Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:04:49 UTC

Brute Force SSH

Medium False Positive
ALR-00156 · 2026-05-24T09:05:56Z

Description

Multiple failed SSH login attempts detected on WS-MAC-005 from external IP. DLP Module flagged 47 attempts in 5 minutes targeting user 'a.wilson'.

Alert Metadata

Alert ID
ALR-00156
Timestamp
2026-05-24T09:05:56Z
Severity
Medium
Status
False Positive
Detection Source
DLP Module
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
WS-MAC-005
User Account
a.wilson
Source IP
103.189.216.215
Destination IP
10.1.177.146
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

09:05:56 Event ingested by SOC365 Engine
09:06:01 EmilyAI triage started — correlation enrichment
09:06:08 EmilyAI confidence: 86% — escalated to human analyst
09:06:21 Alert assigned to analyst: Emma Richardson
09:08:01 Investigation started — querying SIEM and threat intelligence
09:09:33 Containment action taken — endpoint isolated
09:16:23 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00303 9h ago Suspicious PowerShell Execution Informational Resolved WS-MAC-005
ALR-00333 11h ago Brute Force SSH Medium Resolved VM-DEV-01
ALR-00412 12h ago DecoyPulse Honeypot Triggered Medium Investigating WS-MAC-005
ALR-00076 13h ago Ransomware Behaviour Detected Medium Investigating WS-MAC-005
ALR-00067 16h ago Brute Force SSH Low Escalated SRV-MAIL-01