Brute Force SSH
Informational
Investigating
ALR-00419 · 2026-05-21T12:22:09Z
Description
Multiple failed SSH login attempts detected on SRV-BACKUP-01 from external IP. Firewall flagged 47 attempts in 5 minutes targeting user 'f.hall'.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
12:22:09
Event ingested by SOC365 Engine
12:22:12
EmilyAI triage started — correlation enrichment
12:22:16
EmilyAI confidence: 92% — escalated to human analyst
12:22:51
Alert assigned to analyst: EmilyAI (auto)
12:23:01
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00086 | 1h ago | Ransomware Behaviour Detected | Informational | False Positive | SRV-BACKUP-01 |
| ALR-00210 | 6h ago | Lateral Movement Detected | Low | Open | SRV-BACKUP-01 |
| ALR-00309 | 6h ago | Unauthorised USB Device | High | Escalated | SRV-BACKUP-01 |
| ALR-00410 | 10h ago | Brute Force SSH | Low | Escalated | SRV-DC-01 |
| ALR-00196 | 14h ago | Pass-the-Hash Detected | Informational | Resolved | SRV-BACKUP-01 |