Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:27:38 UTC

Kerberoasting Attempt

Low Resolved
ALR-00109 · 2026-04-10T05:40:06Z

Description

Kerberoasting attack detected: user 'r.davies' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Network IDS.

Alert Metadata

Alert ID
ALR-00109
Timestamp
2026-04-10T05:40:06Z
Severity
Low
Status
Resolved
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-SQL-01
User Account
r.davies
Source IP
103.44.216.36
Destination IP
10.0.107.31
Origin Country
FR France

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

05:40:06 Event ingested by SOC365 Engine
05:40:07 EmilyAI triage started — correlation enrichment
05:40:16 EmilyAI confidence: 87% — escalated to human analyst
05:40:26 Alert assigned to analyst: EmilyAI (auto)
05:43:00 Investigation started — querying SIEM and threat intelligence
05:49:59 Containment action taken — endpoint isolated
05:55:31 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00035 59m ago Kerberoasting Attempt Low Escalated WS-LAP-011
ALR-00065 2h ago DLP Policy Violation Medium Escalated SRV-SQL-01
ALR-00036 5h ago Kerberoasting Attempt Informational Resolved SRV-MAIL-01
ALR-00347 5h ago Credential Stuffing Attempt Medium Escalated SRV-SQL-01
ALR-00164 5h ago Certificate Anomaly Medium False Positive SRV-SQL-01