Kerberoasting Attempt
Medium
Resolved
ALR-00001 · 2026-05-22T02:29:56Z
Description
Kerberoasting attack detected: user 'p.thomas' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Cloud Connector.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
02:29:56
Event ingested by SOC365 Engine
02:29:59
EmilyAI triage started — correlation enrichment
02:30:09
EmilyAI confidence: 82% — escalated to human analyst
02:30:31
Alert assigned to analyst: James Okonkwo
02:31:37
Investigation started — querying SIEM and threat intelligence
02:34:50
Containment action taken — endpoint isolated
02:41:54
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00493 | 1h ago | Lateral Movement Detected | Low | Escalated | AP-WIFI-03 |
| ALR-00487 | 3h ago | Kerberoasting Attempt | Medium | Escalated | WS-LAP-012 |
| ALR-00017 | 5h ago | Kerberoasting Attempt | Critical | Open | WS-LAP-010 |
| ALR-00494 | 6h ago | Failed MFA Challenge | Informational | False Positive | AP-WIFI-03 |
| ALR-00458 | 7h ago | Kerberoasting Attempt | Low | False Positive | SRV-WEB-01 |