Case AE25DE · Blue team / DFIR · L2 Practitioner
Encoded PowerShell at 2am
Practise as: Incident drill · Interview
Live alertAt 02:14 EDR flags FIN-WS-042 running powershell.exe -nop -w hidden -enc JABz... spawned by excel.exe, followed by an outbound HTTPS connection to a 5-day-old domain.
Interview questionYou get an alert for encoded PowerShell launched by Excel at 2am. What do you do?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Decode the Base64 (UTF-16LE) payload; check Script Block Logging event 4104 for the deobfuscated script.
- Excel parent points to a malicious macro doc (T1566.001); find the email, sender and all other recipients.
- Isolate the host via EDR, capture memory, and block the domain and IP at proxy/DNS across the fleet.
- Scope: hunt for the domain, doc hash and child process pattern on all hosts; check the user's recent logons.
- Reset the user's credentials and revoke sessions; check for persistence (Run keys, scheduled tasks, WMI).
If the interviewer pushes back
- The decoded script loads a .NET assembly reflectively. How does that change your forensic approach?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.