#investigationpath

3 posts · Last used Jul 21

Investigation Scenario 🔎 Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation. No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command? To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion? #InvestigationPath #DFIR #SOC
3
1
4
0
Investigation Scenario 🔎 A Windows 11 workstation’s Microsoft-Windows-TaskScheduler/Operational log contains Event ID 106, indicating a new scheduled task named "OneDrive Update Service" was registered at 5:45 PM local time. The user insists they were away from the computer when this happened. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
1
2
0
0
You've seen all posts