Active lab. Threat Hunting Labs does not permit public writeups that reveal answers, queries or investigation paths for live cases. This page covers the case at a summary level only. Full notes are kept privately and will be published if the case is opened up.

A Windows intrusion began when an administrator followed an SEO-poisoned RVTools search result. The hunt compares two malicious RVTools-branded download paths, traces browser injection and remote-access activity, and follows the later custom management and command-and-control activity while keeping findings tied to endpoint evidence.
An administrator searching for RVTools downloaded two malicious packages to the same workstation a few minutes apart. The first MSI injected a suspended Chrome process through an MSI custom action, set a user logon value for a heavily obfuscated loader, and later ran a second injection chain through SmartScreen into fresh Chrome and Edge processes that opened the browsers’ credential stores. That same browser path delivered an Inno Setup installer carrying a Python-hosted Cobalt Strike Beacon, which elevated through an auto-elevating Windows binary, excluded itself from Defender, staged the SAM, SYSTEM and SECURITY hives from a shadow copy, and survived its own crash through a scheduled task. The second package, a ZIP with a shortcut, installed Level RMM as SYSTEM, which the operator used for domain reconnaissance and to push a custom RMM service; two more custom agents followed over the next week. Probes of the domain controller never turned into a second foothold, so the workstation remained the only compromised host.

| Field | Value |
|---|---|
| Platform | Threat Hunting Labs, Case 0011 |
| Track | Threat Hunting (25 questions) |
| Evidence | Elastic Endpoint EDR, Windows event logs, EDR detections, Arkime network sessions |
| Query language | KQL (Azure Log Analytics) |
| Hosts in scope | 1 workstation, 1 domain controller |
| Companion reading | THL intrusion report, MalBear Labs malware analysis |
Most of this hunt came down to telling true lineage apart from what the telemetry claims. Parent spoofing shows up twice in the browser path, and a recycled process ID sits right in the middle of the installer chain, so a hunt that trusts parent names or PIDs reaches the wrong answer on several questions. The case rewards working from real-creator fields, entity IDs and API target records instead.
The other main skill was separating legitimate agent noise from operator activity. Level runs its own recurring inventory through the same PowerShell wrapper the operator uses, and the operator’s commands arrive over stdin instead of the command line. Building a baseline of routine agent behaviour first and then looking for what breaks it was the only reliable way to isolate the operator.
The schema itself also took some learning. It is Elastic Endpoint flattened into snake_case columns inside Log Analytics. Timestamps are stored as strings, some fields exist only in the raw nested blob, and a few KQL reserved words come up often enough to break summarize aliases.
| Technique | ID |
|---|---|
| User Execution: Malicious File | T1204.002 |
| System Binary Proxy Execution: Msiexec | T1218.007 |
| Process Injection: Asynchronous Procedure Call | T1055.004 |
| Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | T1547.001 |
| Command and Scripting Interpreter: PowerShell | T1059.001 |
| Command and Scripting Interpreter: Python | T1059.006 |
| Abuse Elevation Control Mechanism: Bypass User Account Control | T1548.002 |
| Impair Defenses: Disable or Modify Tools | T1562.001 |
| Scheduled Task/Job: Scheduled Task | T1053.005 |
| Create or Modify System Process: Windows Service | T1543.003 |
| Remote Access Software | T1219 |
| Application Layer Protocol: Web Protocols | T1071.001 |
| System Network Configuration Discovery | T1016 |
| Credentials from Password Stores: Credentials from Web Browsers | T1555.003 |
| OS Credential Dumping: Security Account Manager | T1003.002 |
| Remote Services: SMB/Windows Admin Shares | T1021.002 |

| Level | Count |
|---|---|
| Hash values | 0 |
| IP addresses | 2 |
| Domain names | 3 |
| Network / host artefacts | 12 |
| Tools | 7 |
| TTPs | 16 |
Parent fields lie, and this case uses that deliberately. Two separate stages reparent their children to Explorer, and the UAC bypass relies on a borrowed parent to hand over an elevated token. Any hunt or detection keyed on parent-child pairs will miss the whole browser path unless it checks the real creator and whether the process was created suspended.
PIDs are not identities. A process ID in the installer chain was reused after an unrelated RMM process exited. Walking lineage by PID links the Beacon to the wrong access path. Entity IDs and creation times are the only safe join keys.
Legitimate RMM is the quietest foothold. Level ran as a signed SYSTEM service, and the operator’s commands shared a wrapper with the agent’s own inventory jobs. Any RMM that isn’t on the organisation’s approved list should be treated as an incident on its own, whatever its signature.
Detect-only on an admin workstation let every stage run. Defender and EDR on the beachhead were set to alert without preventing. Every payload executed and every stage left telemetry, while the same controls in prevention mode on other hosts stopped the lateral pivots. The admin workstation was the one host that most needed blocking turned on.
Native API telemetry catches what process trees can’t. Each injection in the chain used the same queued-APC primitive against unbacked memory, and the Threat-Intelligence ETW provider recorded every one. That single behaviour covers the MSI stage, the SmartScreen stage and the browser stage, however the process names are disguised.
One routine software download on an admin workstation opened four remote-management channels, a Cobalt Strike Beacon and SystemBC. The attackers still never reached a second host, because prevention was on everywhere except the machine where it mattered most.
