<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Investigation Scenario 🔎]]></title><description><![CDATA[<p>Investigation Scenario <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f50e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--mag_right" style="height:23px;width:auto;vertical-align:middle" title="🔎" alt="🔎" /></p><p>You've discovered a user workstation with the Chrome Remote Desktop plugin installed. There's no business reason for the user to have this plugin, and they don't recall installing it. </p><p>What do you look for to investigate whether an incident occurred and the extent of its impact?</p><p><a href="https://infosec.exchange/tags/InvestigationPath" rel="tag">#<span>InvestigationPath</span></a> <a href="https://infosec.exchange/tags/DFIR" rel="tag">#<span>DFIR</span></a> <a href="https://infosec.exchange/tags/SOC" rel="tag">#<span>SOC</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/cb0b7e40-9359-4b2e-bbc5-e35b9d18b479/investigation-scenario</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 07:17:51 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/cb0b7e40-9359-4b2e-bbc5-e35b9d18b479.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 12 May 2026 14:00:46 GMT</pubDate><ttl>60</ttl></channel></rss>