Host triage¶
Process¶
Check name, full path, command line, parent and grandparent, user, integrity level, hash, signature, original filename, Process GUID/PID, and start time.
Why did this process execute, who launched it, and what did it do next?
Pivot next: file writes, DNS/network, child processes, image loads, authentication session, and persistence.
File¶
Check path, filename, extension, hash, signer, creation/modification time, origin, Mark-of-the-Web (Zone.Identifier), user-writable/temp location, and subsequent execution.
Pivot next: creating process, download source, prevalence, sibling hosts, and hash/signature reputation.
Network¶
Check destination IP/domain, port, protocol, direction, bytes, frequency, beaconing, DNS, TLS metadata, User-Agent, and responsible process.
Pivot next: destination history, other hosts/users, certificate/fingerprint, DNS chain, and process lineage.
User¶
Check account, logon type, source IP, privilege, groups, normal host/time, interactive versus remote use, account age, and service-account behavior.
Pivot next: authentication chain, token/session changes, privilege changes, peer activity, and actions after login.
Persistence¶
Check services, scheduled tasks, Run keys, startup folders, WMI subscriptions, new accounts, DLL search-order locations, browser extensions, and Office add-ins.