Module
First Look at a Compromised Windows Host
When an EDR alert fires on a Windows laptop, answer "is this host compromised, since when, and does it come off the network?" from its process tree, its connections, its persistence points and its logon history, then hand tier 2 a note they can act on, in about thirty minutes.
70 min · Beginner
Start First Look at a Compromised Windows Host
What you will learn
- Isolate a laptop in Defender instead of shutting it down, and say what each option keeps and destroys
- Read a process tree parent to child and decode a PowerShell -EncodedCommand
- Tie a connection to its process with netstat -ano and find a beacon by its interval in connection history
- Check scheduled tasks, Run keys and new services, and read a 4698 and its task XML
- Build the timeline from the first malicious event, read logon types, search other hosts and write the handoff note
Lessons
Isolate or Look First
A High EDR alert on a laptop someone is still using. Shutting it down throws away memory and the live connection; pulling the cable blinds the EDR. Isolate it in Defender, know what that keeps and what it costs, and make the call to the person at the desk.
The Process Tree Tells the Story
explorer.exe started PowerShell with a hidden window and an encoded command, and PowerShell started something called svchost.exe from AppData. Read the tree parent to child, decode the command, and judge each process by where it lives and who started it.
Who Is It Talking To
netstat shows a connection to 203.0.113.45:443 owned by the fake svchost.exe. Thirty-four seconds later it shows nothing. Tie each connection to its process, then find the beacon in Defender's history by its 60-second rhythm.
How It Plans to Come Back
The 09:14 alert was the second run, started by a scheduled task, not a click. Check the three places tier 1 checks, read a 4698 and its task XML, and see why ending the process does not end the incident.
Since When, and Who Else
The alert says 09:14 Thursday. The attack started at 16:51 Wednesday. Build the timeline from the first malicious event, read 4624 logon types to see whether anyone else came in, search every host for the same file and domain, and write the note tier 2 acts on.