Back to category

Week 4

Investigate a Living-off-the-Land PowerShell Attack

Intermediate
SOC Analyst
Threat Hunter
Incident Responder
MITRE ATT&CK
NIST CSF
NIST CSF 2.0
PowerShell Forensics
LOLBAS Analysis
Lateral Movement Detection
Windows Event Log Analysis

Client Background

Atlas Manufacturing runs a flat internal network of Windows servers. EDR raised a medium alert for encoded PowerShell on a finance server; the SOC must determine whether it is malicious or admin activity.

Business Environment

You are the Tier-2 SOC analyst. You have Windows Security event logs (4688 process creation with command lines), PowerShell Script Block logs (4104), and EDR alerts for the finance server FS-FIN-04.

Security Incident

At 02:11, an encoded PowerShell command ran on FS-FIN-04, decoded to download and invoke a script from an external IP. Minutes later, WMIexec-style lateral activity targeted a domain controller.

Scope

Windows event logs and PowerShell logs on FS-FIN-04 and the targeted domain controller DC01. Excludes full memory forensics.

Objectives

  • Decode and assess the suspicious PowerShell payload
  • Determine initial access and the parent process chain
  • Trace lateral movement to the domain controller
  • Identify persistence and recommend eradication
  • Account for modern Windows kernel protections (Credential Guard, PPL) in the LOL attack timeline and note that legacy auth (NTLMv1/RC4/DES) is disabled by default in 2026 enterprise baselines, elevating modern LOLBAS lateral paths.

Required Deliverables

Investigation Report
MITRE ATT&CK Mapping
4 hrs estimated