Brute Force SSH
Low
Escalated
ALR-00227 · 2026-04-08T01:44:45Z
Description
Multiple failed SSH login attempts detected on AP-WIFI-03 from external IP. Network IDS flagged 47 attempts in 5 minutes targeting user 'p.thomas'.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
01:44:45
Event ingested by SOC365 Engine
01:44:48
EmilyAI triage started — correlation enrichment
01:44:56
EmilyAI confidence: 80% — escalated to human analyst
01:45:09
Alert assigned to analyst: EmilyAI (auto)
01:45:37
Investigation started — querying SIEM and threat intelligence
01:49:56
Containment action taken — endpoint isolated
02:03:02
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00160 | 11h ago | Data Exfiltration Attempt | Low | Resolved | AP-WIFI-03 |
| ALR-00414 | 12h ago | Unusual Outbound Traffic | High | Investigating | AP-WIFI-03 |
| ALR-00094 | 20h ago | DecoyPulse Honeypot Triggered | High | Open | AP-WIFI-03 |
| ALR-00238 | 23h ago | Brute Force SSH | Low | Open | WS-LAP-010 |
| ALR-00163 | 1d ago | Brute Force SSH | Low | Investigating | SRV-WEB-01 |