// ThreatHuntingLabs  ·  writeup

From SEO Poisoning to Custom RMM and Cobalt Strike — Threat Hunt (Case Lab 1/4)

ThreatHuntingLabs EDR TelemetryKQL

Active lab. Threat Hunting Labs does not permit public writeups that reveal answers, queries or investigation paths for live cases. This page covers the case at a summary level only. Full notes are kept privately and will be published if the case is opened up.

Scenario

A Windows intrusion began when an administrator followed an SEO-poisoned RVTools search result. The hunt compares two malicious RVTools-branded download paths, traces browser injection and remote-access activity, and follows the later custom management and command-and-control activity while keeping findings tied to endpoint evidence.

Executive Summary

An administrator searching for RVTools downloaded two malicious packages to the same workstation a few minutes apart. The first MSI injected a suspended Chrome process through an MSI custom action, set a user logon value for a heavily obfuscated loader, and later ran a second injection chain through SmartScreen into fresh Chrome and Edge processes that opened the browsers’ credential stores. That same browser path delivered an Inno Setup installer carrying a Python-hosted Cobalt Strike Beacon, which elevated through an auto-elevating Windows binary, excluded itself from Defender, staged the SAM, SYSTEM and SECURITY hives from a shadow copy, and survived its own crash through a scheduled task. The second package, a ZIP with a shortcut, installed Level RMM as SYSTEM, which the operator used for domain reconnaissance and to push a custom RMM service; two more custom agents followed over the next week. Probes of the domain controller never turned into a second foothold, so the workstation remained the only compromised host.

Case Profile

FieldValue
PlatformThreat Hunting Labs, Case 0011
TrackThreat Hunting (25 questions)
EvidenceElastic Endpoint EDR, Windows event logs, EDR detections, Arkime network sessions
Query languageKQL (Azure Log Analytics)
Hosts in scope1 workstation, 1 domain controller
Companion readingTHL intrusion report, MalBear Labs malware analysis

Skills Practiced

Most of this hunt came down to telling true lineage apart from what the telemetry claims. Parent spoofing shows up twice in the browser path, and a recycled process ID sits right in the middle of the installer chain, so a hunt that trusts parent names or PIDs reaches the wrong answer on several questions. The case rewards working from real-creator fields, entity IDs and API target records instead.

The other main skill was separating legitimate agent noise from operator activity. Level runs its own recurring inventory through the same PowerShell wrapper the operator uses, and the operator’s commands arrive over stdin instead of the command line. Building a baseline of routine agent behaviour first and then looking for what breaks it was the only reliable way to isolate the operator.

The schema itself also took some learning. It is Elastic Endpoint flattened into snake_case columns inside Log Analytics. Timestamps are stored as strings, some fields exist only in the raw nested blob, and a few KQL reserved words come up often enough to break summarize aliases.

MITRE ATT&CK

TechniqueID
User Execution: Malicious FileT1204.002
System Binary Proxy Execution: MsiexecT1218.007
Process Injection: Asynchronous Procedure CallT1055.004
Boot or Logon Autostart Execution: Registry Run Keys / Startup FolderT1547.001
Command and Scripting Interpreter: PowerShellT1059.001
Command and Scripting Interpreter: PythonT1059.006
Abuse Elevation Control Mechanism: Bypass User Account ControlT1548.002
Impair Defenses: Disable or Modify ToolsT1562.001
Scheduled Task/Job: Scheduled TaskT1053.005
Create or Modify System Process: Windows ServiceT1543.003
Remote Access SoftwareT1219
Application Layer Protocol: Web ProtocolsT1071.001
System Network Configuration DiscoveryT1016
Credentials from Password Stores: Credentials from Web BrowsersT1555.003
OS Credential Dumping: Security Account ManagerT1003.002
Remote Services: SMB/Windows Admin SharesT1021.002

Pyramid of Pain

LevelCount
Hash values0
IP addresses2
Domain names3
Network / host artefacts12
Tools7
TTPs16

Takeaways

Parent fields lie, and this case uses that deliberately. Two separate stages reparent their children to Explorer, and the UAC bypass relies on a borrowed parent to hand over an elevated token. Any hunt or detection keyed on parent-child pairs will miss the whole browser path unless it checks the real creator and whether the process was created suspended.

PIDs are not identities. A process ID in the installer chain was reused after an unrelated RMM process exited. Walking lineage by PID links the Beacon to the wrong access path. Entity IDs and creation times are the only safe join keys.

Legitimate RMM is the quietest foothold. Level ran as a signed SYSTEM service, and the operator’s commands shared a wrapper with the agent’s own inventory jobs. Any RMM that isn’t on the organisation’s approved list should be treated as an incident on its own, whatever its signature.

Detect-only on an admin workstation let every stage run. Defender and EDR on the beachhead were set to alert without preventing. Every payload executed and every stage left telemetry, while the same controls in prevention mode on other hosts stopped the lateral pivots. The admin workstation was the one host that most needed blocking turned on.

Native API telemetry catches what process trees can’t. Each injection in the chain used the same queued-APC primitive against unbacked memory, and the Threat-Intelligence ETW provider recorded every one. That single behaviour covers the MSI stage, the SmartScreen stage and the browser stage, however the process names are disguised.

Conclusion

One routine software download on an admin workstation opened four remote-management channels, a Cobalt Strike Beacon and SystemBC. The attackers still never reached a second host, because prevention was on everywhere except the machine where it mattered most.