Credential Stuffing Attempt
Medium
Investigating
ALR-00032 · 2026-04-05T20:53:35Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by EmilyAI Triage.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
20:53:35
Event ingested by SOC365 Engine
20:53:39
EmilyAI triage started — correlation enrichment
20:53:47
EmilyAI confidence: 79% — escalated to human analyst
20:54:20
Alert assigned to analyst: Sarah Chen
20:54:45
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00200 | 2h ago | Credential Stuffing Attempt | Informational | Escalated | WS-PC-003 |
| ALR-00073 | 11h ago | Credential Stuffing Attempt | Medium | Investigating | WS-PC-002 |
| ALR-00118 | 17h ago | Kerberoasting Attempt | Informational | False Positive | WS-LAP-010 |
| ALR-00420 | 17h ago | Certificate Anomaly | Low | Resolved | WS-LAP-010 |
| ALR-00461 | 1d ago | Port Scan Detected | Low | Escalated | WS-LAP-010 |