Failed MFA Challenge
Medium
Resolved
ALR-00061 · 2026-05-27T13:08:15Z
Description
Multiple failed MFA challenges for user 'system' — 12 push notifications in 3 minutes suggesting MFA fatigue attack. SOC365 Engine locked account.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
13:08:15
Event ingested by SOC365 Engine
13:08:18
EmilyAI triage started — correlation enrichment
13:08:20
EmilyAI confidence: 82% — escalated to human analyst
13:08:58
Alert assigned to analyst: James Okonkwo
13:10:15
Investigation started — querying SIEM and threat intelligence
13:11:46
Containment action taken — endpoint isolated
13:27:49
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00341 | 1h ago | Kerberoasting Attempt | Medium | Escalated | WS-PC-001 |
| ALR-00073 | 3h ago | Kerberoasting Attempt | Informational | Open | WS-PC-001 |
| ALR-00413 | 4h ago | Ransomware Behaviour Detected | Medium | Investigating | WS-PC-001 |
| ALR-00121 | 12h ago | Rogue DHCP Server | Medium | Investigating | WS-PC-001 |
| ALR-00162 | 15h ago | Failed MFA Challenge | Medium | Resolved | SW-CORE-01 |