DecoyPulse Honeypot Triggered
Low
Resolved
ALR-00381 · 2026-05-23T22:07:58Z
Description
DecoyPulse honeypot on SW-CORE-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:07:58
Event ingested by SOC365 Engine
22:07:59
EmilyAI triage started — correlation enrichment
22:08:13
EmilyAI confidence: 93% — escalated to human analyst
22:08:16
Alert assigned to analyst: EmilyAI (auto)
22:10:27
Investigation started — querying SIEM and threat intelligence
22:17:26
Containment action taken — endpoint isolated
22:21:31
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00169 | 49m ago | DecoyPulse Honeypot Triggered | Medium | Open | WS-LAP-012 |
| ALR-00240 | 3h ago | DecoyPulse Honeypot Triggered | Low | Open | WS-PC-006 |
| ALR-00128 | 3h ago | DecoyPulse Honeypot Triggered | Low | Resolved | WS-PC-006 |
| ALR-00344 | 5h ago | Malware Signature Match | Low | Investigating | SW-CORE-01 |
| ALR-00338 | 7h ago | Ransomware Behaviour Detected | Low | Open | SW-CORE-01 |