Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:05:21 UTC

Suspicious PowerShell Execution

Medium Escalated
ALR-00135 · 2026-05-23T07:59:32Z

Description

Encoded PowerShell command executed on SRV-FILE-01 by user 'system'. Command attempts to download and execute remote payload. Flagged by DLP Module.

Alert Metadata

Alert ID
ALR-00135
Timestamp
2026-05-23T07:59:32Z
Severity
Medium
Status
Escalated
Detection Source
DLP Module
Assigned Analyst
Sarah Chen

Endpoint Information

Hostname
SRV-FILE-01
User Account
system
Source IP
194.48.62.243
Destination IP
10.3.135.202
Origin Country
DE Germany

MITRE ATT&CK Mapping

Tactic
Execution
Technique
T1059.001
Reference
attack.mitre.org/techniques/T1059.001

Investigation Timeline

07:59:32 Event ingested by SOC365 Engine
07:59:34 EmilyAI triage started — correlation enrichment
07:59:42 EmilyAI confidence: 94% — escalated to human analyst
07:59:53 Alert assigned to analyst: Sarah Chen
08:01:01 Investigation started — querying SIEM and threat intelligence
08:04:20 Containment action taken — endpoint isolated
08:17:56 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00239 17m ago Suspicious PowerShell Execution Informational False Positive WS-LAP-011
ALR-00281 5h ago DecoyPulse Honeypot Triggered Informational Escalated SRV-FILE-01
ALR-00041 9h ago Brute Force SSH Informational Resolved SRV-FILE-01
ALR-00068 13h ago Suspicious PowerShell Execution Informational False Positive WS-PC-002
ALR-00470 18h ago Suspicious PowerShell Execution Low Open SW-CORE-01