Part of a 4-lab investigation case on Threat Hunting Labs built around a single incident: a high-severity alert on a Windows workstation triggered by a signed binary loading a DLL from a user-writable path. This lab is the Incident Response angle — running the full triage → scope → contain → recover lifecycle against the same intrusion, this time with the goal of a defensible incident record rather than a hunt.
The case runs four separate investigation angles against the same incident: Threat Hunt, Incident Response, Detection Engineering, and Malware Analysis. This lab is 2 of 4 — I’ll be posting the full case once all four are complete rather than piecemeal.
Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.
Seven MITRE ATT&CK techniques surfaced across the response, spanning tool transfer, web-based C2, scripting, registry querying, remote access via VNC, and system discovery:

Seven findings came out of the response, weighted by how costly each is for the attacker to change:

Full case writeup will go up once all 4 labs are done.