Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:06:23 UTC

Brute Force SSH

Medium Investigating
ALR-00282 · 2026-05-21T20:43:21Z

Description

Multiple failed SSH login attempts detected on WS-PC-002 from external IP. Email Gateway flagged 47 attempts in 5 minutes targeting user 'j.smith'.

Alert Metadata

Alert ID
ALR-00282
Timestamp
2026-05-21T20:43:21Z
Severity
Medium
Status
Investigating
Detection Source
Email Gateway
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
WS-PC-002
User Account
j.smith
Source IP
194.110.62.155
Destination IP
10.3.90.188
Origin Country
RO Romania

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

20:43:21 Event ingested by SOC365 Engine
20:43:26 EmilyAI triage started — correlation enrichment
20:43:34 EmilyAI confidence: 83% — escalated to human analyst
20:43:58 Alert assigned to analyst: Sarah Chen
20:46:03 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00443 1h ago Brute Force SSH Medium Open SRV-APP-01
ALR-00479 5h ago Kerberoasting Attempt Medium False Positive WS-PC-002
ALR-00193 12h ago Brute Force SSH Low Investigating SRV-WEB-01
ALR-00342 13h ago Rogue DHCP Server Low Escalated WS-PC-002
ALR-00427 22h ago Port Scan Detected Medium Open WS-PC-002