Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 18:01:03 UTC

Suspicious Scheduled Task

Low Investigating
ALR-00314 · 2026-05-26T07:20:50Z

Description

New scheduled task created on SW-CORE-01 by 'l.johnson' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00314
Timestamp
2026-05-26T07:20:50Z
Severity
Low
Status
Investigating
Detection Source
EmilyAI Triage
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SW-CORE-01
User Account
l.johnson
Source IP
194.61.62.224
Destination IP
10.1.190.210
Origin Country
US United States

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

07:20:50 Event ingested by SOC365 Engine
07:20:52 EmilyAI triage started — correlation enrichment
07:21:05 EmilyAI confidence: 98% — escalated to human analyst
07:21:35 Alert assigned to analyst: EmilyAI (auto)
07:23:22 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00247 11h ago Certificate Anomaly Low Resolved SW-CORE-01
ALR-00225 11h ago Suspicious Scheduled Task Low False Positive SRV-SQL-01
ALR-00389 12h ago Insider Threat Indicator Medium Open SW-CORE-01
ALR-00099 13h ago Certificate Anomaly Low Escalated SW-CORE-01
ALR-00423 20h ago Suspicious Scheduled Task Low Open WS-MAC-005