Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:26:11 UTC

Brute Force SSH

Low Escalated
ALR-00257 · 2026-04-12T09:59:58Z

Description

Multiple failed SSH login attempts detected on WS-MAC-005 from external IP. Network IDS flagged 47 attempts in 5 minutes targeting user 'e.evans'.

Alert Metadata

Alert ID
ALR-00257
Timestamp
2026-04-12T09:59:58Z
Severity
Low
Status
Escalated
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-MAC-005
User Account
e.evans
Source IP
45.227.148.85
Destination IP
10.2.210.165
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

09:59:58 Event ingested by SOC365 Engine
09:59:59 EmilyAI triage started — correlation enrichment
10:00:12 EmilyAI confidence: 89% — escalated to human analyst
10:00:41 Alert assigned to analyst: EmilyAI (auto)
10:01:25 Investigation started — querying SIEM and threat intelligence
10:08:15 Containment action taken — endpoint isolated
10:12:58 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00001 1h ago Suspicious Scheduled Task Medium Resolved WS-MAC-005
ALR-00354 4h ago Suspicious PowerShell Execution Informational False Positive WS-MAC-005
ALR-00251 7h ago Brute Force SSH Medium Open SRV-APP-01
ALR-00438 12h ago Brute Force SSH Low Escalated WS-PC-002
ALR-00078 15h ago Brute Force SSH Low Investigating FW-EDGE-01