Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SOC335---CVE-2024-49138-Exploitation-Detected — SOC335 incident response walkthrough for CVE-2024-49138 CLFS privilege escalation, covering alert triage, threat intel enrichment, process tree analysis, and containment. | Kitploit
Tools/GitHubGitHub/fabianch20/soc335---cve-2024-49138-exploitation-detected
Indicator of Compromise (IOC) ManagementPrivilege EscalationVulnerability AnalysisMalware AnalysisDigital ForensicsThreat IntelligenceLearning & EducationIncident ResponseLog Analysis

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
GitHubfabianch20/soc335---cve-2024-49138-exploitation-detected

SOC335---CVE-2024-49138-Exploitation-Detected

SOC335 incident response walkthrough for CVE-2024-49138 CLFS privilege escalation, covering alert triage, threat intel enrichment, process tree analysis, and containment.

View Repository
16 days agoNot yet reviewed
Share

Rule CVE CVSS Status Verdict Host


> whoami

root@soc:~# cat case_file.txt

  Platform      : LetsDefend
  Case          : SOC335 - CVE-2024-49138 Exploitation Detected
  EventID       : 313
  Alert Time    : 2025-01-22T02:37:00+03:00
  Alert Type    : Privilege Escalation
  Difficulty    : Medium
  Role          : Security Analyst

  Hostname      : Victor
  IP Address    : 172.16.17.207
  Process User  : EC2AMAZ-ILGVOIN\LetsDefend
  Process Name  : svohost.exe   (masquerading svchost.exe)
  Process Path  : C:\temp\service_installer\svohost.exe
  Parent Proc   : C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exe
  File Hash     : b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
  Device Action : Allowed

  MITRE ATT&CK  : T1059.001  PowerShell
                  T1055      Process Injection
                  T1068      Exploitation for Privilege Escalation
                  T1548      Abuse Elevation Control Mechanism
                  T1110      Brute Force

> ./playbook.sh --pivot-methodology

Metodología de 5 fases, cada una resuelta en WHO / WHAT / WHEN / WHY antes de pivotar a la siguiente.

┌─[ STEP 1: ALERT TRIAGE ]─────────────────────────────────────────────────────┐
│                                                                              │
│  WHO   : SIEM queue / SOC335 rule (EventID 313)                              │
│  WHAT  : svohost.exe spawned by powershell.exe outside System32              │
│  WHEN  : 2025-01-22 02:37:00 +03:00                                          │
│  WHY   : separates real EoP attempt from benign svc install                  │
│                                                                              │
│  $ filter process_name="svohost.exe" AND path!="*\System32\*"                │
│                                                                              │
│  PIVOT : hash + host isolated -> enrich with threat intel                    │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 2: THREAT INTEL ENRICHMENT ]──────────────────────────────────────────┐
│                                                                              │
│  WHO   : VirusTotal, CISA KEV, SentinelOne CVE DB                            │
│  WHAT  : hash flagged malicious; behavior maps to CVE-2024-49138 (CLFS EoP)  │
│  WHEN  : patched Dec-2024 Patch Tuesday; exploited pre-patch as 0-day, KEV-  │
│          listed                                                              │
│  WHY   : turns an unknown binary into a named, weaponized CVE with known TTPs│
│                                                                              │
│  $ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9  │
│                                                                              │
│  PIVOT : malware + CVE confirmed -> validate on endpoint process tree        │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 3: ENDPOINT PROCESS TREE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Endpoint Security / EDR telemetry on host Victor                    │
│  WHAT  : child proc whoami.exe executes as NT AUTHORITY\SYSTEM               │
│  WHEN  : immediately after svohost.exe execution, same alert window          │
│  WHY   : proves exploitation SUCCEEDED, not merely attempted                 │
│                                                                              │
│  $ proctree --host Victor --pid 7640                                         │
│                                                                              │
│  PIVOT : escalation confirmed -> pivot to network logs for entry vector      │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 4: NETWORK & LOG PIVOT ]──────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Log Management: RDP auth logs + firewall/netflow                    │
│  WHAT  : RDP brute force from 185.107.56.141; outbound traffic to C2         │
│  WHEN  : brute force precedes 02:37 alert; C2 traffic follows escalation     │
│  WHY   : completes the chain from initial access to impact; feeds IOC list   │
│                                                                              │
│  $ filter dst_ip=172.16.17.207 AND event_type=logon_failed,logon_success     │
│                                                                              │
│  PIVOT : full attack chain reconstructed -> containment & closure            │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 5: CONTAINMENT & CLOSURE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Incident responder / case owner                                     │
│  WHAT  : Device Action=Allowed -> malware NOT quarantined; host isolated     │
│  WHEN  : at alert time, within response SLA                                  │
│  WHY   : halts lateral movement/C2; documents evidence for TP closure        │
│                                                                              │
│  $ isolate-host Victor --reason "CVE-2024-49138 confirmed exploitation"      │
│                                                                              │
│  PIVOT : case closed as True Positive -> remediation (patch CLFS, harden RDP)│
└──────────────────────────────────────────────────────────────────────────────┘

> ./run_investigation.sh

[ Step 1 ] Alert Triage — SIEM / SOC335
$ cat alert_313.log

[i] EventID 313 | Rule: SOC335 - CVE-2024-49138 Exploitation Detected
[i] Parent -> powershell.exe (v1.0)
[i] Child  -> svohost.exe  "C:\temp\service_installer\svohost.exe"
[!] Legit svchost.exe NEVER runs outside C:\Windows\System32\
[+] ANSWER: filename masquerading detected (svohost vs svchost) -> escalate to full case

🔗 [LetsDefend SOC335 case data]

[ Step 2 ] Threat Intel Enrichment — VirusTotal + CVE research
$ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
Download Tool