{"id":1163,"date":"2026-06-18T22:45:18","date_gmt":"2026-06-18T22:45:18","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=1163"},"modified":"2026-06-18T22:45:19","modified_gmt":"2026-06-18T22:45:19","slug":"analyst-note-sample-letsdefend-event-id-278","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=1163","title":{"rendered":"Analyst Note Sample &#8211; LetsDefend Event ID 278"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Additional Info:<br>Investigation Date: 2\/11\/2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retrospective Note:<br>As of 6\/18\/2026, if revisiting this today, I&#8217;d add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.<br>Would also point out that I remotely RDP&#8217;d into the host on the 6th bullet point and checked the script contents on the live host.<br>Add in the queries run on the SIEM to support the 7th and 8th bullet points. Covering that no exfiltration traffic was seen going out of the victim host, as well as any lateral movement.<br>And finally, the rationale for the closure: why it was a true positive. With that being said, I confirmed unauthorized access via SSH brute-force attacks, followed by credential enumeration and decoding activity, which was tied to the alert trigger.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>========== Title(s) ==========\n\nSOC302 - Suspicious Base64 Encoding\/Decoding Commands Detected\n\n========== Alert Details ==========\n\nEventID : 278\nEvent Time : Jul, 17, 2024, 12:18 PM\nRule : SOC302 - Suspicious Base64 Encoding\/Decoding Commands Detected\nLevel : Incident Responder\nHostname : Wilburn\nIp Address : 172.16.17.74\n\nCommand Line :\ndecoded = base64.b64decode(encoded)\n\nTrigger Reason :\nDetects suspicious use of Base64 encoding or decoding commands which could be used for data obfuscation.\n\n========== Raw logs\/Headers ==========\n\nN\/a \n\n=============================================\n\n  \n==== OSINT\/SandboxAnalysis\/ThreatIntel\/Artifacts\/References ====\n\nhttps:&#47;&#47;www.virustotal.com\/gui\/ip-address\/143.244.44.163\/detection\n0\/94\nAs of date 2\/11\/2026, no vendors mark the IP as malicious but relations show history of connection to malicious files\n\nhttps:\/\/www.abuseipdb.com\/check\/143.244.44.163\nIP has a history of maliciousness\n\nInternal Threat intelligence returned no results, recommend adding artifacts\n\nDecoded File hash:\n\nmd5sum decoded_file.txt \nd15ebd5d4016e9099d2ba47107887f3a  decoded_file.txt\nsha1sum decoded_file.txt \n3c535e4050cf5f711fae9d6793366bee8e828e29  decoded_file.txt\nsha256sum decoded_file.txt \n364929ca5c536a03370f0cb8d2207ae466046a8cbe1424cad268c0feb0a63159\n\n========== Historical Analysis ==========\n\nL1 Note :\nMinutes before the alert, I saw a Brute Force attempt with different users from the IP 143.244.44.163 towards the system. However, I could not determine whether this attack was successful or not.\n\n========== Queries Ran ==========\n\nQueries ran from Malicious IP revealed Brute Force attack. No call back seems to be returned\n\n========== Synopsis ==========\n\n> L1 Analyst hand over notes pointed out that a brute force attack was detected before this event was triggered.\n> Verification of the brute force attack on the date of the event confirms that a successful login occurred on the Wilburn host at the IP address of (172.16.17.74) via the SSH protocol from the attacker IP 143.244.44.163 at Jul, 17, 2024, 06:44 AM for the analyst account\n> Performed OSINT on offending IP, taking note of history\n> Investigation of the endpoint shows enumeration activity performed by the unauthorized individual. Activity included looking at system architecture and OS versioning, groups present on the system, interrogating the passwd database and file searches for keywords such as passwords and important strings.\n> EDR shows terminal history showing the intruder using python to decode a file with base64 encoded content\n> After investigating the endpoint, the decoded content seems to be IPs, Usernames, and passwords\n> SIEM and EDR telemetry shows no extraction of the sensitive data found but the individual was still able to access it\n> Telemetry indicates that the Wilburn system is the only one affected. No sign of lateral movement or attacker expansion on network.\n> Isolated affected system. Recommend user password rotation and SSH key change\n\n========== Closure Code ==========\n\nTrue Positive<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I&#8217;d add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP&#8217;d into the host on the 6th bullet point and checked the script contents on the live host.Add in the queries run on the SIEM to support the 7th and 8th bullet points. Covering that no exfiltration traffic was seen going out of the victim host, as<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-1163","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I&#039;d add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP&#039;d into\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=1163\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I&#039;d add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP&#039;d into\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=1163\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-18T22:45:18+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-18T22:45:19+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I&#039;d add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP&#039;d into\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163#listItem\",\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 278\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163#listItem\",\"position\":2,\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 278\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163\",\"name\":\"Analyst Note Sample \\u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"Additional Info:Investigation Date: 2\\\/11\\\/2026 Retrospective Note:As of 6\\\/18\\\/2026, if revisiting this today, I'd add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP'd into\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1163#breadcrumblist\"},\"datePublished\":\"2026-06-18T22:45:18+00:00\",\"dateModified\":\"2026-06-18T22:45:19+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I'd add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP'd into","canonical_url":"https:\/\/victorcoil.tech\/?page_id=1163","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=1163#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1163#listItem","name":"Analyst Note Sample &#8211; LetsDefend Event ID 278"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1163#listItem","position":2,"name":"Analyst Note Sample &#8211; LetsDefend Event ID 278","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=1163#webpage","url":"https:\/\/victorcoil.tech\/?page_id=1163","name":"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I'd add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP'd into","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=1163#breadcrumblist"},"datePublished":"2026-06-18T22:45:18+00:00","dateModified":"2026-06-18T22:45:19+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I'd add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP'd into","og:url":"https:\/\/victorcoil.tech\/?page_id=1163","article:published_time":"2026-06-18T22:45:18+00:00","article:modified_time":"2026-06-18T22:45:19+00:00","twitter:card":"summary_large_image","twitter:title":"Analyst Note Sample \u2013 LetsDefend Event ID 278 - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"Additional Info:Investigation Date: 2\/11\/2026 Retrospective Note:As of 6\/18\/2026, if revisiting this today, I'd add that the 4th bullet in the synopsis, the investigation was done via an EDR solution, and would list the exact commands run by the attacker and the timestamps at which they were executed.Would also point out that I remotely RDP'd into"},"aioseo_meta_data":{"post_id":"1163","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-06-18 22:19:08","updated":"2026-06-18 22:45:19","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAnalyst Note Sample \u2013 LetsDefend Event ID 278\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"Analyst Note Sample &#8211; LetsDefend Event ID 278","link":"https:\/\/victorcoil.tech\/?page_id=1163"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1163"}],"version-history":[{"count":1,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1163\/revisions"}],"predecessor-version":[{"id":1164,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1163\/revisions\/1164"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}