Active lab. Threat Hunting Labs does not permit public writeups that reveal answers, queries or investigation paths for live cases. This page covers the case at a summary level only. Full notes are kept privately and will be published if the case is opened up.
Unusual activity has been reported in the environment. Investigate and determine what occurred.

An administrator’s workstation ran two malicious RVTools-branded packages downloaded through the browser. The discovery route was reported as SEO poisoning but is not captured in the endpoint evidence. One package installed a commercial RMM as SYSTEM, along with a firewall rule and a watchdog task, and the operator used it to push a second, custom management service. The other injected the browser and later delivered a Python-hosted Cobalt Strike Beacon. The Beacon excluded itself from Defender, copied the local credential hives out of a shadow copy, probed a domain controller share without success, and restored itself through a scheduled task when its original process crashed. Injected browser processes also opened the saved-login and cookie stores. The evidence window closes with the replacement Beacon still communicating, so the incident remained open and no containment or recovery was confirmed.

| Field | Value |
|---|---|
| Platform | Threat Hunting Labs, Case 0011 |
| Track | Incident Response (18 questions, 12 of them response decisions) |
| Evidence | Elastic Endpoint EDR, Windows event logs, EDR detections, Arkime network sessions |
| Query language | KQL (Azure Log Analytics) |
| Hosts in scope | 1 workstation, 1 domain controller |
| Companion reading | THL intrusion report, MalBear Labs malware analysis |
This track is built around response judgement, not artefact hunting. Two thirds of the questions are decisions: how to contain a host without losing volatile evidence, what order to collect in, how to revoke rogue remote access without breaking legitimate use of the same vendor elsewhere, and how wide to scope credential resets when different stores were exposed in different ways. Each decision draws on evidence found earlier in the case, so the reasoning has to hold up against the telemetry rather than a playbook.
The telemetry questions support those decisions. Before any removal, the RMM’s firewall rule and task registration have to be traced and preserved. A failed share probe has to be followed to its exit status before containment is widened. The account used for a nearby domain controller logon has to be matched across both hosts. The gap between the Beacon’s exit and its scheduled relaunch has to be measured to show whether killing the process actually ended access.
The recurring skill is evidence-bounded reporting. Several options overstate what the records prove, such as treating a logon as compromise, a local copy as exfiltration, or an attributed vector as observed fact. The right answer each time is the one that says exactly what the evidence supports and flags the rest as unverified.
| Technique | ID |
|---|---|
| User Execution: Malicious File | T1204.002 |
| Process Injection: Asynchronous Procedure Call | T1055.004 |
| Scheduled Task/Job: Scheduled Task | T1053.005 |
| Remote Access Software | T1219 |
| Impair Defenses: Disable or Modify Tools | T1562.001 |
| Impair Defenses: Disable or Modify System Firewall | T1562.004 |
| Credentials from Password Stores: Credentials from Web Browsers | T1555.003 |
| OS Credential Dumping: Security Account Manager | T1003.002 |
| Data from Local System | T1005 |
| Account Discovery: Domain Account | T1087.002 |
| Remote Services: SMB/Windows Admin Shares | T1021.002 |
| Application Layer Protocol: Web Protocols | T1071.001 |

| Level | Count |
|---|---|
| Hash values | 0 |
| IP addresses | 1 |
| Domain names | 0 |
| Network / host artefacts | 8 |
| Tools | 6 |
| TTPs | 12 |
Killing the process is not containment. The Beacon came back from its scheduled task in under a minute, with no operator involved, and recreated that task within seconds of restarting. Persistence has to be removed together with the process, or before it. Otherwise termination just resets the clock.
Isolate through the agent and verify it, because this host is mostly memory. The loader, the injected browsers and the Beacon all ran inside legitimate processes. Shutting down or reimaging first would have destroyed most of the evidence. Agent-based isolation cuts every remote channel at once while keeping the EDR management path available for memory capture.
Revoke rogue RMM at the tenant, not the vendor. The commercial RMM here is a legitimate product. Blocking the vendor across the organisation would break approved use and still leave the installs in place. The enrollment identifies the attacker’s tenant, and revoking through the management owner removes only their access.
Scope credential resets by store, not by suspicion. Browser cookie and login stores call for session revocation and credential rotation from a trusted system. The copied hives expose local account hashes, LSA secrets and cached logons, and each secret goes back to its owner. Accounts that were only enumerated need review, not blind disabling.
Report exactly what the evidence proves. A domain controller logon near a failed share command is a lead, not lateral movement. A local copy of credential hives is not exfiltration, and a reported initial-access vector is not an observed one. The handoff records the incident as open with the last observed activity, because the data never shows access ending.
The attacker never got past one workstation, but that workstation held six independent ways back in, and one of them restored itself faster than a responder could close a ticket. The IR track makes you prove every containment and recovery claim against the telemetry, which is how real incident response works.
