Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:09:11 UTC

Brute Force SSH

Low False Positive
ALR-00472 · 2026-05-24T10:40:59Z

Description

Multiple failed SSH login attempts detected on WS-PC-006 from external IP. Firewall flagged 47 attempts in 5 minutes targeting user 'c.williams'.

Alert Metadata

Alert ID
ALR-00472
Timestamp
2026-05-24T10:40:59Z
Severity
Low
Status
False Positive
Detection Source
Firewall
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-PC-006
User Account
c.williams
Source IP
45.85.148.58
Destination IP
10.2.81.14
Origin Country
CN China

MITRE ATT&CK Mapping

Tactic
Credential Access
Technique
T1110.001
Reference
attack.mitre.org/techniques/T1110.001

Investigation Timeline

10:40:59 Event ingested by SOC365 Engine
10:41:02 EmilyAI triage started — correlation enrichment
10:41:07 EmilyAI confidence: 79% — escalated to human analyst
10:41:38 Alert assigned to analyst: EmilyAI (auto)
10:43:34 Investigation started — querying SIEM and threat intelligence
10:44:05 Containment action taken — endpoint isolated
10:56:32 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00287 1h ago Brute Force SSH Low Resolved AP-WIFI-03
ALR-00053 1h ago C2 Beacon Activity Low Resolved WS-PC-006
ALR-00234 4h ago Brute Force SSH Medium Escalated WS-MAC-005
ALR-00056 6h ago Insider Threat Indicator High Escalated WS-PC-006
ALR-00023 9h ago Brute Force SSH Low Resolved SRV-APP-01