Credential Stuffing Attempt
Medium
Resolved
ALR-00221 · 2026-05-22T22:43:56Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by Attack Surface Scanner.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:43:56
Event ingested by SOC365 Engine
22:43:58
EmilyAI triage started — correlation enrichment
22:44:03
EmilyAI confidence: 89% — escalated to human analyst
22:44:31
Alert assigned to analyst: James Okonkwo
22:45:39
Investigation started — querying SIEM and threat intelligence
22:48:19
Containment action taken — endpoint isolated
22:56:25
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00096 | 5h ago | Credential Stuffing Attempt | Low | False Positive | WS-PC-001 |
| ALR-00228 | 6h ago | Credential Stuffing Attempt | Informational | False Positive | SRV-APP-01 |
| ALR-00295 | 10h ago | Unauthorised USB Device | Medium | False Positive | SRV-FILE-01 |
| ALR-00022 | 12h ago | Failed MFA Challenge | Informational | Open | SRV-FILE-01 |
| ALR-00100 | 13h ago | Rogue DHCP Server | Low | Investigating | SRV-FILE-01 |