Kerberoasting Attempt
High
Investigating
ALR-00430 · 2026-04-07T10:46:58Z
Description
Kerberoasting attack detected: user 'a.wilson' requested TGS tickets for multiple service accounts in 2 minutes. Flagged by Email Gateway.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
10:46:58
Event ingested by SOC365 Engine
10:47:02
EmilyAI triage started — correlation enrichment
10:47:09
EmilyAI confidence: 86% — escalated to human analyst
10:47:24
Alert assigned to analyst: James Okonkwo
10:48:09
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00342 | 16h ago | Insider Threat Indicator | Low | Resolved | VM-DEV-01 |
| ALR-00195 | 22h ago | Privilege Escalation Attempt | High | Escalated | VM-DEV-01 |
| ALR-00468 | 1d ago | Shadow IT Discovery | Low | Resolved | VM-DEV-01 |
| ALR-00023 | 1d ago | Kerberoasting Attempt | Informational | Open | SRV-FILE-01 |
| ALR-00293 | 1d ago | Pass-the-Hash Detected | Informational | Open | VM-DEV-01 |