#InvestigationPath
Investigation Scenario 🔎

A user workstation executed gpedit.msc for an unknown reason.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
January 28, 2025 at 3:00 PM
Investigation Scenario 🔎

While threat hunting, you’ve discovered a host receiving HTTPS traffic on port TCP/53.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
January 14, 2025 at 3:05 PM
Investigation Scenario 🔎

You’ve discovered a Windows system with screenshots of the user’s desktop in the %appdata%\ScreenShot\ directory.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
March 4, 2025 at 3:00 PM
Investigation Scenario 🔎

A user reports that all the files in their documents/desktop folders are gone after returning to the office on Monday. They swear they didn’t delete them.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
April 8, 2025 at 1:59 PM
Investigation Scenario 🔎

A server on your network suddenly sent DNS requests to several (100+) known malicious domains. but did not connect to them.

What do you look for to investigate the source and disposition of this event?

#InvestigationPath #DFIR #SOC
March 18, 2025 at 1:57 PM
Investigation Scenario 🔎

Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.

What do you examine next to determine who added the credential and whether it was used?

#InvestigationPath #DFIR #SOC
September 23, 2026 at 2:00 PM
Investigation Scenario 🔎

An employee was terminated for moonlighting with a competitor. While reviewing their Windows laptop, you find Slack is installed.

What do you look for to investigate their Slack use and if an incident occurred?

#InvestigationPath #DFIR #SOC
December 10, 2024 at 2:59 PM
Investigation Scenario 🔎

You retrieved a running process list from a single department of 20 Windows systems.

What is your approach to find anomalies in this data set? What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
February 25, 2025 at 3:00 PM
Investigation Scenario 🔎

While hunting through DNS traffic, you encounter a series of queries whose contents appear nonsensical.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
December 3, 2024 at 3:01 PM
Investigation Scenario 🔎

You discovered a suspicious PDF on a user’s workstation and found this sandbox report referencing it: app.any.run/tasks/e5ac2...

What do you look for to investigate whether the system was infected and its extent?

#InvestigationPath #DFIR #SOC
Analysis Details of transaction.pdf (MD5: F8C3A70DC433069C890B27B8361D6C2F) Malicious activity - Interactive analysis ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
app.any.run
February 11, 2025 at 3:00 PM
Investigation Scenario 🔎

You've discovered winword.exe as the parent process to files matching the following regular expression pattern: [a-z0-9]{4}\.tmp

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
June 10, 2025 at 2:00 PM
Investigation Scenario 🔎

Proxy logs show a Linux database server making HTTP requests with an empty User Agent string.

You don't have PCAP or other network logs.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
March 11, 2025 at 2:00 PM
Investigation Scenario 🔎

Using network traffic, you've observed an HTTP request to a Github Gist page that contains a comma-separated list of 10 IP addresses.

What do you look for to investigate whether an incident occurred and its source?

#InvestigationPath #DFIR #SOC
May 27, 2025 at 3:27 PM
Investigation Scenario 🔎

You received the depicted Suricata alert related to Impacket usage.

What do you look for to investigate whether an incident occurred and its extent?

#InvestigationPath #DFIR #SOC
November 26, 2024 at 3:00 PM
Investigation Scenario 🔎

Your CFO has returned from another country and they are concerned an untrusted party accessed their Mac laptop.

What do you look for to investigate whether an incident occurred? Where do you focus your first few steps?

#InvestigationPath #DFIR #SOC
February 18, 2025 at 3:00 PM
What do you look for to investigate whether an incident occurred?

Bonus Exercise: List several of the potential explanations for this behavior

#InvestigationPath #DFIR #SOC
July 28, 2026 at 2:00 PM
Investigation Scenario 🔎

You've observed a system making the following HTTP request to an unknown IP address:

GET /1742214432 HTTP/1.1

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
September 9, 2025 at 2:00 PM
Investigation Scenario 🔎

A host on your network executed a process whose parent process is mftrace.exe.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
June 17, 2025 at 2:01 PM
Investigation Scenario 🔎

A host on your network executed the command “netsh wlan show profile” for the first time.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
March 10, 2026 at 2:00 PM
Investigation Scenario 🔎

A macOS system performed a DNS query for a .onion domain.

The system doesn't have an EDR available -- only native logging.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
June 24, 2025 at 2:00 PM
Investigation Scenario 🔎

You received an alert that one of your honeydocs was opened on a network other than your own.

What do you look for to investigate whether an attacker exfiltrated this file from your network?

#InvestigationPath #DFIR #SOC
August 11, 2026 at 2:01 PM
Investigation Scenario 🔎

You've come across a log for the following execution:

msiexec.exe /i "\\10.0.0.5\share\patch.msi" /qn

The file is not available on the remote host.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
September 23, 2025 at 2:00 PM
Investigation Scenario 🔎

A public-facing web server is no longer accessible from the browser. Your director believes a denial of service attack may be the cause.

What do you look for to investigate the cause of the availability issue?

#InvestigationPath #DFIR #SOC
November 11, 2025 at 3:15 PM
Investigation Scenario 🔎

You have received an alert that ~300 registry keys were created and then deleted on a Windows system within a few minutes.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
May 6, 2025 at 2:00 PM
Investigation Scenario 🔎

You've found a new entry in ShimCache on Windows 10: C:\Users\Public\svchost32.exe with a last modified timestamp predating system boot.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC
December 2, 2025 at 2:30 PM