Port Scan Detected
High
Open
ALR-00379 · 2026-04-06T05:38:18Z
Description
Sequential port scan (1-1024) detected targeting SRV-BACKUP-01 from external IP. DLP Module identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
05:38:18
Event ingested by SOC365 Engine
05:38:21
EmilyAI triage started — correlation enrichment
05:38:29
EmilyAI confidence: 94% — escalated to human analyst
05:38:46
Alert assigned to analyst: Marcus Webb
05:39:12
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00389 | 10h ago | Anomalous DNS Query | Low | False Positive | SRV-BACKUP-01 |
| ALR-00203 | 18h ago | Tor Exit Node Connection | Informational | Investigating | SRV-BACKUP-01 |
| ALR-00219 | 1d ago | Shadow IT Discovery | Medium | Open | SRV-BACKUP-01 |
| ALR-00300 | 1d ago | Port Scan Detected | Medium | Escalated | WS-PC-004 |
| ALR-00155 | 1d ago | Unauthorised USB Device | Low | False Positive | SRV-BACKUP-01 |