Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 13:57:12 UTC

Credential Stuffing Attempt

Low Investigating
ALR-00417 · 2026-04-08T18:03:16Z

Description

Credential stuffing attack detected against VPN gateway. 234 unique username/password combinations attempted. Flagged by EmilyAI Triage.

Alert Metadata

Alert ID
ALR-00417
Timestamp
2026-04-08T18:03:16Z
Severity
Low
Status
Investigating
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-006
User Account
c.williams
Source IP
185.143.220.171
Destination IP
10.2.92.50
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.004
Reference
attack.mitre.org/techniques/T1110.004

Investigation Timeline

18:03:16 Event ingested by SOC365 Engine
18:03:19 EmilyAI triage started — correlation enrichment
18:03:27 EmilyAI confidence: 83% — escalated to human analyst
18:03:48 Alert assigned to analyst: EmilyAI (auto)
18:05:08 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00296 5m ago Privilege Escalation Attempt Medium False Positive WS-PC-006
ALR-00096 1h ago C2 Beacon Activity High Escalated WS-PC-006
ALR-00113 1h ago Credential Stuffing Attempt Informational False Positive SW-CORE-01
ALR-00368 3h ago Credential Stuffing Attempt Informational False Positive SRV-BACKUP-01
ALR-00441 6h ago Credential Stuffing Attempt Medium False Positive VM-DEV-01