Help!!

I recently worked on a malware forensic analysis where, after reviewing the available artifacts, I was able to determine that the malware .exe was executed via GPO on AD.

However, I’m struggling with the next step: how do I determine how the attacker initially gained access and how the malware was introduced into the environment?

For those with experience, what artifacts or investigation techniques do you usually rely on to identify the initial access vector?

reddit.com
u/ShadyMoh1998 — 1 day ago
▲ 3 r/GIAC

Need Advice

Due to some circumstances, I’m down to just one month before my GCIH exam. Do you think it’s still possible to make it, or should I consider getting an extension?

What do you guys think?

reddit.com
u/ShadyMoh1998 — 12 days ago

Interview Help!!!

What kind of SOAR-related questions might you ask me? I haven't had the chance to work with SOAR yet, so I'd like to know what I should prepare for.

reddit.com
u/ShadyMoh1998 — 24 days ago

Help!!

I'm working on my first malware forensics case and could use some advice.

We had malware spread across multiple machines, and I know which system was patient zero. Unfortunately, Kaspersky disinfected the infected machines and they were rebooted before I could acquire a forensic image.

At this point, I'm trying to determine how the malware initially got onto the patient zero machine.

Where would you start looking? What artifacts or logs would you prioritize, given that I no longer have a pre-disinfection image?

I'm having trouble thinking through the proper investigation steps, so any guidance, methodology, or resources would be greatly appreciated.

reddit.com
u/ShadyMoh1998 — 27 days ago

Help!!

I'm working on my first malware forensics case and could use some advice.

We had malware spread across multiple machines, and I know which system was patient zero. Unfortunately, Kaspersky disinfected the infected machines and they were rebooted before I could acquire a forensic image.

At this point, I'm trying to determine how the malware initially got onto the patient zero machine.

Where would you start looking? What artifacts or logs would you prioritize, given that I no longer have a pre-disinfection image?

I'm having trouble thinking through the proper investigation steps, so any guidance, methodology, or resources would be greatly appreciated.

reddit.com
u/ShadyMoh1998 — 27 days ago

SOC L2 Interview

Has anyone here interviewed for a SOC Analyst L2 role?

What were the hardest technical questions or scenarios you were asked? Any tips on what to focus on?

reddit.com
u/ShadyMoh1998 — 1 month ago