Kerberoasting Attempt
Informational
Investigating
ALR-00125 · 2026-04-12T13:08:23Z
Description
Kerberoasting attack detected: user 'system' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Dark Web Monitor.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
13:08:23
Event ingested by SOC365 Engine
13:08:28
EmilyAI triage started — correlation enrichment
13:08:30
EmilyAI confidence: 83% — escalated to human analyst
13:09:00
Alert assigned to analyst: EmilyAI (auto)
13:10:13
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00273 | 26m ago | Anomalous DNS Query | Low | Open | SRV-SQL-01 |
| ALR-00006 | 5h ago | Kerberoasting Attempt | Informational | Open | SRV-FILE-01 |
| ALR-00255 | 9h ago | Kerberoasting Attempt | Low | Escalated | WS-PC-002 |
| ALR-00491 | 14h ago | Kerberoasting Attempt | Informational | Resolved | SW-CORE-01 |
| ALR-00284 | 17h ago | Kerberoasting Attempt | Medium | Open | WS-LAP-010 |