Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:03:35 UTC

Suspicious Scheduled Task

Informational Open
ALR-00248 · 2026-05-25T09:42:33Z

Description

New scheduled task created on WS-LAP-012 by 'h.roberts' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00248
Timestamp
2026-05-25T09:42:33Z
Severity
Informational
Status
Open
Detection Source
Network IDS
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
WS-LAP-012
User Account
h.roberts
Source IP
45.216.148.20
Destination IP
10.3.151.143
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

09:42:33 Event ingested by SOC365 Engine
09:42:35 EmilyAI triage started — correlation enrichment
09:42:48 EmilyAI confidence: 97% — escalated to human analyst
09:42:53 Alert assigned to analyst: EmilyAI (auto)
09:43:46 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00187 6h ago Suspicious Scheduled Task Medium Open SRV-APP-01
ALR-00197 9h ago Suspicious Scheduled Task Low False Positive SRV-DC-01
ALR-00214 15h ago Suspicious Scheduled Task Low Escalated SRV-DC-01
ALR-00222 1d ago Kerberoasting Attempt Low Open WS-LAP-012
ALR-00021 1d ago Credential Stuffing Attempt Low Open WS-LAP-012