Brute Force SSH
Medium
Escalated
ALR-00231 · 2026-05-22T09:44:59Z
Description
Multiple failed SSH login attempts detected on SRV-WEB-01 from external IP. DLP Module flagged 47 attempts in 5 minutes targeting user 'm.taylor'.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:44:59
Event ingested by SOC365 Engine
09:45:01
EmilyAI triage started — correlation enrichment
09:45:05
EmilyAI confidence: 87% — escalated to human analyst
09:45:40
Alert assigned to analyst: Marcus Webb
09:46:08
Investigation started — querying SIEM and threat intelligence
09:51:04
Containment action taken — endpoint isolated
09:57:18
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00443 | 1h ago | Brute Force SSH | Medium | Open | SRV-APP-01 |
| ALR-00338 | 7h ago | Certificate Anomaly | Low | Escalated | SRV-WEB-01 |
| ALR-00193 | 12h ago | Brute Force SSH | Low | Investigating | SRV-WEB-01 |
| ALR-00419 | 21h ago | Rogue DHCP Server | High | Investigating | SRV-WEB-01 |
| ALR-00223 | 22h ago | Anomalous DNS Query | Low | Resolved | SRV-WEB-01 |