Kerberoasting Attempt
Medium
False Positive
ALR-00025 · 2026-05-26T20:43:19Z
Description
Kerberoasting attack detected: user 'f.hall' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by EmilyAI Triage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:43:19
Event ingested by SOC365 Engine
20:43:21
EmilyAI triage started — correlation enrichment
20:43:33
EmilyAI confidence: 88% — escalated to human analyst
20:44:01
Alert assigned to analyst: Emma Richardson
20:46:17
Investigation started — querying SIEM and threat intelligence
20:51:22
Containment action taken — endpoint isolated
20:58:17
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00362 | 6h ago | Port Scan Detected | Low | Investigating | SRV-APP-01 |
| ALR-00447 | 7h ago | Unauthorised USB Device | Low | Open | SRV-APP-01 |
| ALR-00280 | 9h ago | Lateral Movement Detected | Medium | Escalated | SRV-APP-01 |
| ALR-00335 | 17h ago | Kerberoasting Attempt | High | Investigating | WS-PC-003 |
| ALR-00250 | 1d ago | Kerberoasting Attempt | Informational | Open | WS-PC-004 |