Failed MFA Challenge
Medium
Resolved
ALR-00126 · 2026-04-08T23:40:26Z
Description
Multiple failed MFA challenges for user 'e.evans' — 12 push notifications in 3 minutes suggesting MFA fatigue attack. Firewall locked account.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:40:26
Event ingested by SOC365 Engine
23:40:29
EmilyAI triage started — correlation enrichment
23:40:34
EmilyAI confidence: 85% — escalated to human analyst
23:40:45
Alert assigned to analyst: Sarah Chen
23:42:35
Investigation started — querying SIEM and threat intelligence
23:44:48
Containment action taken — endpoint isolated
23:51:28
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00067 | 58m ago | Anomalous DNS Query | Low | Escalated | WS-LAP-011 |
| ALR-00408 | 1h ago | Certificate Anomaly | Low | Escalated | WS-LAP-011 |
| ALR-00216 | 1h ago | Failed MFA Challenge | Medium | Investigating | WS-PC-004 |
| ALR-00479 | 4h ago | Ransomware Behaviour Detected | High | Investigating | WS-LAP-011 |
| ALR-00481 | 5h ago | Failed MFA Challenge | High | Investigating | SW-CORE-01 |