Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 15:25:28 UTC

Suspicious Scheduled Task

Medium Escalated
ALR-00357 · 2026-04-09T23:23:58Z

Description

New scheduled task created on VM-DEV-01 by 'e.evans' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00357
Timestamp
2026-04-09T23:23:58Z
Severity
Medium
Status
Escalated
Detection Source
DecoyPulse
Assigned Analyst
Marcus Webb

Endpoint Information

Hostname
VM-DEV-01
User Account
e.evans
Source IP
91.120.195.134
Destination IP
10.2.3.95
Origin Country
UA Ukraine

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

23:23:58 Event ingested by SOC365 Engine
23:24:01 EmilyAI triage started — correlation enrichment
23:24:12 EmilyAI confidence: 98% — escalated to human analyst
23:24:35 Alert assigned to analyst: Marcus Webb
23:25:37 Investigation started — querying SIEM and threat intelligence
23:32:12 Containment action taken — endpoint isolated
23:43:08 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00223 1h ago Suspicious Scheduled Task Informational False Positive WS-LAP-012
ALR-00315 2h ago Suspicious Scheduled Task Low Resolved WS-LAP-011
ALR-00329 6h ago Unusual Outbound Traffic Critical Investigating VM-DEV-01
ALR-00115 9h ago Suspicious Scheduled Task Informational Open FW-EDGE-01
ALR-00086 11h ago Anomalous DNS Query High Escalated VM-DEV-01