DecoyPulse Honeypot Triggered
Informational
Escalated
ALR-00437 · 2026-04-07T11:46:14Z
Description
DecoyPulse honeypot on SRV-MAIL-01 triggered by internal IP. Credentials for decoy admin account used. Zero false positive — investigating.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:46:14
Event ingested by SOC365 Engine
11:46:18
EmilyAI triage started — correlation enrichment
11:46:26
EmilyAI confidence: 87% — escalated to human analyst
11:46:29
Alert assigned to analyst: EmilyAI (auto)
11:49:05
Investigation started — querying SIEM and threat intelligence
11:53:30
Containment action taken — endpoint isolated
11:58:13
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00424 | 1h ago | DecoyPulse Honeypot Triggered | Low | Resolved | SRV-WEB-01 |
| ALR-00074 | 6h ago | DecoyPulse Honeypot Triggered | High | Escalated | WS-LAP-010 |
| ALR-00056 | 7h ago | DecoyPulse Honeypot Triggered | Low | Investigating | VM-DEV-01 |
| ALR-00078 | 11h ago | DecoyPulse Honeypot Triggered | Informational | Investigating | SRV-APP-01 |
| ALR-00175 | 14h ago | Malware Signature Match | Low | Resolved | SRV-MAIL-01 |