Pass-the-Hash Detected
Medium
Investigating
ALR-00400 · 2026-05-21T07:59:53Z
Description
Pass-the-Hash technique detected on WS-PC-003. NTLM authentication from 'p.thomas' without standard Kerberos ticket. Cloud Connector flagged.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:59:53
Event ingested by SOC365 Engine
07:59:57
EmilyAI triage started — correlation enrichment
08:00:02
EmilyAI confidence: 95% — escalated to human analyst
08:00:10
Alert assigned to analyst: Sarah Chen
08:02:17
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00433 | 3h ago | Pass-the-Hash Detected | Medium | Investigating | WS-LAP-010 |
| ALR-00157 | 19h ago | Certificate Anomaly | Medium | Escalated | WS-PC-003 |
| ALR-00394 | 21h ago | Malware Signature Match | Low | Investigating | WS-PC-003 |
| ALR-00031 | 23h ago | Pass-the-Hash Detected | Low | False Positive | WS-LAP-012 |
| ALR-00164 | 1d ago | Pass-the-Hash Detected | Informational | False Positive | WS-MAC-005 |