Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC2-LAB-003Hard
Browser LabLD-SOC2-LAB-003Hard22 min

Deep-Dive a Compromised Workstation

An EDR alert flagged 'unusual process on FIN-WS-09'. Tier-1 could not tell attacker from admin. You have the host's process telemetry, its persistence-creation events, and its logon record. Read the host deeply and reconstruct what happened.

What you will be able to do

  • Read the process ancestry and command line to find the dropped payload and its parent.
  • Identify the persistence mechanism and the initial-access logon type.
  • Map the persistence to its ATT&CK technique.
Windows SecurityLog AnalysisT1059.001Command and Scripting Interpreter: PowerShellT1053.005Scheduled Task/Job: Scheduled TaskT1021.001Remote Services: Remote Desktop Protocol

Sign in to start this lab.

Sign in