Incident Response Lesson 5: Full Investigation Lab
Table of Contents
Return to the Detection Engineering and Incident Response Course
This lab uses synthetic evidence to investigate one compromise. Preserve the source files, record every query, and keep unsupported details marked unknown.
Lab Goal
Deliver four artifacts:
- A source and hash record
- A UTC incident timeline
- A scope and findings report
- A next-search plan
Download authentication events , endpoint events , and DNS events .
Step 1: Verify Sources
shasum -a 256 auth-events.jsonl endpoint-events.jsonl dns-events.csv
wc -l auth-events.jsonl endpoint-events.jsonl dns-events.csv
Expected record counts:
8 auth events
8 endpoint events
7 DNS CSV lines, including the header
If counts differ, download the files again before analysis.
Step 2: Find Entities
jq -r '[.timestamp, (.host // .device), .user, .event_type, (.source_ip // .destination_ip // "-")] | @tsv' \
auth-events.jsonl endpoint-events.jsonl
List unique users, hosts, IP addresses, domains, hashes, application names, rule names, and task names. Mark documentation addresses and .test domains as synthetic indicators.
Expected high-interest entities include:
- Identity:
[email protected] - Host:
HR-LT-044 - Source IP:
203.0.113.77 - Destination IP:
203.0.113.90 - Domain:
cdn-sync.example.test - Task:
Document Sync Update - Application:
Document Sync Test
Step 3: Build the Timeline
Create a table with source, event ID, fact, and interpretation. Include at least these turning points:
E-2001creates the document.E-2002opens the document from Outlook.E-2003launches encoded PowerShell.E-2004writes a script.E-2005creates persistence.A-1004records suspicious legacy-protocol access.A-1005creates a mailbox rule.A-1006grants application consent.D-3002throughD-3004resolve the suspicious domain.E-2006connects to the matching destination.
The identity and endpoint chains overlap in time. The evidence does not establish whether one actor controlled both paths. Treat shared timing and user identity as correlation, then seek provider and network detail.
Step 4: Test Alternatives
Test at least three explanations:
| Explanation | Supporting evidence | Contradicting evidence |
|---|---|---|
| Approved document automation | Office starts PowerShell in some business workflows | Encoded content, persistence, new destination, and unknown script lack approval records |
| User travel | A sign-in from another country might follow travel | Earlier US activity, unknown device, legacy protocol, mailbox rule, and consent raise risk |
| Approved inventory task | FIN-LT-021 uses PowerShell | Different parent, script path, destination, user, and approved script label separate the event |
Do not label an explanation false without evidence. Record which owner or log source would resolve the question.
Step 5: State Findings
Use evidence-strength labels.
Finding 1, high confidence: A document opened from Outlook started encoded
PowerShell on HR-LT-044, wrote a script, created a scheduled task, and connected
to 203.0.113.90 after resolving cdn-sync.example.test.
Finding 2, high confidence: Morgan's cloud identity completed a legacy-protocol
sign-in from 203.0.113.77 after two failures, then created a mailbox rule and
granted Mail.Read plus offline_access to Document Sync Test.
Finding 3, medium confidence: The endpoint and identity activity belong to one
incident. Shared identity and close timing support the link. Missing message,
proxy, and decoded-script evidence limit the claim.
Step 6: Define Scope
Confirmed scope includes Morgan and HR-LT-044. Likely scope includes mailbox data available to the consented application. Exclude FIN-LT-021 with written rationale. Keep data access volume and the script’s full behavior unknown.
Expected Result: your report declares an incident, supports two high-confidence findings, states one medium-confidence correlation, and lists unresolved evidence.
Troubleshooting
| Problem | Fix |
|---|---|
| JSON and CSV rows do not merge cleanly | Normalize selected fields into a separate analyst table |
| Time order looks wrong | Sort full UTC timestamps as text and preserve the trailing Z |
| Encoded content tempts execution | Do not execute the content. Record the value and use an approved isolated decoder workflow |
| A conclusion lacks an event ID | Rewrite the claim as a question or collect supporting evidence |
Verify Your Work
- Source hashes match before and after analysis
- Timeline contains all ten turning points
- Findings separate facts from conclusions
- Alternate explanations include supporting and contradicting evidence
- Scope includes confirmed, likely, excluded, and unknown items
- Next searches name identity, endpoint, mail, and network owners
Next Steps
Continue to Lesson 6: Containment and Recovery . Choose actions in an order which preserves evidence and limits harm.


