Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:18:46 UTC

Kerberoasting Attempt

Medium Escalated
ALR-00201 · 2026-04-07T13:02:11Z

Description

Kerberoasting attack detected: user 'h.roberts' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Attack Surface Scanner.

Alert Metadata

Alert ID
ALR-00201
Timestamp
2026-04-07T13:02:11Z
Severity
Medium
Status
Escalated
Detection Source
Attack Surface Scanner
Assigned Analyst
Anika Patel

Endpoint Information

Hostname
WS-PC-004
User Account
h.roberts
Source IP
103.30.216.133
Destination IP
10.2.130.36
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

13:02:11 Event ingested by SOC365 Engine
13:02:13 EmilyAI triage started — correlation enrichment
13:02:22 EmilyAI confidence: 79% — escalated to human analyst
13:02:26 Alert assigned to analyst: Anika Patel
13:04:35 Investigation started — querying SIEM and threat intelligence
13:05:57 Containment action taken — endpoint isolated
13:18:44 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00235 2h ago Kerberoasting Attempt Low False Positive AP-WIFI-03
ALR-00230 3h ago Kerberoasting Attempt Medium Investigating SRV-BACKUP-01
ALR-00089 5h ago Kerberoasting Attempt Medium Escalated WS-PC-003
ALR-00310 9h ago Kerberoasting Attempt Informational Investigating WS-PC-001
ALR-00373 9h ago Pass-the-Hash Detected Low False Positive WS-PC-004