A user workstation executed gpedit.msc for an unknown reason.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A user workstation executed gpedit.msc for an unknown reason.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
While threat hunting, you’ve discovered a host receiving HTTPS traffic on port TCP/53.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
While threat hunting, you’ve discovered a host receiving HTTPS traffic on port TCP/53.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You’ve discovered a Windows system with screenshots of the user’s desktop in the %appdata%\ScreenShot\ directory.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You’ve discovered a Windows system with screenshots of the user’s desktop in the %appdata%\ScreenShot\ directory.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A user reports that all the files in their documents/desktop folders are gone after returning to the office on Monday. They swear they didn’t delete them.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A user reports that all the files in their documents/desktop folders are gone after returning to the office on Monday. They swear they didn’t delete them.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A server on your network suddenly sent DNS requests to several (100+) known malicious domains. but did not connect to them.
What do you look for to investigate the source and disposition of this event?
#InvestigationPath #DFIR #SOC
A server on your network suddenly sent DNS requests to several (100+) known malicious domains. but did not connect to them.
What do you look for to investigate the source and disposition of this event?
#InvestigationPath #DFIR #SOC
Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.
What do you examine next to determine who added the credential and whether it was used?
#InvestigationPath #DFIR #SOC
Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.
What do you examine next to determine who added the credential and whether it was used?
#InvestigationPath #DFIR #SOC
An employee was terminated for moonlighting with a competitor. While reviewing their Windows laptop, you find Slack is installed.
What do you look for to investigate their Slack use and if an incident occurred?
#InvestigationPath #DFIR #SOC
An employee was terminated for moonlighting with a competitor. While reviewing their Windows laptop, you find Slack is installed.
What do you look for to investigate their Slack use and if an incident occurred?
#InvestigationPath #DFIR #SOC
You retrieved a running process list from a single department of 20 Windows systems.
What is your approach to find anomalies in this data set? What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You retrieved a running process list from a single department of 20 Windows systems.
What is your approach to find anomalies in this data set? What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
While hunting through DNS traffic, you encounter a series of queries whose contents appear nonsensical.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
While hunting through DNS traffic, you encounter a series of queries whose contents appear nonsensical.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You discovered a suspicious PDF on a user’s workstation and found this sandbox report referencing it: app.any.run/tasks/e5ac2...
What do you look for to investigate whether the system was infected and its extent?
#InvestigationPath #DFIR #SOC
You discovered a suspicious PDF on a user’s workstation and found this sandbox report referencing it: app.any.run/tasks/e5ac2...
What do you look for to investigate whether the system was infected and its extent?
#InvestigationPath #DFIR #SOC
You've discovered winword.exe as the parent process to files matching the following regular expression pattern: [a-z0-9]{4}\.tmp
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've discovered winword.exe as the parent process to files matching the following regular expression pattern: [a-z0-9]{4}\.tmp
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
Proxy logs show a Linux database server making HTTP requests with an empty User Agent string.
You don't have PCAP or other network logs.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
Proxy logs show a Linux database server making HTTP requests with an empty User Agent string.
You don't have PCAP or other network logs.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
Using network traffic, you've observed an HTTP request to a Github Gist page that contains a comma-separated list of 10 IP addresses.
What do you look for to investigate whether an incident occurred and its source?
#InvestigationPath #DFIR #SOC
Using network traffic, you've observed an HTTP request to a Github Gist page that contains a comma-separated list of 10 IP addresses.
What do you look for to investigate whether an incident occurred and its source?
#InvestigationPath #DFIR #SOC
You received the depicted Suricata alert related to Impacket usage.
What do you look for to investigate whether an incident occurred and its extent?
#InvestigationPath #DFIR #SOC
You received the depicted Suricata alert related to Impacket usage.
What do you look for to investigate whether an incident occurred and its extent?
#InvestigationPath #DFIR #SOC
Your CFO has returned from another country and they are concerned an untrusted party accessed their Mac laptop.
What do you look for to investigate whether an incident occurred? Where do you focus your first few steps?
#InvestigationPath #DFIR #SOC
Your CFO has returned from another country and they are concerned an untrusted party accessed their Mac laptop.
What do you look for to investigate whether an incident occurred? Where do you focus your first few steps?
#InvestigationPath #DFIR #SOC
Bonus Exercise: List several of the potential explanations for this behavior
#InvestigationPath #DFIR #SOC
Bonus Exercise: List several of the potential explanations for this behavior
#InvestigationPath #DFIR #SOC
You've observed a system making the following HTTP request to an unknown IP address:
GET /1742214432 HTTP/1.1
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've observed a system making the following HTTP request to an unknown IP address:
GET /1742214432 HTTP/1.1
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A host on your network executed a process whose parent process is mftrace.exe.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A host on your network executed a process whose parent process is mftrace.exe.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A host on your network executed the command “netsh wlan show profile” for the first time.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A host on your network executed the command “netsh wlan show profile” for the first time.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A macOS system performed a DNS query for a .onion domain.
The system doesn't have an EDR available -- only native logging.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A macOS system performed a DNS query for a .onion domain.
The system doesn't have an EDR available -- only native logging.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You received an alert that one of your honeydocs was opened on a network other than your own.
What do you look for to investigate whether an attacker exfiltrated this file from your network?
#InvestigationPath #DFIR #SOC
You received an alert that one of your honeydocs was opened on a network other than your own.
What do you look for to investigate whether an attacker exfiltrated this file from your network?
#InvestigationPath #DFIR #SOC
You've come across a log for the following execution:
msiexec.exe /i "\\10.0.0.5\share\patch.msi" /qn
The file is not available on the remote host.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've come across a log for the following execution:
msiexec.exe /i "\\10.0.0.5\share\patch.msi" /qn
The file is not available on the remote host.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
A public-facing web server is no longer accessible from the browser. Your director believes a denial of service attack may be the cause.
What do you look for to investigate the cause of the availability issue?
#InvestigationPath #DFIR #SOC
A public-facing web server is no longer accessible from the browser. Your director believes a denial of service attack may be the cause.
What do you look for to investigate the cause of the availability issue?
#InvestigationPath #DFIR #SOC
You have received an alert that ~300 registry keys were created and then deleted on a Windows system within a few minutes.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You have received an alert that ~300 registry keys were created and then deleted on a Windows system within a few minutes.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've found a new entry in ShimCache on Windows 10: C:\Users\Public\svchost32.exe with a last modified timestamp predating system boot.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've found a new entry in ShimCache on Windows 10: C:\Users\Public\svchost32.exe with a last modified timestamp predating system boot.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC