Knowledgebase

Viewing articles tagged 'Incident Response'

PowerShell Providers: Navigate the Registry Like a Filesystem A managed services client called us at 2 AM because a fleet of 180 Windows Server 2022 boxes had stopped autoloading their LOB agent after a botched GPO push. The Powe… Multipartite Virus: Hunting Multi-Vector Malware in Production A manufacturing client called us on a Tuesday morning with a problem that didn’t add up. Their endpoint agent had flagged and quarantined a suspicious executable on th… MITRE ATT&CK Integration in Tabletop Exercises: A Checklist Last quarter, we facilitated a tabletop exercise for a financial services client. Their CISO was confident the IR team could handle a ransomware scenario. Forty-five m… Internal vs External IP Analysis in Threat Hunting Your SIEM fires a high-severity alert at 3 AM. A workstation on the finance VLAN just made an outbound connection to an IP address flagged in three threat intelligence… Windows USB Forensics: Tracking External Device Connections A financial services client called us on a Friday afternoon. Their DLP solution flagged 14 GB of data copied to a removable device, but the employee had already left t… Ransomware Encryption Analysis: Attack Mechanics on Windows A managed services client called our SOC at 2:14 AM on a Tuesday. Their file server was throwing access denied errors across three departments. By 2:20 AM we had confi… Using Autoruns to Audit Every Windows Autostart Location During a quarterly security review for a client running a 200-seat Windows environment, we found a DLL registered under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersi… Forensic Triage on Windows: Rapid Evidence Collection Your SIEM flags a suspicious PowerShell execution on a domain controller at 11:43 PM. The endpoint detection tool confirms process injection consistent with MITRE ATT&… Digital Forensics for Incident Response: Field Guide Three weeks into a ransomware investigation at a mid-size logistics firm, the IR team handed me what they called a “forensic copy” of the infected server. It had been… Cybersecurity Naming Conventions: A Complete IT Guide Cybersecurity naming conventions are standardized rules for labeling digital assets – including user accounts, firewall rules, log files, and security policies. Organi… Windows Digital Forensics Guide for IT Security Teams When a security incident occurs on a Windows system, the clock starts ticking immediately. Every action taken – or not taken – can determine whether critical evidence…
Back