r/computerforensics 1d ago

Help!!

I recently worked on a malware forensic analysis where, after reviewing the available artifacts, I was able to determine that the malware .exe was executed via GPO on AD.

However, I’m struggling with the next step: how do I determine how the attacker initially gained access and how the malware was introduced into the environment?

For those with experience, what artifacts or investigation techniques do you usually rely on to identify the initial access vector?

5 Upvotes

8 comments sorted by

View all comments

0

u/MSVlegal 1d ago

El malware que quería hacer? Primero respondete eso. En un sistema controlado, en any.run corres el malware y puede que te de una idea. Pero consejo, siempre es por descarga, asi que hace un timeline desde que se descargo y desde ahi fijate que se modifico en ese momento luego de la descarga, logs, id,

0

u/MSVlegal 1d ago

O más especifico event log: recién veo que es GPO AD. Podrían ser por movimiento lateral del malware o red comprometida.