#investigationpath

3 posts · Last used 24d

Back to Timeline
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange · Jul 21, 2026
Investigation Scenario 🔎 Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation. No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command? To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion? #InvestigationPath #DFIR #SOC
0
1
0
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange · Jul 14, 2026
Investigation Scenario 🔎 A Windows 11 workstation’s Microsoft-Windows-TaskScheduler/Operational log contains Event ID 106, indicating a new scheduled task named "OneDrive Update Service" was registered at 5:45 PM local time. The user insists they were away from the computer when this happened. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
0
2
0
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange · Jul 07, 2026
Investigation Scenario 🔎 You’ve found ~/.config/systemd/user/dbus-update.service enabled for a user account on an Ubuntu system. The service executes ~/.local/bin/dbus-update, an ELF binary that isn’t owned by any installed package. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
0
1
0

You've seen all posts