Skip to content

Host triage

Process

Check name, full path, command line, parent and grandparent, user, integrity level, hash, signature, original filename, Process GUID/PID, and start time.

Why did this process execute, who launched it, and what did it do next?

Expected lineage
explorer.exe → chrome.exe
Investigate
WINWORD.EXE → powershell.exe → rundll32.exe
High interest
outlook.exe → cmd.exe → powershell.exe → unknown.exe

Pivot next: file writes, DNS/network, child processes, image loads, authentication session, and persistence.

File

Check path, filename, extension, hash, signer, creation/modification time, origin, Mark-of-the-Web (Zone.Identifier), user-writable/temp location, and subsequent execution.

Pivot next: creating process, download source, prevalence, sibling hosts, and hash/signature reputation.

Network

Check destination IP/domain, port, protocol, direction, bytes, frequency, beaconing, DNS, TLS metadata, User-Agent, and responsible process.

Pivot next: destination history, other hosts/users, certificate/fingerprint, DNS chain, and process lineage.

User

Check account, logon type, source IP, privilege, groups, normal host/time, interactive versus remote use, account age, and service-account behavior.

Pivot next: authentication chain, token/session changes, privilege changes, peer activity, and actions after login.

Persistence

Check services, scheduled tasks, Run keys, startup folders, WMI subscriptions, new accounts, DLL search-order locations, browser extensions, and Office add-ins.