Investigation Scenario ๐
Uncategorized
1
Posts
1
Posters
0
Views
-
Investigation Scenario

You find Event ID 7045 showing a new service installed: WinUpdateCheck, pointing to C:\ProgramData\wucheck.exe. You report to the SOC lead that this system is infected and needs to be contained.
They ask you to justify that request.
What evidence do you present to elevate this from โsuspicious service creationโ to confirmed malicious activity? Lead with your strongest likely evidence sources and conclusions.
-
R relay@relay.infosec.exchange shared this topic