Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 21:33:58 UTC

Credential Stuffing Attempt

Informational Resolved
ALR-00301 · 2026-05-25T07:43:22Z

Description

Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by EmilyAI Triage.

Alert Metadata

Alert ID
ALR-00301
Timestamp
2026-05-25T07:43:22Z
Severity
Informational
Status
Resolved
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-006
User Account
r.davies
Source IP
45.59.148.163
Destination IP
10.1.136.23
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.004
Reference
attack.mitre.org/techniques/T1110.004

Investigation Timeline

07:43:22 Event ingested by SOC365 Engine
07:43:24 EmilyAI triage started — correlation enrichment
07:43:35 EmilyAI confidence: 87% — escalated to human analyst
07:44:05 Alert assigned to analyst: EmilyAI (auto)
07:46:18 Investigation started — querying SIEM and threat intelligence
07:52:26 Containment action taken — endpoint isolated
08:02:41 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00047 4h ago Credential Stuffing Attempt Low Open WS-LAP-011
ALR-00191 4h ago Privilege Escalation Attempt Medium Open WS-PC-006
ALR-00353 6h ago Port Scan Detected Medium Resolved WS-PC-006
ALR-00027 15h ago Suspicious Scheduled Task High Escalated WS-PC-006
ALR-00496 16h ago Shadow IT Discovery Low Investigating WS-PC-006