Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:08:16 UTC

Privilege Escalation Attempt

Low Escalated
ALR-00474 · 2026-05-20T21:58:53Z

Description

User 'h.roberts' on SRV-APP-01 attempted to escalate to SYSTEM via token manipulation. Network IDS blocked the attempt.

Alert Metadata

Alert ID
ALR-00474
Timestamp
2026-05-20T21:58:53Z
Severity
Low
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-APP-01
User Account
h.roberts
Source IP
185.147.220.167
Destination IP
10.3.87.206
Origin Country
IN India

MITRE ATT&CK Mapping

Tactic
Privilege Escalation
Technique
T1134
Reference
attack.mitre.org/techniques/T1134

Investigation Timeline

21:58:53 Event ingested by SOC365 Engine
21:58:58 EmilyAI triage started — correlation enrichment
21:58:58 EmilyAI confidence: 79% — escalated to human analyst
21:59:21 Alert assigned to analyst: EmilyAI (auto)
22:00:59 Investigation started — querying SIEM and threat intelligence
22:07:05 Containment action taken — endpoint isolated
22:12:26 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00225 56m ago Privilege Escalation Attempt Informational Open AP-WIFI-03
ALR-00451 3h ago Ransomware Behaviour Detected Informational Open SRV-APP-01
ALR-00014 10h ago Unusual Outbound Traffic Critical Investigating SRV-APP-01
ALR-00164 11h ago Lateral Movement Detected Medium Investigating SRV-APP-01
ALR-00172 12h ago Pass-the-Hash Detected Medium Resolved SRV-APP-01