Pass-the-Hash Detected
Informational
Open
ALR-00463 · 2026-04-07T22:28:41Z
Description
Pass-the-Hash technique detected on WS-LAP-010. NTLM authentication from 'j.smith' without standard Kerberos ticket. Firewall flagged.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:28:41
Event ingested by SOC365 Engine
22:28:46
EmilyAI triage started — correlation enrichment
22:28:47
EmilyAI confidence: 96% — escalated to human analyst
22:29:10
Alert assigned to analyst: EmilyAI (auto)
22:30:07
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00423 | 27m ago | Pass-the-Hash Detected | High | Open | WS-LAP-011 |
| ALR-00103 | 5h ago | Pass-the-Hash Detected | Informational | Resolved | WS-PC-003 |
| ALR-00495 | 6h ago | Pass-the-Hash Detected | Critical | Investigating | WS-PC-006 |
| ALR-00189 | 6h ago | Kerberoasting Attempt | Low | Open | WS-LAP-010 |
| ALR-00046 | 10h ago | Phishing Email Blocked | Informational | Resolved | WS-LAP-010 |