Week 4
Investigate a Living-off-the-Land PowerShell Attack
Client Background
Atlas Manufacturing runs a flat internal network of Windows servers. EDR raised a medium alert for encoded PowerShell on a finance server; the SOC must determine whether it is malicious or admin activity.
Business Environment
You are the Tier-2 SOC analyst. You have Windows Security event logs (4688 process creation with command lines), PowerShell Script Block logs (4104), and EDR alerts for the finance server FS-FIN-04.
Security Incident
At 02:11, an encoded PowerShell command ran on FS-FIN-04, decoded to download and invoke a script from an external IP. Minutes later, WMIexec-style lateral activity targeted a domain controller.
Scope
Windows event logs and PowerShell logs on FS-FIN-04 and the targeted domain controller DC01. Excludes full memory forensics.
Objectives
- Decode and assess the suspicious PowerShell payload
- Determine initial access and the parent process chain
- Trace lateral movement to the domain controller
- Identify persistence and recommend eradication
- Account for modern Windows kernel protections (Credential Guard, PPL) in the LOL attack timeline and note that legacy auth (NTLMv1/RC4/DES) is disabled by default in 2026 enterprise baselines, elevating modern LOLBAS lateral paths.
Required Deliverables