Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:25:41 UTC

Suspicious Scheduled Task

Medium Open
ALR-00112 · 2026-04-06T04:02:21Z

Description

New scheduled task created on SRV-WEB-01 by 'r.davies' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00112
Timestamp
2026-04-06T04:02:21Z
Severity
Medium
Status
Open
Detection Source
Network IDS
Assigned Analyst
Emma Richardson

Endpoint Information

Hostname
SRV-WEB-01
User Account
r.davies
Source IP
194.196.62.194
Destination IP
10.3.63.126
Origin Country
RU Russia

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

04:02:21 Event ingested by SOC365 Engine
04:02:25 EmilyAI triage started — correlation enrichment
04:02:28 EmilyAI confidence: 80% — escalated to human analyst
04:03:06 Alert assigned to analyst: Emma Richardson
04:04:47 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00223 1h ago Suspicious Scheduled Task Informational False Positive WS-LAP-012
ALR-00315 2h ago Suspicious Scheduled Task Low Resolved WS-LAP-011
ALR-00434 6h ago Malware Signature Match Low Investigating SRV-WEB-01
ALR-00115 9h ago Suspicious Scheduled Task Informational Open FW-EDGE-01
ALR-00054 13h ago Data Exfiltration Attempt Low Open SRV-WEB-01