Port Scan Detected
Informational
Open
ALR-00458 · 2026-05-27T16:08:35Z
Description
Sequential port scan (1-1024) detected targeting SW-CORE-01 from external IP. Attack Surface Scanner identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:08:35
Event ingested by SOC365 Engine
16:08:38
EmilyAI triage started — correlation enrichment
16:08:44
EmilyAI confidence: 97% — escalated to human analyst
16:09:15
Alert assigned to analyst: EmilyAI (auto)
16:09:38
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00355 | 1h ago | Port Scan Detected | Medium | Open | SW-CORE-01 |
| ALR-00068 | 2h ago | Kerberoasting Attempt | High | Open | SW-CORE-01 |
| ALR-00159 | 3h ago | Suspicious PowerShell Execution | Low | Open | SW-CORE-01 |
| ALR-00196 | 4h ago | Brute Force SSH | High | Open | SW-CORE-01 |
| ALR-00368 | 6h ago | Kerberoasting Attempt | Informational | False Positive | SW-CORE-01 |