Suspicious Scheduled Task
Low
Open
ALR-00054 · 2026-05-23T08:27:20Z
Description
New scheduled task created on FW-EDGE-01 by 'r.davies' running encoded batch script at 02:00 daily. No change request on file.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
08:27:20
Event ingested by SOC365 Engine
08:27:21
EmilyAI triage started — correlation enrichment
08:27:29
EmilyAI confidence: 78% — escalated to human analyst
08:28:03
Alert assigned to analyst: EmilyAI (auto)
08:29:22
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00104 | 9h ago | Insider Threat Indicator | Low | False Positive | FW-EDGE-01 |
| ALR-00490 | 1d ago | Privilege Escalation Attempt | Informational | False Positive | FW-EDGE-01 |
| ALR-00277 | 1d ago | Suspicious PowerShell Execution | Informational | Resolved | FW-EDGE-01 |
| ALR-00228 | 1d ago | Suspicious Scheduled Task | Informational | Open | WS-PC-004 |
| ALR-00043 | 1d ago | Suspicious Scheduled Task | Low | Open | AP-WIFI-03 |