8,420

warnKerberoasting — abnormal TGS requests

INC-2284·DC-01·Windows Security·Confidence 77%·Assigned: you
45m 00sSLA remaining

Encoded PowerShell execution on FIN-WKS-04

EDR flagged a PowerShell process launched with an encoded command, spawned by Microsoft Word, then opening an outbound TLS session to a Tor exit node. Classic phishing-to-C2 chain. Read the evidence, extract the IOCs, and map the behavior before you decide on containment.

severity CRITICAL
host       (Finance VLAN)
user     m.ortega  (standard privileges)
process  WINWORD.EXEpowershell.exe -nop -w hidden -enc SQBFAFgA...
network  outbound TLS → :443
detect   office_spawns_encoded_shell

Click any highlighted value to extract it as an IOC.

Aestrea Coach
Socratic
CoachYou're assigned INC-2284. Don't rush to a verdict — walk the evidence. What's the first thing you'd check?
Case progress
IOCs collected0
Techniques mapped0 / 8
Verdict reached