Table of Contents

Return to the Detection Engineering and Incident Response Course

The capstone joins engineering and response into one review package. Finish your submission before reading the reference answer.

Scenario

Your security operations lead asks for a detection and incident package based on the three course data files. The package must support analyst review, management decisions, and follow-up engineering work.

Required Deliverables

  1. Evidence record: filenames, hashes, counts, time zone, and source limits
  2. Detection strategy card: behavior, evidence, correlation, exclusions, escalation, and ATT&CK references
  3. Rule draft: Sigma-style YAML with status test
  4. Test matrix: two positive, two negative, and one boundary case
  5. Timeline: at least ten source-linked entries
  6. Scope statement: confirmed, likely, excluded, unknown, and as-of time
  7. Response plan: five action cards in order
  8. Recovery gates: identity, endpoint, mail, monitoring, and business
  9. Improvement backlog: six owned and testable items
  10. Executive update: five sentences or fewer

Constraints

  • Do not execute the encoded command.
  • Do not change source evidence.
  • Do not claim message export without message-access records.
  • Do not include FIN-LT-021 in confirmed scope without new evidence.
  • Label ATT&CK mappings as behavior mappings rather than proof.

Expected Result: another analyst reproduces your findings from the same files and understands every remaining uncertainty.

Reference Answer

Incident Decision

Declare a high-severity incident with high confidence in endpoint compromise and identity misuse. Treat the link between both paths as medium confidence until added provider or network evidence supports one actor or sequence.

Evidence Record

These SHA-256 values cover the exact supplied files as published for this course. Recalculate them from your downloads before and after analysis. All times below are UTC. Identity-provider, mail-access, proxy, and script-content records are absent.

FileLinesSHA-256
auth-events.jsonl8fa4bbaf8693287f884d5592f5d401ed66fb0087daada87ed4db6454d0d6de5cb
endpoint-events.jsonl8a3d053605d71798663ef947bb0f4424b0dfe2f0bbb6aa641c5820b5d5d9cdef1
dns-events.csv7, including header14ddb700e39a3dd46d428d5c0dcda01550baf04e74028fba7744813d551615a9

Core Timeline

Time UTCIDSupported interpretation
13:58:02E-2001Outlook writes a macro-enabled document
13:59:28E-2002Word opens the document
14:00:16E-2003Word starts encoded PowerShell
14:00:24D-3002The host resolves the suspicious test domain
14:00:31E-2004PowerShell writes sync-update.ps1
14:01:10E-2005A scheduled task creates persistence
14:02:49E-2006PowerShell connects to the DNS answer on TCP 443
14:04:09A-1004Legacy-protocol sign-in succeeds after failures
14:06:41A-1005A mailbox rule hides invoice mail
14:07:33A-1006A mail-reading OAuth grant is approved

The endpoint and identity chains overlap. Shared timing and identity support correlation, while the available sources do not prove a single actor or causal sequence.

Scope

As of 2026-06-18T15:00:00Z, confirmed scope includes Morgan’s identity and HR-LT-044. Likely scope includes mail reachable through the delegated grant. Exclude FIN-LT-021 after comparing its approved inventory chain. Unknowns include message access, script content, destination content, initial document delivery detail, and other activity tied to the indicators.

Detection Package

The strongest first rule detects Office starting encoded PowerShell. A second analytic should correlate the same host with a dropped script, scheduled task, DNS request, or outbound connection within a short window. Identity analytics should cover failed-to-successful legacy access, suspicious mailbox rule creation, and risky delegated consent.

Use this Sigma-style rule as the submitted draft. Its test status means no production validation is claimed. The backend field mapping and actual match results still need a local translator or SIEM test.

title: Office Process Starts Encoded PowerShell
id: 908e82a9-4f44-4f20-8da1-9e8af49fdb81
status: test
description: Detects an Office process starting PowerShell with an encoded command.
logsource:
  category: process_creation
  product: windows
detection:
  parent_office:
    ParentImage|endswith:
      - '\\WINWORD.EXE'
      - '\\EXCEL.EXE'
      - '\\POWERPNT.EXE'
  child_powershell:
    Image|endswith:
      - '\\powershell.exe'
      - '\\pwsh.exe'
  encoded_flag:
    CommandLine|contains:
      - '-EncodedCommand'
      - '-enc '
  condition: parent_office and child_powershell and encoded_flag
falsepositives:
  - Approved document automation after environment review
level: high

The strategy card names Office-to-PowerShell execution, process parent and command-line fields, a 60-second host/user correlation window, approved automation as an exclusion candidate, and persistence or outbound activity as escalation evidence. Map the PowerShell behavior to T1059.001 and the scheduled-task evidence separately to T1053.005. Neither mapping proves malicious intent.

CaseInput shapeExpected rule resultObserved result
Positive 1Word starts PowerShell with -EncodedCommandMatchOffline checker: match
Positive 2Excel starts pwsh.exe with -encMatchOffline checker: match
Negative 1Software Center starts an approved PowerShell fileNo matchOffline checker: no match
Negative 2Word starts a PDF viewerNo matchOffline checker: no match
BoundaryWord starts PowerShell without an encoded flagNo match, review separate analyticOffline checker: no match

The supplied offline checker and five cases produced 5/5 passed, exit code 0, and zero matches among the two negative cases. For full offline credit, run the checker yourself, attach its output, and map its three predicates to the Sigma selections. Mark the backend query not run, no SIEM translator available. For a SIEM-backed submission, also attach the translated query, field mapping, observed results, and false-positive count. The offline checker does not execute the YAML or prove production behavior.

Response Priorities

Preserve evidence, isolate the endpoint, restrict the identity, revoke sessions and grants, remove the preserved mailbox rule, collect artifacts, recover credentials, rebuild from trusted media, pass recovery gates, and monitor recurrence.

The incident commander may collect volatile endpoint evidence before isolation if active harm is controlled. If active exfiltration continues, contain first and record the evidence tradeoff. Use these five action-card exemplars:

Action and ownerEvidence and approval before changeSuccess checkRollback or recovery
Isolate HR-LT-044, endpoint leadIncident commander approval, endpoint and volatile data decisionHost loses unapproved network pathsRestore approved connectivity after trusted rebuild
Restrict Morgan’s identity, identity leadExport sign-in and session records, approve business interruptionOld sessions fail and new access uses approved MFATemporary scoped access through incident authority
Revoke OAuth grant, identity leadPreserve consent and application IDsGrant absent and old token path failsReauthorize a reviewed app if business owner confirms need
Remove mailbox rule, mail leadExport rule definition and message traceRule absent and new mail follows normal routingRestore only a verified business rule
Rebuild endpoint, endpoint leadPreserve document, script, task, hashes, and chain of custodyTrusted image boots, old task absent, detections healthyKeep device isolated and restore approved backup

Each action card needs a timestamp and approval ID in the learner’s submitted package.

Recovery gateEvidence required before closure
IdentityCredential and factor recovery, session revocation, consent review
EndpointTrusted rebuild, patches, healthy agent, no old task or script
MailRule review and message trace preserved
MonitoringBehavior detections active with owner, expiry, and test result
BusinessService owner accepts restored function and residual risk
Improvement itemOwnerValidation
Limit legacy authenticationIdentity engineeringTest a blocked legacy sign-in and approved modern sign-in
Alert on risky delegated consentIdentity engineeringReplay a synthetic consent event into the alert path
Keep process parent and command lineEndpoint engineeringVerify both fields arrive from a managed test host
Detect unsanctioned scheduled tasksDetection engineeringPositive and approved-task negative replay
Correlate DNS and endpoint connectionsNetwork engineeringResolve and connect in an isolated test, verify host join
Tune Office-to-PowerShell ruleSOC detection ownerRun five-case matrix and record alert volume

Executive Update

Security declared an incident involving one employee identity and one managed
Windows endpoint. Evidence shows suspicious cloud access, delegated mail access,
document-driven script execution, persistence, and outbound communication.
Containment and evidence preservation are in progress. Mail access volume and
the script's full behavior remain under investigation, with the next update due
after identity and endpoint collection finishes.

Scoring Rubric

AreaPointsFull-credit evidence
Evidence handling15Stable hashes, counts, UTC, preserved sources, stated limits
Detection design20Behavior hypothesis, current ATT&CK objects, rule, tests, runbook
Investigation25Reproducible timeline, alternatives, supported findings
Scope15Confirmed, likely, excluded, unknown, as-of time
Response15Ordered cards, authority, rollback, success checks
Communication10Short, factual update with impact and unknowns

Passing score: 80 points with no evidence-integrity failure.

Troubleshooting

  • Your timeline differs: compare UTC parsing and correlation IDs.
  • Your scope is broader: identify direct evidence for each added entity.
  • Your rule matches inventory work: tighten parent process and encoded flag logic.
  • Your response starts with deletion: move preservation and authority checks first.

Verify Completion

  • All ten deliverables exist
  • Source hashes stayed stable
  • Findings cite event IDs
  • Answer key comparison records corrections
  • Final score meets the threshold

Return to the course hub and retain the package as a synthetic portfolio sample.