Module

First Look at a Compromised Windows Host

When an EDR alert fires on a Windows laptop, answer "is this host compromised, since when, and does it come off the network?" from its process tree, its connections, its persistence points and its logon history, then hand tier 2 a note they can act on, in about thirty minutes.

70 min · Beginner

Start First Look at a Compromised Windows Host

What you will learn

  • Isolate a laptop in Defender instead of shutting it down, and say what each option keeps and destroys
  • Read a process tree parent to child and decode a PowerShell -EncodedCommand
  • Tie a connection to its process with netstat -ano and find a beacon by its interval in connection history
  • Check scheduled tasks, Run keys and new services, and read a 4698 and its task XML
  • Build the timeline from the first malicious event, read logon types, search other hosts and write the handoff note

Lessons

  • Isolate or Look First

    A High EDR alert on a laptop someone is still using. Shutting it down throws away memory and the live connection; pulling the cable blinds the EDR. Isolate it in Defender, know what that keeps and what it costs, and make the call to the person at the desk.

  • The Process Tree Tells the Story

    explorer.exe started PowerShell with a hidden window and an encoded command, and PowerShell started something called svchost.exe from AppData. Read the tree parent to child, decode the command, and judge each process by where it lives and who started it.

  • Who Is It Talking To

    netstat shows a connection to 203.0.113.45:443 owned by the fake svchost.exe. Thirty-four seconds later it shows nothing. Tie each connection to its process, then find the beacon in Defender's history by its 60-second rhythm.

  • How It Plans to Come Back

    The 09:14 alert was the second run, started by a scheduled task, not a click. Check the three places tier 1 checks, read a 4698 and its task XML, and see why ending the process does not end the incident.

  • Since When, and Who Else

    The alert says 09:14 Thursday. The attack started at 16:51 Wednesday. Build the timeline from the first malicious event, read 4624 logon types to see whether anyone else came in, search every host for the same file and domain, and write the note tier 2 acts on.

More in this zone

First Look at a Compromised Windows Host | EpicDetect