Brute Force SSH
Informational
Investigating
ALR-00380 · 2026-05-25T22:05:14Z
Description
Multiple failed SSH login attempts detected on WS-LAP-011 from external IP. DLP Module flagged 47 attempts in 5 minutes targeting user 'p.thomas'.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
22:05:14
Event ingested by SOC365 Engine
22:05:15
EmilyAI triage started — correlation enrichment
22:05:19
EmilyAI confidence: 98% — escalated to human analyst
22:05:34
Alert assigned to analyst: EmilyAI (auto)
22:06:53
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00243 | 1h ago | Brute Force SSH | Low | Investigating | WS-PC-001 |
| ALR-00254 | 11h ago | Insider Threat Indicator | Medium | Resolved | WS-LAP-011 |
| ALR-00102 | 12h ago | Suspicious Scheduled Task | Low | False Positive | WS-LAP-011 |
| ALR-00036 | 12h ago | Brute Force SSH | Low | Escalated | AP-WIFI-03 |
| ALR-00229 | 17h ago | Brute Force SSH | High | Investigating | WS-LAP-012 |