Suspicious Scheduled Task
High
Open
ALR-00482 · 2026-04-12T11:11:01Z
Description
New scheduled task created on AP-WIFI-03 by 'k.brown' running encoded batch script at 02:00 daily. No change request on file.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
11:11:01
Event ingested by SOC365 Engine
11:11:04
EmilyAI triage started — correlation enrichment
11:11:11
EmilyAI confidence: 93% — escalated to human analyst
11:11:42
Alert assigned to analyst: Marcus Webb
11:11:58
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00380 | 2h ago | Suspicious Scheduled Task | Low | Escalated | WS-PC-001 |
| ALR-00263 | 2h ago | Suspicious Scheduled Task | Critical | Escalated | WS-LAP-010 |
| ALR-00397 | 14h ago | Unusual Outbound Traffic | Low | Escalated | AP-WIFI-03 |
| ALR-00330 | 17h ago | Suspicious Scheduled Task | High | Open | FW-EDGE-01 |
| ALR-00413 | 1d ago | Ransomware Behaviour Detected | Medium | Open | AP-WIFI-03 |