Testing CS
Prompt
You're a SOC analyst. At 02:14 UTC, EDR flags winword.exe spawning cmd.exe, which spawns powershell.exe -enc <base64>. Ten minutes later, the same host makes DNS requests to a domain with high-entropy subdomains at a fixed 60-second interval. At 02:40, the host authenticates to a file server over SMB using a domain admin account that has never logged in from this machine. 1. Reconstruct the likely attack chain and map each stage to MITRE ATT&CK techniques. 2. Explain what the DNS pattern suggests, and give two alternative benign explanations. 3. What's the most urgent containment decision, and what's the tradeoff? 4. List the five most valuable log sources to pull next, and what you'd look for in each. 5. What single piece of evidence would make you reconsider your hypothesis?
Response not available
Response not available