Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:53:44 UTC

Kerberoasting Attempt

Low Investigating
ALR-00068 · 2026-04-12T03:32:58Z

Description

Kerberoasting attack detected: user 'd.walker' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Cloud Connector.

Alert Metadata

Alert ID
ALR-00068
Timestamp
2026-04-12T03:32:58Z
Severity
Low
Status
Investigating
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-APP-01
User Account
d.walker
Source IP
103.249.216.16
Destination IP
10.1.182.57
Origin Country
BR Brazil

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

03:32:58 Event ingested by SOC365 Engine
03:33:00 EmilyAI triage started — correlation enrichment
03:33:11 EmilyAI confidence: 96% — escalated to human analyst
03:33:33 Alert assigned to analyst: EmilyAI (auto)
03:34:08 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00384 22m ago Port Scan Detected Informational Open SRV-APP-01
ALR-00171 4h ago DLP Policy Violation Medium Open SRV-APP-01
ALR-00195 5h ago Insider Threat Indicator Medium Investigating SRV-APP-01
ALR-00026 7h ago Kerberoasting Attempt Medium Escalated SRV-APP-01
ALR-00158 13h ago Shadow IT Discovery Informational False Positive SRV-APP-01