Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:10:15 UTC

Brute Force SSH

High Escalated
ALR-00171 · 2026-05-22T17:39:28Z

Description

Multiple failed SSH login attempts detected on SRV-APP-01 from external IP. EmilyAI Triage flagged 47 attempts in 5 minutes targeting user 'c.williams'.

Alert Metadata

Alert ID
ALR-00171
Timestamp
2026-05-22T17:39:28Z
Severity
High
Status
Escalated
Detection Source
EmilyAI Triage
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
SRV-APP-01
User Account
c.williams
Source IP
103.208.216.245
Destination IP
10.1.110.123
Origin Country
VN Vietnam

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

17:39:28 Event ingested by SOC365 Engine
17:39:31 EmilyAI triage started — correlation enrichment
17:39:38 EmilyAI confidence: 96% — escalated to human analyst
17:39:47 Alert assigned to analyst: Sarah Chen
17:42:10 Investigation started — querying SIEM and threat intelligence
17:47:23 Containment action taken — endpoint isolated
17:53:56 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00263 12h ago Malware Signature Match Medium False Positive SRV-APP-01
ALR-00152 15h ago Brute Force SSH Informational Investigating WS-LAP-011
ALR-00161 21h ago Brute Force SSH High Investigating SRV-FILE-01
ALR-00170 1d ago Pass-the-Hash Detected Low False Positive SRV-APP-01
ALR-00325 1d ago Port Scan Detected Medium Investigating SRV-APP-01