Suspicious PowerShell Execution
Low
False Positive
ALR-00081 · 2026-05-26T10:45:48Z
Description
Encoded PowerShell command executed on VM-DEV-01 by user 'system'. Command attempts to download and execute remote payload. Flagged by Email Gateway.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
10:45:48
Event ingested by SOC365 Engine
10:45:51
EmilyAI triage started — correlation enrichment
10:45:59
EmilyAI confidence: 78% — escalated to human analyst
10:46:24
Alert assigned to analyst: EmilyAI (auto)
10:46:58
Investigation started — querying SIEM and threat intelligence
10:52:21
Containment action taken — endpoint isolated
11:03:01
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00476 | 21m ago | Unusual Outbound Traffic | Medium | False Positive | VM-DEV-01 |
| ALR-00271 | 1h ago | Port Scan Detected | Low | Open | VM-DEV-01 |
| ALR-00316 | 13h ago | Suspicious PowerShell Execution | Low | Open | WS-MAC-005 |
| ALR-00312 | 17h ago | Suspicious PowerShell Execution | Low | Investigating | SRV-DC-01 |
| ALR-00344 | 20h ago | Brute Force SSH | Low | Resolved | VM-DEV-01 |