TIMESTAMPSOURCEIDDETAIL
03:12:41Security.evtx4624
Logon Type 10 - RDP
03:12:58Sysmon.evtx1
cmd.exe → powershell.exe
03:13:05Sysmon.evtx1
powershell.exe → whoami.exe
03:13:12Sysmon.evtx1
powershell.exe → net.exe group
03:13:28Sysmon.evtx3
C2 beacon → 185.220.101.42:443
03:14:01Sysmon.evtx1
powershell.exe → mimikatz.exe
03:14:33Security.evtx4648
Explicit creds → DC01
03:15:02Sysmon.evtx11
ransomware.exe dropped
03:15:18MFTECmdCREATE
C:\Windows\Temp\enc.exe
03:15:44Sysmon.evtx1
PsExec → WORKSTATION-07
03:16:01HayabusaALERT
Lateral Movement Detected
03:16:22Security.evtx4625
Failed logon → SRV-DB01
PROCESS INSPECTORSYSMON EID 1
explorer.exe:1204
├─cmd.exe:5528
│ ├─powershell.exe:6744
│ │ ├─whoami.exe:7012
│ │ ├─net.exe:7180
│ │ ├─mimikatz.exe:7344LOLBIN
│ ├─PsExec.exe:7520
LATERAL MOVEMENT3 HOPS
C2RDPSMBPsExec4625WS01DC01SRV-FSSRV-DBWS07185.220.*