Suspicious PowerShell Execution
Low
Escalated
ALR-00386 · 2026-05-21T09:54:46Z
Description
Encoded PowerShell command executed on WS-PC-001 by user 'j.smith'. Command attempts to download and execute remote payload. Flagged by Firewall.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:54:46
Event ingested by SOC365 Engine
09:54:50
EmilyAI triage started — correlation enrichment
09:54:59
EmilyAI confidence: 79% — escalated to human analyst
09:55:09
Alert assigned to analyst: EmilyAI (auto)
09:56:23
Investigation started — querying SIEM and threat intelligence
10:00:17
Containment action taken — endpoint isolated
10:10:51
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00232 | 8m ago | DLP Policy Violation | High | Investigating | WS-PC-001 |
| ALR-00244 | 1h ago | Suspicious PowerShell Execution | Medium | Investigating | SRV-FILE-01 |
| ALR-00167 | 3h ago | Suspicious PowerShell Execution | Medium | Open | AP-WIFI-03 |
| ALR-00078 | 7h ago | Unusual Outbound Traffic | Low | Investigating | WS-PC-001 |
| ALR-00203 | 10h ago | Tor Exit Node Connection | Informational | False Positive | WS-PC-001 |