Suspicious PowerShell Execution
Medium
False Positive
ALR-00136 · 2026-04-11T04:32:12Z
Description
Encoded PowerShell command executed on SRV-MAIL-01 by user 'h.roberts'. Command attempts to download and execute remote payload. Flagged by Firewall.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
04:32:12
Event ingested by SOC365 Engine
04:32:13
EmilyAI triage started — correlation enrichment
04:32:17
EmilyAI confidence: 86% — escalated to human analyst
04:32:47
Alert assigned to analyst: Sarah Chen
04:34:12
Investigation started — querying SIEM and threat intelligence
04:38:43
Containment action taken — endpoint isolated
04:44:45
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00196 | 5h ago | Phishing Email Blocked | Low | False Positive | SRV-MAIL-01 |
| ALR-00192 | 5h ago | DLP Policy Violation | Critical | Investigating | SRV-MAIL-01 |
| ALR-00070 | 6h ago | Suspicious PowerShell Execution | Medium | False Positive | SRV-MAIL-01 |
| ALR-00045 | 8h ago | Suspicious PowerShell Execution | Medium | False Positive | SRV-DC-01 |
| ALR-00363 | 9h ago | Suspicious PowerShell Execution | Low | False Positive | FW-EDGE-01 |