Lateral Movement Detected
High
Escalated
ALR-00383 · 2026-04-11T21:38:21Z
Description
EmilyAI Triage detected lateral movement from SRV-WEB-01 to SRV-DC-01 using user 'n.clark' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:38:21
Event ingested by SOC365 Engine
21:38:24
EmilyAI triage started — correlation enrichment
21:38:35
EmilyAI confidence: 93% — escalated to human analyst
21:38:40
Alert assigned to analyst: Marcus Webb
21:40:08
Investigation started — querying SIEM and threat intelligence
21:43:03
Containment action taken — endpoint isolated
21:52:36
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00007 | 2h ago | DecoyPulse Honeypot Triggered | Low | Escalated | SRV-WEB-01 |
| ALR-00074 | 5h ago | Brute Force SSH | Informational | Investigating | SRV-WEB-01 |
| ALR-00479 | 10h ago | Tor Exit Node Connection | Medium | Escalated | SRV-WEB-01 |
| ALR-00234 | 16h ago | Lateral Movement Detected | Low | Investigating | WS-PC-006 |
| ALR-00307 | 16h ago | Ransomware Behaviour Detected | Low | False Positive | SRV-WEB-01 |