Table of Contents

Return to the Detection Engineering and Incident Response Course

This lab uses synthetic evidence to investigate one compromise. Preserve the source files, record every query, and keep unsupported details marked unknown.

Lab Goal

Deliver four artifacts:

  • A source and hash record
  • A UTC incident timeline
  • A scope and findings report
  • A next-search plan

Download authentication events , endpoint events , and DNS events .

Step 1: Verify Sources

shasum -a 256 auth-events.jsonl endpoint-events.jsonl dns-events.csv
wc -l auth-events.jsonl endpoint-events.jsonl dns-events.csv

Expected record counts:

8 auth events
8 endpoint events
7 DNS CSV lines, including the header

If counts differ, download the files again before analysis.

Step 2: Find Entities

jq -r '[.timestamp, (.host // .device), .user, .event_type, (.source_ip // .destination_ip // "-")] | @tsv' \
  auth-events.jsonl endpoint-events.jsonl

List unique users, hosts, IP addresses, domains, hashes, application names, rule names, and task names. Mark documentation addresses and .test domains as synthetic indicators.

Expected high-interest entities include:

  • Identity: [email protected]
  • Host: HR-LT-044
  • Source IP: 203.0.113.77
  • Destination IP: 203.0.113.90
  • Domain: cdn-sync.example.test
  • Task: Document Sync Update
  • Application: Document Sync Test

Step 3: Build the Timeline

Create a table with source, event ID, fact, and interpretation. Include at least these turning points:

  1. E-2001 creates the document.
  2. E-2002 opens the document from Outlook.
  3. E-2003 launches encoded PowerShell.
  4. E-2004 writes a script.
  5. E-2005 creates persistence.
  6. A-1004 records suspicious legacy-protocol access.
  7. A-1005 creates a mailbox rule.
  8. A-1006 grants application consent.
  9. D-3002 through D-3004 resolve the suspicious domain.
  10. E-2006 connects to the matching destination.

The identity and endpoint chains overlap in time. The evidence does not establish whether one actor controlled both paths. Treat shared timing and user identity as correlation, then seek provider and network detail.

Step 4: Test Alternatives

Test at least three explanations:

ExplanationSupporting evidenceContradicting evidence
Approved document automationOffice starts PowerShell in some business workflowsEncoded content, persistence, new destination, and unknown script lack approval records
User travelA sign-in from another country might follow travelEarlier US activity, unknown device, legacy protocol, mailbox rule, and consent raise risk
Approved inventory taskFIN-LT-021 uses PowerShellDifferent parent, script path, destination, user, and approved script label separate the event

Do not label an explanation false without evidence. Record which owner or log source would resolve the question.

Step 5: State Findings

Use evidence-strength labels.

Finding 1, high confidence: A document opened from Outlook started encoded
PowerShell on HR-LT-044, wrote a script, created a scheduled task, and connected
to 203.0.113.90 after resolving cdn-sync.example.test.

Finding 2, high confidence: Morgan's cloud identity completed a legacy-protocol
sign-in from 203.0.113.77 after two failures, then created a mailbox rule and
granted Mail.Read plus offline_access to Document Sync Test.

Finding 3, medium confidence: The endpoint and identity activity belong to one
incident. Shared identity and close timing support the link. Missing message,
proxy, and decoded-script evidence limit the claim.

Step 6: Define Scope

Confirmed scope includes Morgan and HR-LT-044. Likely scope includes mailbox data available to the consented application. Exclude FIN-LT-021 with written rationale. Keep data access volume and the script’s full behavior unknown.

Expected Result: your report declares an incident, supports two high-confidence findings, states one medium-confidence correlation, and lists unresolved evidence.

Troubleshooting

ProblemFix
JSON and CSV rows do not merge cleanlyNormalize selected fields into a separate analyst table
Time order looks wrongSort full UTC timestamps as text and preserve the trailing Z
Encoded content tempts executionDo not execute the content. Record the value and use an approved isolated decoder workflow
A conclusion lacks an event IDRewrite the claim as a question or collect supporting evidence

Verify Your Work

  • Source hashes match before and after analysis
  • Timeline contains all ten turning points
  • Findings separate facts from conclusions
  • Alternate explanations include supporting and contradicting evidence
  • Scope includes confirmed, likely, excluded, and unknown items
  • Next searches name identity, endpoint, mail, and network owners

Next Steps

Continue to Lesson 6: Containment and Recovery . Choose actions in an order which preserves evidence and limits harm.