JELAJAH SOC
YO

ALT-2407 · Windows Event Log

SMB lateral movement from finance workstation

WS-FIN-014 wrote an executable to ADMIN$ on SRV-SQL-01 and created a service pointing to it.

Back to queue
highFalse Positiveconfidence 61% · 1970-01-01 02:36:00Z · rule DET-0158 Admin Share Write + Service CreateLinked to INC-1041

Detection summary

WS-FIN-014 wrote an executable to ADMIN$ on SRV-SQL-01 and created a service pointing to it.

Affected host
WS-FIN-014
Affected user
a.pratama
Source IP
10.20.14.61
Detection rule
DET-0158 Admin Share Write + Service Create
Log source
Windows Event Log
Assignee
D. Kusuma

Recommended actions

  • Contain both hosts
  • Delete the created service
  • Escalate to L2

Analyst decision

Triage checklist

  • 1. Confirm the detection logic matched genuine activity.
  • 2. Check user and asset context for expected behaviour.
  • 3. Pivot on host, user, IP and hash in the Log Explorer.
  • 4. Enrich IOCs with threat intelligence.
  • 5. Set a verdict and record your reasoning.