ALT-2407 · Windows Event Log
SMB lateral movement from finance workstation
WS-FIN-014 wrote an executable to ADMIN$ on SRV-SQL-01 and created a service pointing to it.
highFalse Positiveconfidence 61% · 1970-01-01 02:36:00Z · rule DET-0158 Admin Share Write + Service CreateLinked to INC-1041
Detection summary
WS-FIN-014 wrote an executable to ADMIN$ on SRV-SQL-01 and created a service pointing to it.
- Affected host
- WS-FIN-014
- Affected user
- a.pratama
- Source IP
- 10.20.14.61
- Detection rule
- DET-0158 Admin Share Write + Service Create
- Log source
- Windows Event Log
- Assignee
- D. Kusuma
Recommended actions
- Contain both hosts
- Delete the created service
- Escalate to L2
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.