Credential Stuffing Attempt
Medium
Escalated
ALR-00022 · 2026-04-05T21:50:20Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by SOC365 Engine.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
21:50:20
Event ingested by SOC365 Engine
21:50:22
EmilyAI triage started — correlation enrichment
21:50:33
EmilyAI confidence: 96% — escalated to human analyst
21:50:38
Alert assigned to analyst: Sarah Chen
21:51:58
Investigation started — querying SIEM and threat intelligence
21:54:48
Containment action taken — endpoint isolated
22:09:39
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00029 | 1h ago | Malware Signature Match | Medium | Resolved | WS-MAC-005 |
| ALR-00341 | 2h ago | Phishing Email Blocked | Low | Resolved | WS-MAC-005 |
| ALR-00027 | 12h ago | Credential Stuffing Attempt | Low | False Positive | WS-MAC-005 |
| ALR-00357 | 14h ago | Failed MFA Challenge | Medium | Resolved | WS-MAC-005 |
| ALR-00500 | 18h ago | Rogue DHCP Server | Informational | Open | WS-MAC-005 |