Browser LabLD-SYSMON-LAB-001Easy
Browser LabLD-SYSMON-LAB-001Easy15 min
Follow the Lineage
An alert fired on encoded PowerShell on FIN-07. You have the Sysmon Event ID 1 (process create) excerpt. Trace the lineage and name the malicious parent that started the chain.
What you will be able to do
- Reconstruct parent/child lineage from Event ID 1.
- Identify the macro-execution parent.
Windows SecurityIncident TriageT1566.001 — Spearphishing AttachmentT1059.001 — PowerShell
Sign in to start this lab.
Sign in