Port Scan Detected
Medium
Resolved
ALR-00381 · 2026-04-11T07:28:33Z
Description
Sequential port scan (1-1024) detected targeting SRV-SQL-01 from external IP. Network IDS identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:28:33
Event ingested by SOC365 Engine
07:28:36
EmilyAI triage started — correlation enrichment
07:28:42
EmilyAI confidence: 80% — escalated to human analyst
07:28:55
Alert assigned to analyst: Sarah Chen
07:29:27
Investigation started — querying SIEM and threat intelligence
07:37:10
Containment action taken — endpoint isolated
07:44:03
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00232 | 4h ago | Insider Threat Indicator | Medium | Escalated | SRV-SQL-01 |
| ALR-00170 | 8h ago | Pass-the-Hash Detected | Medium | Escalated | SRV-SQL-01 |
| ALR-00465 | 8h ago | Shadow IT Discovery | Medium | Escalated | SRV-SQL-01 |
| ALR-00275 | 9h ago | Port Scan Detected | Medium | Resolved | WS-PC-002 |
| ALR-00423 | 20h ago | Data Exfiltration Attempt | Medium | Open | SRV-SQL-01 |