Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 21:03:32 UTC

Kerberoasting Attempt

High Escalated
ALR-00425 · 2026-05-25T17:24:46Z

Description

Kerberoasting attack detected: user 'd.walker' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Firewall.

Alert Metadata

Alert ID
ALR-00425
Timestamp
2026-05-25T17:24:46Z
Severity
High
Status
Escalated
Detection Source
Firewall
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
VM-DEV-01
User Account
d.walker
Source IP
194.14.62.99
Destination IP
10.2.6.104
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1558.003
Reference
attack.mitre.org/techniques/T1558.003

Investigation Timeline

17:24:46 Event ingested by SOC365 Engine
17:24:48 EmilyAI triage started — correlation enrichment
17:24:56 EmilyAI confidence: 85% — escalated to human analyst
17:25:11 Alert assigned to analyst: Marcus Webb
17:26:18 Investigation started — querying SIEM and threat intelligence
17:34:43 Containment action taken — endpoint isolated
17:42:10 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00159 2h ago Credential Stuffing Attempt Low False Positive VM-DEV-01
ALR-00349 2h ago Kerberoasting Attempt Informational Resolved WS-PC-003
ALR-00082 6h ago Rogue DHCP Server Low Escalated VM-DEV-01
ALR-00371 7h ago Ransomware Behaviour Detected Low Investigating VM-DEV-01
ALR-00148 13h ago Ransomware Behaviour Detected Medium Resolved VM-DEV-01