Browser LabLD-SOC1-LAB-012Medium
Browser LabLD-SOC1-LAB-012Medium20 min
First Moves on a Confirmed Incident
EDR has CONFIRMED a compromise on WS-042: a finance user clicked a phishing link, PowerShell ran, and the host is beaconing to an external controller right now. The user has access to the payment system. The incident is real — your job is the first moves. Make each response decision in the right order: what to preserve, how to contain without destroying evidence, what NOT to do yet, and how urgently to escalate.
What you will be able to do
- Preserve volatile evidence before acting
- Choose a containment that stops the attacker without destroying evidence
- Respect the response order and escalate with the right urgency
Incident TriageAnalyst ReportingT1566.002 — Phishing: Spearphishing LinkT1071.001 — Application Layer Protocol: Web Protocols
Sign in to start this lab.
Sign in