Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 22:17:20 UTC

Suspicious Scheduled Task

Informational Escalated
ALR-00428 · 2026-05-26T20:29:29Z

Description

New scheduled task created on FW-EDGE-01 by 'r.davies' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00428
Timestamp
2026-05-26T20:29:29Z
Severity
Informational
Status
Escalated
Detection Source
Cloud Connector
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
FW-EDGE-01
User Account
r.davies
Source IP
103.17.216.185
Destination IP
10.3.61.221
Origin Country
NL Netherlands

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

20:29:29 Event ingested by SOC365 Engine
20:29:32 EmilyAI triage started — correlation enrichment
20:29:34 EmilyAI confidence: 88% — escalated to human analyst
20:29:54 Alert assigned to analyst: EmilyAI (auto)
20:32:26 Investigation started — querying SIEM and threat intelligence
20:38:05 Containment action taken — endpoint isolated
20:48:15 Alert resolved — remediation complete

Related Alerts

ID Time Alert Severity Status Host
ALR-00121 1h ago DecoyPulse Honeypot Triggered Informational Investigating FW-EDGE-01
ALR-00351 3h ago Port Scan Detected Low False Positive FW-EDGE-01
ALR-00468 6h ago Failed MFA Challenge Medium Investigating FW-EDGE-01
ALR-00117 7h ago Suspicious Scheduled Task Medium False Positive WS-LAP-012
ALR-00458 9h ago Suspicious Scheduled Task Medium Escalated WS-PC-006