Open in app

Sign In

Write

Sign In

Secnimi
Secnimi

2 Followers

Home

About

Feb 2

SOC164 — Suspicious Mshta Behavior EventID: 114 @ LetsDefend.io walkthrough

By Secnimi Hopefully I have fulfilled the request of Omer Gunal, Co-Founder of LetsDefend.io to show the right solution and steps for this investigation. This walkthrough is following the playbook (with few screen shots short). Lets dive in the playbook right the way. Go to the Monitoring page…for this case…

4 min read

SOC164 — Suspicious Mshta Behavior EventID: 114 @ LetsDefend.io walkthrough
SOC164 — Suspicious Mshta Behavior EventID: 114 @ LetsDefend.io walkthrough

4 min read

Secnimi

Secnimi

2 Followers

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech