Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 14:41:20 UTC

Kerberoasting Attempt

Medium Resolved
ALR-00001 · 2026-05-22T02:29:56Z

Description

Kerberoasting attack detected: user 'p.thomas' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Cloud Connector.

Alert Metadata

Alert ID
ALR-00001
Timestamp
2026-05-22T02:29:56Z
Severity
Medium
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
James Okonkwo

Endpoint Information

Hostname
AP-WIFI-03
User Account
p.thomas
Source IP
91.228.195.244
Destination IP
10.3.196.246
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

02:29:56 Event ingested by SOC365 Engine
02:29:59 EmilyAI triage started — correlation enrichment
02:30:09 EmilyAI confidence: 82% — escalated to human analyst
02:30:31 Alert assigned to analyst: James Okonkwo
02:31:37 Investigation started — querying SIEM and threat intelligence
02:34:50 Containment action taken — endpoint isolated
02:41:54 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00493 1h ago Lateral Movement Detected Low Escalated AP-WIFI-03
ALR-00487 3h ago Kerberoasting Attempt Medium Escalated WS-LAP-012
ALR-00017 5h ago Kerberoasting Attempt Critical Open WS-LAP-010
ALR-00494 6h ago Failed MFA Challenge Informational False Positive AP-WIFI-03
ALR-00458 7h ago Kerberoasting Attempt Low False Positive SRV-WEB-01