// ThreatHuntingLabs  ·  writeup

From SEO Poisoning to Custom RMM and Cobalt Strike — Incident Response (Case Lab 2/4)

ThreatHuntingLabs EDR TelemetryKQL

Active lab. Threat Hunting Labs does not permit public writeups that reveal answers, queries or investigation paths for live cases. This page covers the case at a summary level only. Full notes are kept privately and will be published if the case is opened up.

Scenario

Unusual activity has been reported in the environment. Investigate and determine what occurred.

Executive Summary

An administrator’s workstation ran two malicious RVTools-branded packages downloaded through the browser. The discovery route was reported as SEO poisoning but is not captured in the endpoint evidence. One package installed a commercial RMM as SYSTEM, along with a firewall rule and a watchdog task, and the operator used it to push a second, custom management service. The other injected the browser and later delivered a Python-hosted Cobalt Strike Beacon. The Beacon excluded itself from Defender, copied the local credential hives out of a shadow copy, probed a domain controller share without success, and restored itself through a scheduled task when its original process crashed. Injected browser processes also opened the saved-login and cookie stores. The evidence window closes with the replacement Beacon still communicating, so the incident remained open and no containment or recovery was confirmed.

Case Profile

FieldValue
PlatformThreat Hunting Labs, Case 0011
TrackIncident Response (18 questions, 12 of them response decisions)
EvidenceElastic Endpoint EDR, Windows event logs, EDR detections, Arkime network sessions
Query languageKQL (Azure Log Analytics)
Hosts in scope1 workstation, 1 domain controller
Companion readingTHL intrusion report, MalBear Labs malware analysis

Skills Practiced

This track is built around response judgement, not artefact hunting. Two thirds of the questions are decisions: how to contain a host without losing volatile evidence, what order to collect in, how to revoke rogue remote access without breaking legitimate use of the same vendor elsewhere, and how wide to scope credential resets when different stores were exposed in different ways. Each decision draws on evidence found earlier in the case, so the reasoning has to hold up against the telemetry rather than a playbook.

The telemetry questions support those decisions. Before any removal, the RMM’s firewall rule and task registration have to be traced and preserved. A failed share probe has to be followed to its exit status before containment is widened. The account used for a nearby domain controller logon has to be matched across both hosts. The gap between the Beacon’s exit and its scheduled relaunch has to be measured to show whether killing the process actually ended access.

The recurring skill is evidence-bounded reporting. Several options overstate what the records prove, such as treating a logon as compromise, a local copy as exfiltration, or an attributed vector as observed fact. The right answer each time is the one that says exactly what the evidence supports and flags the rest as unverified.

MITRE ATT&CK

TechniqueID
User Execution: Malicious FileT1204.002
Process Injection: Asynchronous Procedure CallT1055.004
Scheduled Task/Job: Scheduled TaskT1053.005
Remote Access SoftwareT1219
Impair Defenses: Disable or Modify ToolsT1562.001
Impair Defenses: Disable or Modify System FirewallT1562.004
Credentials from Password Stores: Credentials from Web BrowsersT1555.003
OS Credential Dumping: Security Account ManagerT1003.002
Data from Local SystemT1005
Account Discovery: Domain AccountT1087.002
Remote Services: SMB/Windows Admin SharesT1021.002
Application Layer Protocol: Web ProtocolsT1071.001

Pyramid of Pain

LevelCount
Hash values0
IP addresses1
Domain names0
Network / host artefacts8
Tools6
TTPs12

Takeaways

Killing the process is not containment. The Beacon came back from its scheduled task in under a minute, with no operator involved, and recreated that task within seconds of restarting. Persistence has to be removed together with the process, or before it. Otherwise termination just resets the clock.

Isolate through the agent and verify it, because this host is mostly memory. The loader, the injected browsers and the Beacon all ran inside legitimate processes. Shutting down or reimaging first would have destroyed most of the evidence. Agent-based isolation cuts every remote channel at once while keeping the EDR management path available for memory capture.

Revoke rogue RMM at the tenant, not the vendor. The commercial RMM here is a legitimate product. Blocking the vendor across the organisation would break approved use and still leave the installs in place. The enrollment identifies the attacker’s tenant, and revoking through the management owner removes only their access.

Scope credential resets by store, not by suspicion. Browser cookie and login stores call for session revocation and credential rotation from a trusted system. The copied hives expose local account hashes, LSA secrets and cached logons, and each secret goes back to its owner. Accounts that were only enumerated need review, not blind disabling.

Report exactly what the evidence proves. A domain controller logon near a failed share command is a lead, not lateral movement. A local copy of credential hives is not exfiltration, and a reported initial-access vector is not an observed one. The handoff records the incident as open with the last observed activity, because the data never shows access ending.

Conclusion

The attacker never got past one workstation, but that workstation held six independent ways back in, and one of them restored itself faster than a responder could close a ticket. The IR track makes you prove every containment and recovery claim against the telemetry, which is how real incident response works.