
Documented incident response case for CVE-2024-49138 exploitation, featuring log analysis, hash validation, C2 detection, and containment procedures for SOC training.
C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exeb432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9This repository documents an incident response case involving logon failures, malicious activity detection, and containment efforts.
We start by investigating the alert received and proceed to analyze logs from Log Management and Endpoint Security.
There are multiple OS types, with either Admin or Guest accounts showing Error Code 0xC000006D.
We analyzed the hash provided in the alert and confirmed it as malicious. MITRE ATT&CK framework mapping and malware behavior were also validated.
By inspecting terminal history, we identified suspicious activity, including a $url command retrieving a potentially malicious URL.
Using the gathered information, we proceeded with the appropriate playbook steps for this case.
We analyzed the malware behavior via AnyRun and identified the Command and Control (C2) address. This was confirmed through network behavior analysis.
We successfully contained the affected device.
We finalized the case with SOC Analyst notes and playbook execution documentation.
The case was closed with a final review and scoring to assess the accuracy of actions taken during the investigation.
0xC000006D logon failures is critical for identifying suspicious activity.This repository serves as a reference for handling similar incidents. Contributions and discussions are welcome!
C:\Windows\System32\svchost.exe -k termsvcs -s TermServiceC:\Windows\System32\svchost.exe:
C:\Windows\System32\.-k termsvcs:
termsvcs) for this instance of svchost.exe.termsvcs group is specifically related to Terminal Services.-s TermService:
TermServiceC:\Windows\system32\svchost.exe -k netsvcs -p -s ScheduleC:\Windows\system32\svchost.exe:
C:\Windows\system32\.-k netsvcs:
netsvcs) that this instance of svchost.exe is hosting.netsvcs group typically includes networking-related and other essential services.-p:
-s Schedule:
Schedule).Process ID:
svchost.exe managing the Task Scheduler service.C:\Windows\system32\svchost.exe -k DcomLaunch -p