Investigation Scenario 🔎
Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation.
No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command?
To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion?
#InvestigationPath #DFIR #SOC
#investigationpath
3 posts · Last used Jul 21
Investigation Scenario 🔎
A Windows 11 workstation’s Microsoft-Windows-TaskScheduler/Operational log contains Event ID 106, indicating a new scheduled task named "OneDrive Update Service" was registered at 5:45 PM local time. The user insists they were away from the computer when this happened.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
Investigation Scenario 🔎
You’ve found ~/.config/systemd/user/dbus-update.service enabled for a user account on an Ubuntu system. The service executes ~/.local/bin/dbus-update, an ELF binary that isn’t owned by any installed package.
What do you look for to investigate whether an incident occurred?
#InvestigationPath #DFIR #SOC
You've seen all posts