Lateral Movement Detected
Low
Escalated
ALR-00440 · 2026-04-06T16:58:45Z
Description
EmilyAI Triage detected lateral movement from SRV-APP-01 to SRV-DC-01 using user 'f.hall' credentials. SMB admin shares accessed.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:58:45
Event ingested by SOC365 Engine
16:58:47
EmilyAI triage started — correlation enrichment
16:58:57
EmilyAI confidence: 89% — escalated to human analyst
16:59:30
Alert assigned to analyst: EmilyAI (auto)
17:00:23
Investigation started — querying SIEM and threat intelligence
17:07:42
Containment action taken — endpoint isolated
17:17:20
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00201 | 10h ago | Brute Force SSH | Informational | Investigating | SRV-APP-01 |
| ALR-00305 | 11h ago | C2 Beacon Activity | Low | Investigating | SRV-APP-01 |
| ALR-00142 | 14h ago | Lateral Movement Detected | Low | Investigating | SRV-DC-01 |
| ALR-00242 | 21h ago | Data Exfiltration Attempt | Medium | Resolved | SRV-APP-01 |
| ALR-00397 | 23h ago | Data Exfiltration Attempt | Informational | Resolved | SRV-APP-01 |