Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 17:00:12 UTC

Kerberoasting Attempt

Critical Investigating
ALR-00404 · 2026-04-09T01:02:34Z

Description

Kerberoasting attack detected: user 'l.johnson' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Dark Web Monitor.

Alert Metadata

Alert ID
ALR-00404
Timestamp
2026-04-09T01:02:34Z
Severity
Critical
Status
Investigating
Detection Source
Dark Web Monitor
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
FW-EDGE-01
User Account
l.johnson
Source IP
194.41.62.203
Destination IP
10.2.33.100
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

01:02:34 Event ingested by SOC365 Engine
01:02:36 EmilyAI triage started — correlation enrichment
01:02:48 EmilyAI confidence: 96% — escalated to human analyst
01:03:03 Alert assigned to analyst: Emma Richardson
01:05:02 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00393 1h ago Kerberoasting Attempt Medium Resolved AP-WIFI-03
ALR-00307 13h ago Kerberoasting Attempt Medium False Positive AP-WIFI-03
ALR-00273 13h ago Pass-the-Hash Detected Low False Positive FW-EDGE-01
ALR-00175 21h ago DLP Policy Violation Low Resolved FW-EDGE-01
ALR-00147 21h ago Rogue DHCP Server Low Escalated FW-EDGE-01