Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:18:48 UTC

Credential Stuffing Attempt

Low Escalated
ALR-00366 · 2026-04-12T03:35:38Z

Description

Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by SOC365 Engine.

Alert Metadata

Alert ID
ALR-00366
Timestamp
2026-04-12T03:35:38Z
Severity
Low
Status
Escalated
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-SQL-01
User Account
n.clark
Source IP
45.159.148.115
Destination IP
10.2.34.135
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.004
Reference
attack.mitre.org/techniques/T1110.004

Investigation Timeline

03:35:38 Event ingested by SOC365 Engine
03:35:42 EmilyAI triage started — correlation enrichment
03:35:45 EmilyAI confidence: 87% — escalated to human analyst
03:36:18 Alert assigned to analyst: EmilyAI (auto)
03:38:03 Investigation started — querying SIEM and threat intelligence
03:39:51 Containment action taken — endpoint isolated
03:48:08 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00489 5h ago Shadow IT Discovery Low Investigating SRV-SQL-01
ALR-00169 10h ago Credential Stuffing Attempt Low Investigating WS-LAP-011
ALR-00254 13h ago Credential Stuffing Attempt Informational False Positive VM-DEV-01
ALR-00018 19h ago Credential Stuffing Attempt Medium Investigating WS-MAC-005
ALR-00499 1d ago Privilege Escalation Attempt Informational False Positive SRV-SQL-01