Credential Stuffing Attempt
Informational
False Positive
ALR-00170 · 2026-04-05T22:38:51Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by DLP Module.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:38:51
Event ingested by SOC365 Engine
22:38:55
EmilyAI triage started — correlation enrichment
22:39:05
EmilyAI confidence: 98% — escalated to human analyst
22:39:31
Alert assigned to analyst: EmilyAI (auto)
22:41:12
Investigation started — querying SIEM and threat intelligence
22:47:51
Containment action taken — endpoint isolated
22:53:44
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00374 | 2h ago | Credential Stuffing Attempt | Informational | Open | SRV-FILE-01 |
| ALR-00436 | 9h ago | C2 Beacon Activity | Low | Open | WS-PC-003 |
| ALR-00282 | 12h ago | Pass-the-Hash Detected | Low | Open | WS-PC-003 |
| ALR-00268 | 22h ago | Failed MFA Challenge | Informational | Resolved | WS-PC-003 |
| ALR-00178 | 1d ago | DLP Policy Violation | Medium | Open | WS-PC-003 |