Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:21 UTC

Kerberoasting Attempt

Low Resolved
ALR-00230 · 2026-05-25T16:58:26Z

Description

Kerberoasting attack detected: user 'd.walker' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Cloud Connector.

Alert Metadata

Alert ID
ALR-00230
Timestamp
2026-05-25T16:58:26Z
Severity
Low
Status
Resolved
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-006
User Account
d.walker
Source IP
185.79.220.244
Destination IP
10.1.27.61
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

16:58:26 Event ingested by SOC365 Engine
16:58:29 EmilyAI triage started — correlation enrichment
16:58:36 EmilyAI confidence: 91% — escalated to human analyst
16:59:02 Alert assigned to analyst: EmilyAI (auto)
17:01:22 Investigation started — querying SIEM and threat intelligence
17:08:05 Containment action taken — endpoint isolated
17:12:47 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00276 2h ago DLP Policy Violation Low Escalated WS-PC-006
ALR-00410 8h ago Kerberoasting Attempt Informational Escalated WS-LAP-012
ALR-00278 8h ago Tor Exit Node Connection Informational Open WS-PC-006
ALR-00355 16h ago Anomalous DNS Query Informational False Positive WS-PC-006
ALR-00152 21h ago Kerberoasting Attempt Informational False Positive WS-PC-001