Suspicious PowerShell Execution
Informational
Investigating
ALR-00071 · 2026-05-24T03:52:04Z
Description
Encoded PowerShell command executed on WS-PC-003 by user 'f.hall'. Command attempts to download and execute remote payload. Flagged by Dark Web Monitor.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
03:52:04
Event ingested by SOC365 Engine
03:52:09
EmilyAI triage started — correlation enrichment
03:52:18
EmilyAI confidence: 78% — escalated to human analyst
03:52:35
Alert assigned to analyst: EmilyAI (auto)
03:54:30
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00354 | 1h ago | Unusual Outbound Traffic | Informational | False Positive | WS-PC-003 |
| ALR-00209 | 3h ago | DecoyPulse Honeypot Triggered | Low | False Positive | WS-PC-003 |
| ALR-00119 | 3h ago | Unauthorised USB Device | Informational | Escalated | WS-PC-003 |
| ALR-00267 | 8h ago | Ransomware Behaviour Detected | High | Escalated | WS-PC-003 |
| ALR-00231 | 11h ago | Suspicious PowerShell Execution | Informational | False Positive | WS-PC-004 |