Browser LabLD-SOC2-LAB-003Hard
Browser LabLD-SOC2-LAB-003Hard22 min
Deep-Dive a Compromised Workstation
An EDR alert flagged 'unusual process on FIN-WS-09'. Tier-1 could not tell attacker from admin. You have the host's process telemetry, its persistence-creation events, and its logon record. Read the host deeply and reconstruct what happened.
What you will be able to do
- Read the process ancestry and command line to find the dropped payload and its parent.
- Identify the persistence mechanism and the initial-access logon type.
- Map the persistence to its ATT&CK technique.
Windows SecurityLog AnalysisT1059.001 — Command and Scripting Interpreter: PowerShellT1053.005 — Scheduled Task/Job: Scheduled TaskT1021.001 — Remote Services: Remote Desktop Protocol
Sign in to start this lab.
Sign in