Brute Force SSH
Medium
Open
ALR-00297 · 2026-04-09T16:33:39Z
Description
Multiple failed SSH login attempts detected on WS-LAP-012 from external IP. EmilyAI Triage flagged 47 attempts in 5 minutes targeting user 'k.brown'.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
16:33:39
Event ingested by SOC365 Engine
16:33:43
EmilyAI triage started — correlation enrichment
16:33:47
EmilyAI confidence: 97% — escalated to human analyst
16:34:00
Alert assigned to analyst: Sarah Chen
16:34:27
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00223 | 1h ago | Suspicious Scheduled Task | Informational | False Positive | WS-LAP-012 |
| ALR-00048 | 2h ago | Ransomware Behaviour Detected | Medium | False Positive | WS-LAP-012 |
| ALR-00332 | 2h ago | DecoyPulse Honeypot Triggered | Medium | False Positive | WS-LAP-012 |
| ALR-00380 | 16h ago | DecoyPulse Honeypot Triggered | High | Open | WS-LAP-012 |
| ALR-00500 | 18h ago | Insider Threat Indicator | High | Escalated | WS-LAP-012 |