAIL-01 |
| ALR-00296 | 11h ago | Pass-the-Hash Detected | Informational | Resolved | WS-LAP-010 |
| ALR-00100 | 11h ago | Pass-the-Hash Detected | Informational | False Positive | SW-CORE-01 |
| ALR-00216 | 23h ago | Tor Exit Node Connection | Low | False Positive | SRV-MAIL-01 |