// ThreatHuntingLabs  ·  writeup

Ursnif Malware Targeting Italy — Detection Engineering (Case Lab 3/4)

ThreatHuntingLabs EDR TelemetryKQL

Case Context

Part of a 4-lab investigation case on Threat Hunting Labs built around a single incident: a high-severity alert on a Windows workstation triggered by a signed binary loading a DLL from a user-writable path. This lab is the Detection Engineering angle — turning the attack chain surfaced by the earlier angles into generalised, tunable detection logic rather than a one-off match on this sample.

The case runs four separate investigation angles against the same incident: Threat Hunt, Incident Response, Detection Engineering, and Malware Analysis. This lab is 3 of 4 — I’ll be posting the full case once all four are complete rather than piecemeal.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

Techniques Encountered

Six MITRE ATT&CK techniques needed detection coverage, spanning proxy execution, web-based C2, scripting, and remote access:

MITRE ATT&CK techniques covered by the detections

Prioritising Findings — Pyramid of Pain

Unlike the other three angles, the Detection Engineering debrief recorded zero Pyramid of Pain findings for this case — the panel wasn’t populated for this angle.

What I Practiced

Full case writeup will go up once all 4 labs are done.