Credential Stuffing Attempt
Medium
False Positive
ALR-00271 · 2026-05-24T12:21:18Z
Description
Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by Attack Surface Scanner.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
12:21:18
Event ingested by SOC365 Engine
12:21:22
EmilyAI triage started — correlation enrichment
12:21:30
EmilyAI confidence: 86% — escalated to human analyst
12:21:51
Alert assigned to analyst: Marcus Webb
12:23:23
Investigation started — querying SIEM and threat intelligence
12:25:51
Containment action taken — endpoint isolated
12:36:07
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00129 | 5h ago | Credential Stuffing Attempt | Low | False Positive | WS-LAP-012 |
| ALR-00288 | 12h ago | Suspicious PowerShell Execution | Low | Open | AP-WIFI-03 |
| ALR-00383 | 14h ago | C2 Beacon Activity | High | Open | AP-WIFI-03 |
| ALR-00473 | 15h ago | Tor Exit Node Connection | High | Escalated | AP-WIFI-03 |
| ALR-00404 | 19h ago | C2 Beacon Activity | Low | Investigating | AP-WIFI-03 |