Key Defensive Takeaways
- Understand parent-child process relationships (e.g., word.exe spawning powershell.exe is a critical red flag).
- Enable PowerShell Script Block Logging (Event ID 4104) to capture obfuscated payload execution in plain text.
- Cross-reference command-line flags with the LOLBAS project documentation during alert triage.
Attackers no longer bring custom malware into corporate networks when they can simply misuse what is already installed. The LOLBAS (Living Off The Land Binaries and Scripts) project catalogs hundreds of legitimate Microsoft binaries that can execute code, download payloads, or bypass AppLocker.
1. Anomalous Parent-Child Relationships
Office applications (Word, Excel) or web servers (w3wp.exe, nginx) have no legitimate operational reason to spawn cmd.exe or powershell.exe. Establishing parent-process baseline rules in your SIEM immediately surfaces initial compromise attempts.
2. PowerShell Script Block Logging Telemetry
PowerShell execution policies do not prevent attacks. By enabling Event ID 4104, Windows decodes Base64 obfuscated scripts and logs the executed abstract syntax tree, allowing SOC analysts to see the true attacker intent.
Defensive Summary
Effective blue teaming is about understanding how normal systems operate so that anomalies jump out immediately. Practice analyzing benign logs to build instinct for the malicious.