Renamed Plink / Reverse SSH Tunnel
PowerShell telemetry referenced a renamed tunneling utility and unusual SSH-related execution.
Correlated script-block and process activity to identify remote port forwarding behavior consistent with an SSH tunnel.
Documented the execution chain and remote-access risk, then escalated for containment and business validation.
Malware DNS Callback Investigation
Suspicious DNS telemetry indicated communication with a domain identified by threat intelligence controls.
Correlated DNS, endpoint and security-product evidence to validate whether the host exhibited callback behavior.
Established scope, validated the communication pattern and prepared endpoint and network response actions.
Suspicious IIS Reconnaissance & Exploitation
Web logs showed requests targeting setup, diagnostics, administrative and application test pages.
Correlated source activity, user agents, targeted paths and suspicious server-side artifacts for compromise indicators.
Documented suspicious reconnaissance and potential exploitation indicators for deeper host-level assessment.
Phishing / BEC Investigation
Executive impersonation indicators included authentication anomalies, Reply-To mismatch and an HTML attachment.
Reviewed SPF, DKIM, DMARC, sender alignment, attachment behavior, URLs and message scope across recipients.
Established malicious characteristics, scoped exposure and recommended containment plus user-protection actions.