Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:26:20 UTC

Credential Stuffing Attempt

Low Escalated
ALR-00106 · 2026-04-08T01:41:22Z

Description

Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by Endpoint Agent.

Alert Metadata

Alert ID
ALR-00106
Timestamp
2026-04-08T01:41:22Z
Severity
Low
Status
Escalated
Detection Source
Endpoint Agent
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
VM-DEV-01
User Account
f.hall
Source IP
103.203.216.195
Destination IP
10.3.150.124
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.004
Reference
attack.mitre.org/techniques/T1110.004

Investigation Timeline

01:41:22 Event ingested by SOC365 Engine
01:41:23 EmilyAI triage started — correlation enrichment
01:41:36 EmilyAI confidence: 81% — escalated to human analyst
01:41:53 Alert assigned to analyst: EmilyAI (auto)
01:42:43 Investigation started — querying SIEM and threat intelligence
01:48:30 Containment action taken — endpoint isolated
02:01:22 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00305 16m ago Failed MFA Challenge Informational Resolved VM-DEV-01
ALR-00082 2h ago Rogue DHCP Server Low False Positive VM-DEV-01
ALR-00190 3h ago Credential Stuffing Attempt Low Investigating WS-PC-001
ALR-00279 10h ago Credential Stuffing Attempt Medium Escalated WS-PC-001
ALR-00183 10h ago Credential Stuffing Attempt Medium Escalated SRV-APP-01