Lateral Movement Detected
Medium
Resolved
ALR-00365 · 2026-04-06T16:04:05Z
Description
DecoyPulse detected lateral movement from FW-EDGE-01 to SRV-DC-01 using user 'h.roberts' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:04:05
Event ingested by SOC365 Engine
16:04:06
EmilyAI triage started — correlation enrichment
16:04:16
EmilyAI confidence: 83% — escalated to human analyst
16:04:45
Alert assigned to analyst: Emma Richardson
16:05:23
Investigation started — querying SIEM and threat intelligence
16:13:40
Containment action taken — endpoint isolated
16:18:38
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00286 | 5h ago | Lateral Movement Detected | Medium | Open | WS-PC-006 |
| ALR-00357 | 5h ago | Lateral Movement Detected | Informational | Open | WS-LAP-012 |
| ALR-00453 | 7h ago | Data Exfiltration Attempt | Medium | Resolved | FW-EDGE-01 |
| ALR-00159 | 7h ago | Lateral Movement Detected | Medium | False Positive | WS-MAC-005 |
| ALR-00049 | 10h ago | Privilege Escalation Attempt | Medium | Open | FW-EDGE-01 |