critEncoded PowerShell — active C2 on finance subnet
INC-2291·FIN-WKS-04·EDR·Confidence 96%·Assigned: you
14m 00sSLA remaining
Encoded PowerShell execution on FIN-WKS-04
EDR flagged a PowerShell process launched with an encoded command, spawned by Microsoft Word, then opening an outbound TLS session to a Tor exit node. Classic phishing-to-C2 chain. Read the evidence, extract the IOCs, and map the behavior before you decide on containment.
severity CRITICAL host (Finance VLAN) user m.ortega (standard privileges) process WINWORD.EXE → powershell.exe -nop -w hidden -enc SQBFAFgA... network outbound TLS → :443 detect office_spawns_encoded_shell
Click any highlighted value to extract it as an IOC.
Aestrea Coach
SocraticCoachYou're assigned INC-2291. Don't rush to a verdict — walk the evidence. What's the first thing you'd check?
Case progress
IOCs collected0
Techniques mapped0 / 8
Verdict reached—