Browser LabLD-SOC2-LAB-009Hard
Browser LabLD-SOC2-LAB-009Hard22 min
Run the Incident From Escalation to Closure
Module 8's hunt escalated a live intrusion: WINWORD spawned mshta.exe on FIN-WS-12, which is beaconing to C2 now, and the same foothold appears on other hosts. You are the incident responder. Drive the lifecycle without destroying evidence or leaving the attacker a way back.
What you will be able to do
- Identify the first response phase and an evidence-preserving containment action.
- Scope the intrusion before eradicating.
- Eradicate the attacker's footholds and close with lessons learned.
Incident TriageAnalyst ReportingT1218.005 — System Binary Proxy Execution: MshtaT1547.001 — Boot or Logon Autostart Execution: Registry Run KeysT1053.005 — Scheduled Task/Job: Scheduled Task
Sign in to start this lab.
Sign in