04 / INVESTIGATIONS

Selected SOC case studies.

Sanitized investigation patterns showing how detections were validated, correlated and translated into response actions. Sensitive customer details are intentionally excluded.

CASE 01 • REMOTE ACCESS

Renamed Plink / Reverse SSH Tunnel

HIGH SIGNAL
DETECTION

PowerShell telemetry referenced a renamed tunneling utility and unusual SSH-related execution.

ANALYSIS

Correlated script-block and process activity to identify remote port forwarding behavior consistent with an SSH tunnel.

RESPONSE

Documented the execution chain and remote-access risk, then escalated for containment and business validation.

T1059.001 PowerShellT1572 Protocol TunnelingEDRRemote Access
CASE 02 • COMMAND & CONTROL

Malware DNS Callback Investigation

C2 ANALYSIS
DETECTION

Suspicious DNS telemetry indicated communication with a domain identified by threat intelligence controls.

ANALYSIS

Correlated DNS, endpoint and security-product evidence to validate whether the host exhibited callback behavior.

RESPONSE

Established scope, validated the communication pattern and prepared endpoint and network response actions.

T1071.004 DNSIOC CorrelationThreat IntelligenceC2
CASE 03 • WEB EXPOSURE

Suspicious IIS Reconnaissance & Exploitation

WEB ATTACK
DETECTION

Web logs showed requests targeting setup, diagnostics, administrative and application test pages.

ANALYSIS

Correlated source activity, user agents, targeted paths and suspicious server-side artifacts for compromise indicators.

RESPONSE

Documented suspicious reconnaissance and potential exploitation indicators for deeper host-level assessment.

T1190 Public-Facing ApplicationIIS LogsReconnaissanceRCE Analysis
CASE 04 • EMAIL SECURITY

Phishing / BEC Investigation

IDENTITY RISK
DETECTION

Executive impersonation indicators included authentication anomalies, Reply-To mismatch and an HTML attachment.

ANALYSIS

Reviewed SPF, DKIM, DMARC, sender alignment, attachment behavior, URLs and message scope across recipients.

RESPONSE

Established malicious characteristics, scoped exposure and recommended containment plus user-protection actions.

T1566.001 Spearphishing AttachmentSPF / DKIM / DMARCBECEmail Security
NEXT

Explore the home lab