Investigation Scenario ๐Ÿ”Ž

A host on your network executed the command โ€œnetsh wlan show profileโ€ for the first time.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC

I post these scenarios every Tuesday! We're up to 135 of them so far! If you enjoy them, you'll probably like my Investigation Theory class where I work with folks directly on improving their investigative skills leverage principles from cognitive science: https://www.networkdefense.co/courses/
Courses โ€” Applied Network Defense

Applied Network Defense