Credential Stuffing Attempt
Medium
Investigating
ALR-00165 · 2026-04-11T09:18:49Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by Email Gateway.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:18:49
Event ingested by SOC365 Engine
09:18:52
EmilyAI triage started — correlation enrichment
09:18:58
EmilyAI confidence: 97% — escalated to human analyst
09:19:28
Alert assigned to analyst: Sarah Chen
09:20:19
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00089 | 5h ago | Credential Stuffing Attempt | Low | Open | WS-PC-001 |
| ALR-00347 | 5h ago | Credential Stuffing Attempt | Medium | Escalated | SRV-SQL-01 |
| ALR-00336 | 13h ago | DLP Policy Violation | Medium | Open | AP-WIFI-03 |
| ALR-00348 | 17h ago | Credential Stuffing Attempt | High | Open | VM-DEV-01 |
| ALR-00236 | 17h ago | Ransomware Behaviour Detected | Low | False Positive | AP-WIFI-03 |