Investigation scenarios and lessons
These notes describe common investigation patterns and lessons. Hypothetical scenarios sit alongside verified anonymised cases. Identifying details are removed. They are not customer case studies.
Ransomware After Exposed Remote Access
Ransomware encrypted a workstation after attackers brute-forced an internet-exposed remote desktop and a shared administrative account. A line-of-business server was planted with the same malware but never restarted, so encryption never ran there. Backups, not antivirus, prevented operational collapse.
Read the case noteCompromised Web Application
A web application began serving unexpected content. Investigation revealed a web shell, credential theft, and lateral movement to internal systems — not merely a defacement.
Credential Abuse Investigation
Unusual login patterns from multiple geographic locations suggested account compromise. Timeline reconstruction connected the activity to a phishing campaign weeks earlier.
Malware Persistence Investigation
Endpoint alerts flagged suspicious executables. Analysis revealed scheduled task persistence, command-and-control communication, and evidence of data staging.
Suspicious Administrative Access
Administrative actions on cloud infrastructure did not match normal operational patterns. Investigation traced access to a compromised service account with excessive permissions.
Sensitive Data Exposure Investigation
A misconfigured cloud storage bucket exposed internal documents. Scope assessment determined what data was accessible, for how long, and whether unauthorized access occurred.
Insider Threat Investigation
Unusual data access patterns preceded an employee's departure. Log correlation revealed systematic access to sensitive repositories outside normal role requirements.