Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC2-LAB-009Hard
Browser LabLD-SOC2-LAB-009Hard22 min

Run the Incident From Escalation to Closure

Module 8's hunt escalated a live intrusion: WINWORD spawned mshta.exe on FIN-WS-12, which is beaconing to C2 now, and the same foothold appears on other hosts. You are the incident responder. Drive the lifecycle without destroying evidence or leaving the attacker a way back.

What you will be able to do

  • Identify the first response phase and an evidence-preserving containment action.
  • Scope the intrusion before eradicating.
  • Eradicate the attacker's footholds and close with lessons learned.
Incident TriageAnalyst ReportingT1218.005System Binary Proxy Execution: MshtaT1547.001Boot or Logon Autostart Execution: Registry Run KeysT1053.005Scheduled Task/Job: Scheduled Task

Sign in to start this lab.

Sign in