Open cardosec

Case AE25DE · Blue team / DFIR · L2 Practitioner

Encoded PowerShell at 2am

Practise as: Incident drill · Interview

Live alertAt 02:14 EDR flags FIN-WS-042 running powershell.exe -nop -w hidden -enc JABz... spawned by excel.exe, followed by an outbound HTTPS connection to a 5-day-old domain.

Interview questionYou get an alert for encoded PowerShell launched by Excel at 2am. What do you do?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Decode the Base64 (UTF-16LE) payload; check Script Block Logging event 4104 for the deobfuscated script.
  2. Excel parent points to a malicious macro doc (T1566.001); find the email, sender and all other recipients.
  3. Isolate the host via EDR, capture memory, and block the domain and IP at proxy/DNS across the fleet.
  4. Scope: hunt for the domain, doc hash and child process pattern on all hosts; check the user's recent logons.
  5. Reset the user's credentials and revoke sessions; check for persistence (Run keys, scheduled tasks, WMI).

If the interviewer pushes back

  • The decoded script loads a .NET assembly reflectively. How does that change your forensic approach?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.