Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:57:21 UTC

Failed MFA Challenge

Informational Investigating
ALR-00050 · 2026-04-07T23:40:32Z

Description

Multiple failed MFA challenges for user 's.jones' — 12 push notifications in 3 minutes suggesting MFA fatigue attack. EmilyAI Triage locked account.

Alert Metadata

Alert ID
ALR-00050
Timestamp
2026-04-07T23:40:32Z
Severity
Informational
Status
Investigating
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-001
User Account
s.jones
Source IP
45.184.148.38
Destination IP
10.3.151.46
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1621
Reference
attack.mitre.org/techniques/T1621

Investigation Timeline

23:40:32 Event ingested by SOC365 Engine
23:40:36 EmilyAI triage started — correlation enrichment
23:40:38 EmilyAI confidence: 92% — escalated to human analyst
23:41:04 Alert assigned to analyst: EmilyAI (auto)
23:41:36 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00363 1h ago Ransomware Behaviour Detected High Escalated WS-PC-001
ALR-00406 2h ago Failed MFA Challenge Informational False Positive SRV-DC-01
ALR-00401 4h ago Tor Exit Node Connection High Open WS-PC-001
ALR-00324 5h ago DecoyPulse Honeypot Triggered Low Open WS-PC-001
ALR-00196 17h ago Phishing Email Blocked Medium Resolved WS-PC-001