Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:08:20 UTC

Pass-the-Hash Detected

Informational Investigating
ALR-00490 · 2026-05-25T07:31:34Z

Description

Pass-the-Hash technique detected on AP-WIFI-03. NTLM authentication from 'j.smith' without standard Kerberos ticket. EmilyAI Triage flagged.

Alert Metadata

Alert ID
ALR-00490
Timestamp
2026-05-25T07:31:34Z
Severity
Informational
Status
Investigating
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
AP-WIFI-03
User Account
j.smith
Source IP
91.39.195.73
Destination IP
10.1.30.12
Origin Country
DE Germany

MITRE ATT&CK Mapping

Tactic
Lateral Movement
Technique
T1550.002
Reference
attack.mitre.org/techniques/T1550.002

Investigation Timeline

07:31:34 Event ingested by SOC365 Engine
07:31:36 EmilyAI triage started — correlation enrichment
07:31:48 EmilyAI confidence: 84% — escalated to human analyst
07:32:16 Alert assigned to analyst: EmilyAI (auto)
07:33:55 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00433 3h ago Pass-the-Hash Detected Medium Investigating WS-LAP-010
ALR-00178 6h ago Kerberoasting Attempt Medium False Positive AP-WIFI-03
ALR-00013 11h ago Brute Force SSH Low Escalated AP-WIFI-03
ALR-00238 12h ago Suspicious Scheduled Task Low Resolved AP-WIFI-03
ALR-00374 19h ago Shadow IT Discovery Medium Resolved AP-WIFI-03