MIND YOUR ATTACK GAPS
GAP:
Nothing Looks Wrong
ENDPOINT LOG DC-01
An attacker is live on this host, using only built-in Windows tools. Tap every command you think is the attacker. Antivirus already scanned them all.
09:02:11 DC-01 svc_backup · robocopy.exe
robocopy D:\Shares E:\Backup /MIR
✓ SIGNED AV: CLEAN
09:02:44 DC-01 j.owens · whoami.exe
whoami /groups
✓ SIGNED AV: CLEAN
09:03:09 DC-01 a.mbeki · nltest.exe
nltest /domain_trusts /all_trusts
✓ SIGNED AV: CLEAN
09:03:31 WKS-114 helpdesk · powershell.exe
Get-ADUser -Filter * -Properties LastLogonDate
✓ SIGNED AV: CLEAN
09:03:58 DC-01 a.mbeki · net.exe
net group "Domain Admins" /domain
✓ SIGNED AV: CLEAN
09:04:20 DC-01 j.owens · net.exe
net group "Domain Admins" /domain
✓ SIGNED AV: CLEAN
09:04:52 FS-02 svc_sql · sqlservr.exe
sqlservr.exe -s MSSQLSERVER
✓ SIGNED AV: CLEAN
09:05:17 DC-01 a.mbeki · ntdsutil.exe
ntdsutil "ac i ntds" "ifm" "create full C:\Windows\Temp\i" q q
✓ SIGNED AV: CLEAN
09:05:39 WKS-114 helpdesk · certutil.exe
certutil -hashfile setup.exe SHA256
✓ SIGNED AV: CLEAN
09:06:02 DC-01 j.owens · ipconfig.exe
ipconfig /all
✓ SIGNED AV: CLEAN
09:06:28 DC-01 svc_sccm · powershell.exe
powershell -nop -w hidden -enc SQBFAFgA...
✓ SIGNED AV: CLEAN
09:06:51 DC-01 svc_backup · vssadmin.exe
vssadmin list shadows
✓ SIGNED AV: CLEAN
NOW WATCH THE SEQUENCE

One command is admin work. Three in a row are an attack.

Antivirus scanned each line and found nothing. The attack was the order they ran in, one account, four minutes.
No single command was malware. The behavior across them was the breach.
GAP: NOTHING LOOKS WRONG
0
"Nothing they did ever looked wrong."