TryHackMe: Boogeyman 3
A capstone investigation from TryHackMe's SOC Level 1 path. One fake PDF on the CEO's machine, followed through Kibana to a DCSync and ransomware on the domain controller two hours later.
The only evidence was an Elastic stack with two days of logs. I traced an HTA dropper through a scheduled task, a fodhelper UAC bypass, Mimikatz and pass-the-hash, a plaintext password in a readable IT automation script, PowerShell remoting to a second workstation, and finally DCSync and ransomware on DC01. My first search came back empty because Kibana was still set to the last 15 minutes, and a filter I thought I'd applied never actually ran, so I learned to check the query bar before trusting any hit count.