Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SYSMON-LAB-001Easy
Browser LabLD-SYSMON-LAB-001Easy15 min

Follow the Lineage

An alert fired on encoded PowerShell on FIN-07. You have the Sysmon Event ID 1 (process create) excerpt. Trace the lineage and name the malicious parent that started the chain.

What you will be able to do

  • Reconstruct parent/child lineage from Event ID 1.
  • Identify the macro-execution parent.
Windows SecurityIncident TriageT1566.001Spearphishing AttachmentT1059.001PowerShell

Sign in to start this lab.

Sign in