Medium Alerts
100 alerts
| ID | Timestamp | Alert Type | Severity | Status | Source | Hostname | User | Origin | Analyst | MITRE |
|---|---|---|---|---|---|---|---|---|---|---|
| ALR-00208 | 11m ago | Pass-the-Hash Detected | Medium | Open | Network IDS | WS-PC-004 | r.davies | NL Netherlands | Sarah Chen | T1550.002 |
| ALR-00267 | 43m ago | Certificate Anomaly | Medium | Escalated | Attack Surface Scanner | VM-DEV-01 | r.davies | VN Vietnam | Marcus Webb | T1553.004 |
| ALR-00112 | 2h ago | Kerberoasting Attempt | Medium | Investigating | Attack Surface Scanner | WS-LAP-010 | a.wilson | IN India | Marcus Webb | T1558.003 |
| ALR-00158 | 4h ago | Ransomware Behaviour Detected | Medium | Investigating | Network IDS | AP-WIFI-03 | h.roberts | VN Vietnam | Anika Patel | T1486 |
| ALR-00012 | 5h ago | C2 Beacon Activity | Medium | Open | Cloud Connector | WS-PC-006 | n.clark | GB United Kingdom | Anika Patel | T1071.001 |
| ALR-00176 | 7h ago | Data Exfiltration Attempt | Medium | Open | Network IDS | SRV-SQL-01 | e.evans | NG Nigeria | James Okonkwo | T1567.002 |
| ALR-00118 | 8h ago | Malware Signature Match | Medium | Open | Email Gateway | SRV-APP-01 | m.taylor | KP North Korea | Marcus Webb | T1204.002 |
| ALR-00219 | 11h ago | Ransomware Behaviour Detected | Medium | Escalated | Attack Surface Scanner | WS-LAP-012 | s.jones | VN Vietnam | Emma Richardson | T1486 |
| ALR-00258 | 14h ago | Insider Threat Indicator | Medium | False Positive | Endpoint Agent | SRV-FILE-01 | f.hall | US United States | Sarah Chen | T1119 |
| ALR-00182 | 18h ago | Pass-the-Hash Detected | Medium | Resolved | SOC365 Engine | WS-PC-006 | e.evans | NG Nigeria | Emma Richardson | T1550.002 |
| ALR-00086 | 1d ago | Certificate Anomaly | Medium | Escalated | SOC365 Engine | WS-PC-006 | d.walker | KP North Korea | Anika Patel | T1553.004 |
| ALR-00056 | 1d ago | Phishing Email Blocked | Medium | Escalated | Dark Web Monitor | SRV-FILE-01 | k.brown | UA Ukraine | James Okonkwo | T1566.001 |
| ALR-00194 | 1d ago | Port Scan Detected | Medium | Escalated | Endpoint Agent | WS-LAP-010 | k.brown | VN Vietnam | Anika Patel | T1046 |
| ALR-00235 | 1d ago | Certificate Anomaly | Medium | Open | Network IDS | SRV-DC-01 | h.roberts | CN China | Anika Patel | T1553.004 |
| ALR-00272 | 1d ago | Insider Threat Indicator | Medium | Escalated | Firewall | SRV-WEB-01 | e.evans | IR Iran | Sarah Chen | T1119 |
| ALR-00172 | 1d ago | Credential Stuffing Attempt | Medium | Open | SOC365 Engine | WS-PC-001 | l.johnson | CN China | Marcus Webb | T1110.004 |
| ALR-00275 | 1d ago | Lateral Movement Detected | Medium | Escalated | Network IDS | SRV-BACKUP-01 | s.jones | CN China | Anika Patel | T1021.002 |
| ALR-00080 | 1d ago | DLP Policy Violation | Medium | Escalated | DLP Module | WS-PC-002 | k.brown | US United States | Emma Richardson | T1048 |
| ALR-00156 | 1d ago | Data Exfiltration Attempt | Medium | False Positive | Endpoint Agent | SRV-BACKUP-01 | c.williams | UA Ukraine | James Okonkwo | T1567.002 |
| ALR-00098 | 1d ago | Lateral Movement Detected | Medium | Resolved | DLP Module | WS-PC-006 | d.walker | BR Brazil | James Okonkwo | T1021.002 |
| ALR-00246 | 1d ago | Certificate Anomaly | Medium | Escalated | DecoyPulse | FW-EDGE-01 | k.brown | UA Ukraine | Emma Richardson | T1553.004 |
| ALR-00064 | 1d ago | Malware Signature Match | Medium | False Positive | Email Gateway | SW-CORE-01 | n.clark | VN Vietnam | Sarah Chen | T1204.002 |
| ALR-00201 | 1d ago | Anomalous DNS Query | Medium | Escalated | DLP Module | SRV-FILE-01 | p.thomas | CN China | James Okonkwo | T1568.002 |
| ALR-00240 | 1d ago | Pass-the-Hash Detected | Medium | Open | Dark Web Monitor | SRV-FILE-01 | p.thomas | RU Russia | Marcus Webb | T1550.002 |
| ALR-00239 | 1d ago | DecoyPulse Honeypot Triggered | Medium | Escalated | Cloud Connector | VM-DEV-01 | m.taylor | GB United Kingdom | Emma Richardson | T1018 |
| ALR-00087 | 1d ago | Lateral Movement Detected | Medium | Open | Network IDS | WS-LAP-010 | s.jones | US United States | Anika Patel | T1021.002 |
| ALR-00054 | 1d ago | DLP Policy Violation | Medium | Escalated | Network IDS | SRV-DC-01 | h.roberts | NG Nigeria | James Okonkwo | T1048 |
| ALR-00192 | 2d ago | C2 Beacon Activity | Medium | Resolved | Cloud Connector | SRV-BACKUP-01 | c.williams | GB United Kingdom | Marcus Webb | T1071.001 |
| ALR-00210 | 2d ago | C2 Beacon Activity | Medium | Escalated | Network IDS | SW-CORE-01 | l.johnson | US United States | Emma Richardson | T1071.001 |
| ALR-00019 | 2d ago | Certificate Anomaly | Medium | Escalated | Endpoint Agent | SRV-APP-01 | r.davies | IN India | Marcus Webb | T1553.004 |
| ALR-00171 | 2d ago | DecoyPulse Honeypot Triggered | Medium | Resolved | Email Gateway | SRV-FILE-01 | system | DE Germany | Anika Patel | T1018 |
| ALR-00211 | 2d ago | Rogue DHCP Server | Medium | Resolved | SOC365 Engine | SRV-SQL-01 | n.clark | RU Russia | Marcus Webb | T1557.003 |
| ALR-00174 | 2d ago | Phishing Email Blocked | Medium | Open | Dark Web Monitor | SRV-DC-01 | system | RU Russia | Sarah Chen | T1566.001 |
| ALR-00143 | 2d ago | Rogue DHCP Server | Medium | Escalated | Network IDS | SRV-FILE-01 | j.smith | RU Russia | Anika Patel | T1557.003 |
| ALR-00053 | 2d ago | Credential Stuffing Attempt | Medium | Escalated | Dark Web Monitor | SRV-FILE-01 | f.hall | NL Netherlands | Anika Patel | T1110.004 |
| ALR-00046 | 2d ago | Lateral Movement Detected | Medium | Investigating | Network IDS | SRV-SQL-01 | h.roberts | US United States | James Okonkwo | T1021.002 |
| ALR-00026 | 2d ago | Suspicious PowerShell Execution | Medium | Resolved | DLP Module | WS-LAP-010 | k.brown | FR France | Sarah Chen | T1059.001 |
| ALR-00282 | 2d ago | Data Exfiltration Attempt | Medium | Open | Network IDS | WS-PC-002 | c.williams | CN China | Marcus Webb | T1567.002 |
| ALR-00212 | 2d ago | Pass-the-Hash Detected | Medium | Open | DLP Module | WS-LAP-012 | system | UA Ukraine | Anika Patel | T1550.002 |
| ALR-00268 | 2d ago | Phishing Email Blocked | Medium | Open | Dark Web Monitor | FW-EDGE-01 | n.clark | NL Netherlands | James Okonkwo | T1566.001 |
| ALR-00187 | 2d ago | Brute Force SSH | Medium | Open | Firewall | AP-WIFI-03 | c.williams | VN Vietnam | Emma Richardson | T1110.001 |
| ALR-00018 | 2d ago | Malware Signature Match | Medium | Investigating | SOC365 Engine | SRV-SQL-01 | n.clark | UA Ukraine | Marcus Webb | T1204.002 |
| ALR-00249 | 2d ago | Failed MFA Challenge | Medium | Open | Cloud Connector | WS-PC-001 | k.brown | UA Ukraine | Anika Patel | T1621 |
| ALR-00072 | 2d ago | Port Scan Detected | Medium | Investigating | Network IDS | WS-PC-003 | h.roberts | FR France | Sarah Chen | T1046 |
| ALR-00005 | 3d ago | Shadow IT Discovery | Medium | Open | Email Gateway | SRV-BACKUP-01 | r.davies | GB United Kingdom | Anika Patel | T1567 |
| ALR-00038 | 3d ago | Unauthorised USB Device | Medium | Investigating | EmilyAI Triage | SRV-BACKUP-01 | r.davies | FR France | James Okonkwo | T1091 |
| ALR-00111 | 3d ago | Brute Force SSH | Medium | Open | Dark Web Monitor | WS-PC-004 | p.thomas | KP North Korea | Marcus Webb | T1110.001 |
| ALR-00015 | 3d ago | Failed MFA Challenge | Medium | Open | EmilyAI Triage | SRV-BACKUP-01 | f.hall | VN Vietnam | Emma Richardson | T1621 |
| ALR-00241 | 3d ago | Ransomware Behaviour Detected | Medium | Investigating | Email Gateway | SRV-MAIL-01 | e.evans | UA Ukraine | James Okonkwo | T1486 |
| ALR-00108 | 3d ago | Kerberoasting Attempt | Medium | Resolved | Email Gateway | WS-LAP-011 | s.jones | RO Romania | Emma Richardson | T1558.003 |
| ALR-00039 | 3d ago | Credential Stuffing Attempt | Medium | Investigating | Attack Surface Scanner | FW-EDGE-01 | n.clark | NG Nigeria | Anika Patel | T1110.004 |
| ALR-00216 | 3d ago | Certificate Anomaly | Medium | Resolved | EmilyAI Triage | FW-EDGE-01 | s.jones | FR France | James Okonkwo | T1553.004 |
| ALR-00229 | 3d ago | DecoyPulse Honeypot Triggered | Medium | Escalated | Cloud Connector | WS-MAC-005 | m.taylor | RO Romania | Anika Patel | T1018 |
| ALR-00304 | 3d ago | Insider Threat Indicator | Medium | Investigating | SOC365 Engine | WS-PC-006 | e.evans | IN India | Anika Patel | T1119 |
| ALR-00024 | 3d ago | Failed MFA Challenge | Medium | False Positive | Email Gateway | WS-PC-003 | s.jones | CN China | Marcus Webb | T1621 |
| ALR-00059 | 3d ago | C2 Beacon Activity | Medium | False Positive | EmilyAI Triage | SRV-MAIL-01 | n.clark | BR Brazil | James Okonkwo | T1071.001 |
| ALR-00133 | 3d ago | Unauthorised USB Device | Medium | Resolved | DecoyPulse | WS-LAP-010 | f.hall | UA Ukraine | Sarah Chen | T1091 |
| ALR-00055 | 3d ago | Failed MFA Challenge | Medium | Escalated | Attack Surface Scanner | SRV-SQL-01 | d.walker | RU Russia | James Okonkwo | T1621 |
| ALR-00214 | 3d ago | Anomalous DNS Query | Medium | Open | Endpoint Agent | AP-WIFI-03 | k.brown | IN India | James Okonkwo | T1568.002 |
| ALR-00050 | 3d ago | Anomalous DNS Query | Medium | Resolved | Attack Surface Scanner | WS-LAP-010 | p.thomas | RO Romania | James Okonkwo | T1568.002 |
| ALR-00271 | 4d ago | Tor Exit Node Connection | Medium | Investigating | DLP Module | FW-EDGE-01 | n.clark | NG Nigeria | Sarah Chen | T1090.003 |
| ALR-00286 | 4d ago | Pass-the-Hash Detected | Medium | Open | Endpoint Agent | SRV-WEB-01 | c.williams | NG Nigeria | Sarah Chen | T1550.002 |
| ALR-00043 | 4d ago | DLP Policy Violation | Medium | False Positive | Dark Web Monitor | WS-PC-002 | l.johnson | US United States | Anika Patel | T1048 |
| ALR-00170 | 4d ago | Rogue DHCP Server | Medium | Resolved | Dark Web Monitor | SRV-BACKUP-01 | system | UA Ukraine | Marcus Webb | T1557.003 |
| ALR-00270 | 4d ago | Anomalous DNS Query | Medium | Investigating | SOC365 Engine | SRV-APP-01 | f.hall | FR France | Marcus Webb | T1568.002 |
| ALR-00162 | 4d ago | Rogue DHCP Server | Medium | Resolved | Dark Web Monitor | SRV-SQL-01 | h.roberts | KP North Korea | Anika Patel | T1557.003 |
| ALR-00122 | 4d ago | Unusual Outbound Traffic | Medium | Open | Attack Surface Scanner | WS-LAP-011 | m.taylor | IN India | Anika Patel | T1041 |
| ALR-00119 | 4d ago | Suspicious Scheduled Task | Medium | Open | DecoyPulse | WS-LAP-011 | l.johnson | NG Nigeria | Anika Patel | T1053.005 |
| ALR-00082 | 4d ago | Certificate Anomaly | Medium | Resolved | Firewall | VM-DEV-01 | h.roberts | RU Russia | Marcus Webb | T1553.004 |
| ALR-00009 | 4d ago | Ransomware Behaviour Detected | Medium | Open | Firewall | SRV-APP-01 | a.wilson | GB United Kingdom | Sarah Chen | T1486 |
| ALR-00104 | 4d ago | Unusual Outbound Traffic | Medium | Open | Endpoint Agent | WS-MAC-005 | m.taylor | DE Germany | Sarah Chen | T1041 |
| ALR-00141 | 4d ago | Privilege Escalation Attempt | Medium | Open | EmilyAI Triage | WS-PC-002 | h.roberts | VN Vietnam | Anika Patel | T1134 |
| ALR-00033 | 4d ago | Kerberoasting Attempt | Medium | Escalated | EmilyAI Triage | SRV-WEB-01 | k.brown | IR Iran | Anika Patel | T1558.003 |
| ALR-00075 | 4d ago | Lateral Movement Detected | Medium | Open | Cloud Connector | FW-EDGE-01 | c.williams | CN China | Emma Richardson | T1021.002 |
| ALR-00217 | 4d ago | Privilege Escalation Attempt | Medium | False Positive | Cloud Connector | WS-PC-006 | e.evans | RU Russia | Sarah Chen | T1134 |
| ALR-00296 | 5d ago | Unauthorised USB Device | Medium | Open | EmilyAI Triage | SW-CORE-01 | h.roberts | KP North Korea | Marcus Webb | T1091 |
| ALR-00288 | 5d ago | Data Exfiltration Attempt | Medium | False Positive | Endpoint Agent | WS-LAP-010 | j.smith | KP North Korea | James Okonkwo | T1567.002 |
| ALR-00237 | 5d ago | Anomalous DNS Query | Medium | Investigating | Endpoint Agent | FW-EDGE-01 | n.clark | IN India | Sarah Chen | T1568.002 |
| ALR-00151 | 5d ago | Unauthorised USB Device | Medium | Escalated | Cloud Connector | FW-EDGE-01 | e.evans | VN Vietnam | James Okonkwo | T1091 |
| ALR-00004 | 5d ago | Brute Force SSH | Medium | False Positive | DLP Module | WS-PC-001 | system | US United States | Sarah Chen | T1110.001 |
| ALR-00081 | 5d ago | Unusual Outbound Traffic | Medium | Investigating | DLP Module | VM-DEV-01 | f.hall | UA Ukraine | Anika Patel | T1041 |
| ALR-00197 | 5d ago | DLP Policy Violation | Medium | Resolved | EmilyAI Triage | WS-MAC-005 | f.hall | CN China | Sarah Chen | T1048 |
| ALR-00041 | 5d ago | Port Scan Detected | Medium | False Positive | SOC365 Engine | FW-EDGE-01 | r.davies | RO Romania | James Okonkwo | T1046 |
| ALR-00209 | 5d ago | Pass-the-Hash Detected | Medium | Investigating | Dark Web Monitor | WS-PC-006 | d.walker | IR Iran | Marcus Webb | T1550.002 |
| ALR-00250 | 5d ago | Credential Stuffing Attempt | Medium | False Positive | Cloud Connector | WS-LAP-011 | k.brown | UA Ukraine | Emma Richardson | T1110.004 |
| ALR-00179 | 5d ago | Privilege Escalation Attempt | Medium | Escalated | DLP Module | WS-PC-002 | r.davies | UA Ukraine | Marcus Webb | T1134 |
| ALR-00088 | 5d ago | Unauthorised USB Device | Medium | Investigating | Cloud Connector | SRV-MAIL-01 | c.williams | GB United Kingdom | Emma Richardson | T1091 |
| ALR-00131 | 6d ago | Shadow IT Discovery | Medium | Escalated | EmilyAI Triage | WS-LAP-011 | r.davies | RO Romania | Anika Patel | T1567 |
| ALR-00204 | 6d ago | Anomalous DNS Query | Medium | Investigating | Endpoint Agent | AP-WIFI-03 | d.walker | VN Vietnam | Sarah Chen | T1568.002 |
| ALR-00051 | 6d ago | Failed MFA Challenge | Medium | Resolved | Cloud Connector | SRV-SQL-01 | system | GB United Kingdom | James Okonkwo | T1621 |
| ALR-00107 | 6d ago | Ransomware Behaviour Detected | Medium | False Positive | SOC365 Engine | WS-PC-006 | e.evans | DE Germany | Sarah Chen | T1486 |
| ALR-00142 | 6d ago | Rogue DHCP Server | Medium | Investigating | Firewall | VM-DEV-01 | r.davies | IR Iran | Sarah Chen | T1557.003 |
| ALR-00207 | 6d ago | Insider Threat Indicator | Medium | False Positive | DecoyPulse | SRV-BACKUP-01 | m.taylor | RO Romania | Marcus Webb | T1119 |
| ALR-00253 | 6d ago | Unauthorised USB Device | Medium | Escalated | Dark Web Monitor | SRV-FILE-01 | system | FR France | Marcus Webb | T1091 |
| ALR-00257 | 6d ago | Credential Stuffing Attempt | Medium | Escalated | EmilyAI Triage | AP-WIFI-03 | h.roberts | GB United Kingdom | James Okonkwo | T1110.004 |
| ALR-00149 | 6d ago | Ransomware Behaviour Detected | Medium | Open | Attack Surface Scanner | WS-LAP-010 | k.brown | CN China | Anika Patel | T1486 |
| ALR-00052 | 6d ago | Rogue DHCP Server | Medium | False Positive | EmilyAI Triage | VM-DEV-01 | r.davies | NG Nigeria | Anika Patel | T1557.003 |
| ALR-00034 | 6d ago | Credential Stuffing Attempt | Medium | False Positive | SOC365 Engine | WS-LAP-011 | j.smith | NL Netherlands | Emma Richardson | T1110.004 |
| ALR-00127 | 6d ago | Suspicious PowerShell Execution | Medium | Resolved | Firewall | WS-LAP-010 | h.roberts | US United States | Marcus Webb | T1059.001 |
| ALR-00181 | 6d ago | C2 Beacon Activity | Medium | Investigating | Dark Web Monitor | AP-WIFI-03 | e.evans | FR France | James Okonkwo | T1071.001 |