Browser LabLD-SYSMON-LAB-003Medium
Browser LabLD-SYSMON-LAB-003Medium16 min
Signal or Noise?
Two process chains fired similar-looking events. One is a benign admin tool; the other is an intrusion. Use lineage and context to tell them apart — not every PowerShell is an attack.
What you will be able to do
- Distinguish benign automation from malicious execution.
- Justify the verdict from lineage and context.
Windows SecurityIncident TriageT1059.001 — PowerShell
Sign in to start this lab.
Sign in