Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:20:56 UTC

Brute Force SSH

Low Escalated
ALR-00255 · 2026-04-10T21:56:43Z

Description

Multiple failed SSH login attempts detected on WS-PC-003 from external IP. DLP Module flagged 47 attempts in 5 minutes targeting user 'd.walker'.

Alert Metadata

Alert ID
ALR-00255
Timestamp
2026-04-10T21:56:43Z
Severity
Low
Status
Escalated
Detection Source
DLP Module
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-003
User Account
d.walker
Source IP
185.248.220.101
Destination IP
10.1.113.43
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

21:56:43 Event ingested by SOC365 Engine
21:56:44 EmilyAI triage started — correlation enrichment
21:56:58 EmilyAI confidence: 83% — escalated to human analyst
21:57:18 Alert assigned to analyst: EmilyAI (auto)
21:58:08 Investigation started — querying SIEM and threat intelligence
22:00:24 Containment action taken — endpoint isolated
22:08:31 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00019 8h ago Privilege Escalation Attempt Informational Resolved WS-PC-003
ALR-00135 9h ago Unauthorised USB Device Informational False Positive WS-PC-003
ALR-00013 10h ago Tor Exit Node Connection Low Escalated WS-PC-003
ALR-00201 10h ago Brute Force SSH Informational Investigating SRV-APP-01
ALR-00382 11h ago Shadow IT Discovery Informational False Positive WS-PC-003