Suspicious Scheduled Task
Informational
Resolved
ALR-00071 · 2026-04-11T09:54:07Z
Description
New scheduled task created on WS-PC-004 by 'a.wilson' running encoded batch script at 02:00 daily. No change request on file.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:54:07
Event ingested by SOC365 Engine
09:54:09
EmilyAI triage started — correlation enrichment
09:54:17
EmilyAI confidence: 93% — escalated to human analyst
09:54:24
Alert assigned to analyst: EmilyAI (auto)
09:56:56
Investigation started — querying SIEM and threat intelligence
10:02:24
Containment action taken — endpoint isolated
10:04:13
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00216 | 1h ago | Failed MFA Challenge | Medium | Investigating | WS-PC-004 |
| ALR-00229 | 3h ago | Suspicious Scheduled Task | Low | Open | WS-PC-001 |
| ALR-00075 | 8h ago | Shadow IT Discovery | Medium | Resolved | WS-PC-004 |
| ALR-00161 | 11h ago | Suspicious Scheduled Task | Low | Resolved | SRV-SQL-01 |
| ALR-00098 | 1d ago | Suspicious Scheduled Task | Informational | Investigating | WS-PC-004 |