HOST: WKSTN-014 · USER: james.porter · 11:34 UTC
The EDR platform fired a CRITICAL alert on workstation WKSTN-014 assigned to James Porter (Sales Department). The alert flagged an unknown process making repeated outbound connections to an external IP. James reported his machine has been running slowly since yesterday morning and he noticed a brief command prompt window flash on screen when he logged in.
| Property | Value |
|---|---|
| Hostname | WKSTN-014 |
| User | james.porter |
| OS | Windows 11 Pro 23H2 |
| IP | 10.10.14.22 |
| Dept | Sales |
| Last Login | 2026-05-08 08:47 UTC |
Alert Type: Suspicious Outbound Network Connection
Process: svchost32.exe (note: NOT the legitimate svchost.exe)
Connection: Repeated beaconing every 60 seconds to external IP
Severity: CRITICAL
Legitimate Windows svchost.exe always runs from C:\Windows\System32\ and is always a child of services.exe. Any deviation from this is a strong IOC.