Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:27:00 UTC

Failed MFA Challenge

Informational Escalated
ALR-00272 · 2026-04-09T11:04:47Z

Description

Multiple failed MFA challenges for user 'l.johnson' — 12 push notifications in 3 minutes suggesting MFA fatigue attack. DecoyPulse locked account.

Alert Metadata

Alert ID
ALR-00272
Timestamp
2026-04-09T11:04:47Z
Severity
Informational
Status
Escalated
Detection Source
DecoyPulse
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
l.johnson
Source IP
103.53.216.101
Destination IP
10.3.22.158
Origin Country
IN India

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1621
Reference
attack.mitre.org/techniques/T1621

Investigation Timeline

11:04:47 Event ingested by SOC365 Engine
11:04:48 EmilyAI triage started — correlation enrichment
11:04:57 EmilyAI confidence: 88% — escalated to human analyst
11:05:05 Alert assigned to analyst: EmilyAI (auto)
11:06:28 Investigation started — querying SIEM and threat intelligence
11:09:29 Containment action taken — endpoint isolated
11:23:17 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00423 9h ago Insider Threat Indicator Informational Investigating SW-CORE-01
ALR-00107 10h ago Tor Exit Node Connection Low Escalated SW-CORE-01
ALR-00417 10h ago DecoyPulse Honeypot Triggered Low Investigating SW-CORE-01
ALR-00462 14h ago Unauthorised USB Device Medium Open SW-CORE-01
ALR-00034 1d ago Unauthorised USB Device Informational Investigating SW-CORE-01