TIMESTAMPSOURCEIDDETAIL
03:12:41Security.evtx4624
Logon Type 10 - RDP
03:12:58Sysmon.evtx1
cmd.exe → powershell.exe
03:13:05Sysmon.evtx1
powershell.exe → whoami.exe
03:13:12Sysmon.evtx1
powershell.exe → net.exe group
03:13:28Sysmon.evtx3
C2 beacon → 185.220.101.42:443
03:14:01Sysmon.evtx1
powershell.exe → mimikatz.exe
03:14:33Security.evtx4648
Explicit creds → DC01
03:15:02Sysmon.evtx11
ransomware.exe dropped
03:15:18MFTECmdCREATE
C:\Windows\Temp\enc.exe
03:15:44Sysmon.evtx1
PsExec → WORKSTATION-07
03:16:01HayabusaALERT
Lateral Movement Detected
03:16:22Security.evtx4625
Failed logon → SRV-DB01
PROCESS INSPECTORSYSMON EID 1
explorer.exe:1204
├─cmd.exe:5528
│ ├─powershell.exe:6744
│ │ ├─whoami.exe:7012
│ │ ├─net.exe:7180
│ │ ├─mimikatz.exe:7344CREDENTIAL DUMP
│ ├─PsExec.exe:7520
LATERAL MOVEMENT3 HOPS
151022121101242133921U42-TECH.S…U42-TECHTEST-VM-CTIU42-HR10.2.10.13.182:445.19:49690.10.234.13:445.19:49701127.0.0.110.2.10.159!DESKTOP-M458NRQ!DESKTOP-F7153U5!WIN-DN3C3GPH…