Analysing A Security Alert 101

Photo by Markus Winkler on Unsplash
Alert view in Security Onion
Options when you click on an alert.
MZ header with DOS stub
Result of log correlation
Zeek event
  • The DC performed a GET request to download a file;
  • The URL and IP the file was downloaded from are from Google;
  • Both are also known to disperse updates;
  • The Windows Event Logs confirm Google Chrome was updated;

--

--

Founder// Hunter @ Chapter8.com

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store