Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:30 UTC

Credential Stuffing Attempt

Low Escalated
ALR-00132 · 2026-05-23T07:23:14Z

Description

Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by DecoyPulse.

Alert Metadata

Alert ID
ALR-00132
Timestamp
2026-05-23T07:23:14Z
Severity
Low
Status
Escalated
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-004
User Account
system
Source IP
185.49.220.100
Destination IP
10.2.84.220
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.004
Reference
attack.mitre.org/techniques/T1110.004

Investigation Timeline

07:23:14 Event ingested by SOC365 Engine
07:23:19 EmilyAI triage started — correlation enrichment
07:23:19 EmilyAI confidence: 88% — escalated to human analyst
07:23:49 Alert assigned to analyst: EmilyAI (auto)
07:24:20 Investigation started — querying SIEM and threat intelligence
07:32:49 Containment action taken — endpoint isolated
07:37:46 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00304 2h ago Credential Stuffing Attempt Medium Investigating WS-LAP-011
ALR-00287 9h ago Unusual Outbound Traffic Medium False Positive WS-PC-004
ALR-00018 9h ago Credential Stuffing Attempt Low Resolved WS-LAP-012
ALR-00245 14h ago Credential Stuffing Attempt Informational Investigating SW-CORE-01
ALR-00363 17h ago Pass-the-Hash Detected Medium Open WS-PC-004