Failed MFA Challenge
Medium
Investigating
ALR-00048 · 2026-04-07T18:33:44Z
Description
Multiple failed MFA challenges for user 'r.davies' — 12 push notifications in 3 minutes suggesting MFA fatigue attack. Network IDS locked account.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
18:33:44
Event ingested by SOC365 Engine
18:33:48
EmilyAI triage started — correlation enrichment
18:33:53
EmilyAI confidence: 94% — escalated to human analyst
18:34:10
Alert assigned to analyst: Anika Patel
18:36:12
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00139 | 3m ago | Privilege Escalation Attempt | Informational | Open | WS-PC-002 |
| ALR-00227 | 2h ago | Port Scan Detected | High | Open | WS-PC-002 |
| ALR-00286 | 4h ago | Failed MFA Challenge | Low | Open | SRV-WEB-01 |
| ALR-00357 | 14h ago | Failed MFA Challenge | Medium | Resolved | WS-MAC-005 |
| ALR-00298 | 1d ago | Data Exfiltration Attempt | Informational | Open | WS-PC-002 |