Port Scan Detected
Medium
False Positive
ALR-00494 · 2026-05-25T03:46:36Z
Description
Sequential port scan (1-1024) detected targeting WS-MAC-005 from external IP. DecoyPulse identified SYN scan pattern.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
03:46:36
Event ingested by SOC365 Engine
03:46:38
EmilyAI triage started — correlation enrichment
03:46:51
EmilyAI confidence: 89% — escalated to human analyst
03:47:00
Alert assigned to analyst: Anika Patel
03:47:33
Investigation started — querying SIEM and threat intelligence
03:53:58
Containment action taken — endpoint isolated
04:02:25
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00163 | 1h ago | Port Scan Detected | Low | Open | VM-DEV-01 |
| ALR-00055 | 7h ago | Port Scan Detected | Medium | Open | WS-PC-003 |
| ALR-00495 | 7h ago | Port Scan Detected | Informational | False Positive | WS-LAP-012 |
| ALR-00249 | 11h ago | Data Exfiltration Attempt | Critical | Open | WS-MAC-005 |
| ALR-00386 | 12h ago | Port Scan Detected | Low | Resolved | WS-PC-002 |