Interactive Demo — Simulated data only. Back to SOC in a Box
SOC365 Dashboard
Acme Legal Services Ltd Live 19:10:45 UTC

Suspicious Scheduled Task

Informational Open
ALR-00434 · 2026-05-21T03:18:19Z

Description

New scheduled task created on SRV-MAIL-01 by 'f.hall' running encoded batch script at 02:00 daily. No change request on file.

Alert Metadata

Alert ID
ALR-00434
Timestamp
2026-05-21T03:18:19Z
Severity
Informational
Status
Open
Detection Source
SOC365 Engine
Assigned Analyst
EmilyAI (auto)

Endpoint Information

Hostname
SRV-MAIL-01
User Account
f.hall
Source IP
91.231.195.32
Destination IP
10.0.142.81
Origin Country
DE Germany

MITRE ATT&CK Mapping

Tactic
Persistence
Technique
T1053.005
Reference
attack.mitre.org/techniques/T1053.005

Investigation Timeline

03:18:19 Event ingested by SOC365 Engine
03:18:20 EmilyAI triage started — correlation enrichment
03:18:25 EmilyAI confidence: 90% — escalated to human analyst
03:18:34 Alert assigned to analyst: EmilyAI (auto)
03:20:51 Investigation started — querying SIEM and threat intelligence

Related Alerts

ID Time Alert Severity Status Host
ALR-00451 4h ago Suspicious Scheduled Task Medium Resolved VM-DEV-01
ALR-00246 14h ago Suspicious Scheduled Task Low Resolved SRV-MAIL-01
ALR-00200 15h ago Suspicious Scheduled Task Medium False Positive WS-PC-003
ALR-00245 16h ago Certificate Anomaly Informational Escalated SRV-MAIL-01
ALR-00255 16h ago Rogue DHCP Server High Investigating SRV-MAIL-01