Suspicious PowerShell Execution
Informational
Resolved
ALR-00007 · 2026-05-23T07:45:47Z
Description
Encoded PowerShell command executed on FW-EDGE-01 by user 'e.evans'. Command attempts to download and execute remote payload. Flagged by DecoyPulse.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:45:47
Event ingested by SOC365 Engine
07:45:50
EmilyAI triage started — correlation enrichment
07:45:57
EmilyAI confidence: 81% — escalated to human analyst
07:46:15
Alert assigned to analyst: EmilyAI (auto)
07:46:44
Investigation started — querying SIEM and threat intelligence
07:53:01
Containment action taken — endpoint isolated
07:57:23
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00224 | 33m ago | Anomalous DNS Query | Informational | Resolved | FW-EDGE-01 |
| ALR-00426 | 6h ago | Unusual Outbound Traffic | Low | Investigating | FW-EDGE-01 |
| ALR-00375 | 1d ago | Suspicious PowerShell Execution | Informational | False Positive | FW-EDGE-01 |
| ALR-00142 | 1d ago | Suspicious PowerShell Execution | Informational | Resolved | WS-PC-003 |
| ALR-00165 | 1d ago | Port Scan Detected | Medium | Resolved | FW-EDGE-01 |