Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:03:40 UTC

Suspicious Scheduled Task

Low Escalated
ALR-00134 · 2026-05-24T09:02:11Z

Description

New scheduled task created on VM-DEV-01 by 'r.davies' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00134
Timestamp
2026-05-24T09:02:11Z
Severity
Low
Status
Escalated
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
VM-DEV-01
User Account
r.davies
Source IP
91.113.195.251
Destination IP
10.2.8.192
Origin Country
GB United Kingdom

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

09:02:11 Event ingested by SOC365 Engine
09:02:15 EmilyAI triage started — correlation enrichment
09:02:25 EmilyAI confidence: 82% — escalated to human analyst
09:02:35 Alert assigned to analyst: EmilyAI (auto)
09:05:09 Investigation started — querying SIEM and threat intelligence
09:10:42 Containment action taken — endpoint isolated
09:12:48 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00187 6h ago Suspicious Scheduled Task Medium Open SRV-APP-01
ALR-00162 9h ago Lateral Movement Detected Critical Escalated VM-DEV-01
ALR-00197 9h ago Suspicious Scheduled Task Low False Positive SRV-DC-01
ALR-00048 10h ago Ransomware Behaviour Detected Medium Resolved VM-DEV-01
ALR-00270 13h ago C2 Beacon Activity Medium False Positive VM-DEV-01