{"id":1189,"date":"2026-07-07T19:33:49","date_gmt":"2026-07-07T19:33:49","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=1189"},"modified":"2026-07-07T19:33:50","modified_gmt":"2026-07-07T19:33:50","slug":"analyst-note-sample-letsdefend-event-id-292","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=1189","title":{"rendered":"Analyst Note Sample &#8211; LetsDefend Event ID 292"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Additional Info:<br>Date of Investigation: Sep, 06, 2024, 01:59 AM<br>Alert Title: Unauthorized Access to NTDS.dit File Detected<br>Time to investigate: 52 Minutes<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retrospective Note:<br>If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As for the terminal history, note down the commands used, timestamps, and the IP used for exfiltration. Once on the host, point out whether I should be looking at Sysmon or security logs, along with the full timestamps. I did notice I input the GitHub page contacted on the case, but would put it in the notes as well. The biggest thing here is that I didn&#8217;t point out that the ninjacopy tool was used to dump the NTDS .dit file, and that the credentials dump was what was exfiltrated. This results in a true positive for the alert title &#8220;Unauthorized access to NTDS&#8221;.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Affected systems and users\n\nEndpoint IP: 172.16.17.223\nMalicious IP: 185.107.56.72\nHostname: Paul\n\n\nSteps taken in the investigation\nChecked Mitre and found the GitHub of the tool listed in the alert. The tool uses direct volume access for defense evasion. Checked endpoint security for network connections, and found 3 IP addresses, 2 being reported by 1 vendor as malicious in Virustotal. After checking the terminal history, I can confirm that exfiltration has occurred to one of these IP addresses. \nOn the endpoint, logs show that the Malicious IP logged on via RDP over the network at 12:17:28. The second IP marked by VirusTotal appears to be the GitHub where the tool was downloaded from. The Ntds file and the tool still exist in the machine's temp folder. \n\nActions taken\nThe system is contained.\n\nReferences\nhttps:&#47;&#47;attack.mitre.org\/techniques\/T1006\/ \nhttps:\/\/www.virustotal.com\/gui\/ip-address\/185.107.56.72\/detection\nhttps:\/\/www.abuseipdb.com\/check\/185.107.56.72\nhttps:\/\/www.virustotal.com\/gui\/file\/975803e4b80db0c3b3c8a1e8074da3f5a5c77c710cbf96de38caf9744dd76c9b\n\n----------- (Artifacts below were separate from notes but input into case management)\n\nExtracted Artifacts:\n\nType Value\nRequested URL: hxxps&#91;:\/\/]185&#91;.]107&#91;.]56&#91;.]72&#91;:]8000\/upload\nRequested URL: hxxps&#91;:\/\/]raw.githubusercontent&#91;.]com\/PowerShellMafia\/PowerSploit\/master\/Exfiltration\/Invoke-NinjaCopy&#91;.]ps1\nIP Address: 185.107.56&#91;.]72\nMD5 Hash: 7415795492e4d3afdd1bbdf3da6cbb9e<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As for the terminal history, note down the commands used, timestamps, and the IP used for exfiltration. Once on the host, point out whether I should be looking at Sysmon or security logs, along with the full timestamps. I did notice I input the GitHub page<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-1189","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=1189\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=1189\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-07T19:33:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-07T19:33:50+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189#listItem\",\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 292\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189#listItem\",\"position\":2,\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 292\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189\",\"name\":\"Analyst Note Sample \\u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1189#breadcrumblist\"},\"datePublished\":\"2026-07-07T19:33:49+00:00\",\"dateModified\":\"2026-07-07T19:33:50+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As","canonical_url":"https:\/\/victorcoil.tech\/?page_id=1189","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=1189#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1189#listItem","name":"Analyst Note Sample &#8211; LetsDefend Event ID 292"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1189#listItem","position":2,"name":"Analyst Note Sample &#8211; LetsDefend Event ID 292","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=1189#webpage","url":"https:\/\/victorcoil.tech\/?page_id=1189","name":"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=1189#breadcrumblist"},"datePublished":"2026-07-07T19:33:49+00:00","dateModified":"2026-07-07T19:33:50+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As","og:url":"https:\/\/victorcoil.tech\/?page_id=1189","article:published_time":"2026-07-07T19:33:49+00:00","article:modified_time":"2026-07-07T19:33:50+00:00","twitter:card":"summary_large_image","twitter:title":"Analyst Note Sample \u2013 LetsDefend Event ID 292 - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"Additional Info:Date of Investigation: Sep, 06, 2024, 01:59 AMAlert Title: Unauthorized Access to NTDS.dit File DetectedTime to investigate: 52 Minutes Retrospective Note:If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As"},"aioseo_meta_data":{"post_id":"1189","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-06 03:21:53","updated":"2026-07-07 20:10:37","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAnalyst Note Sample \u2013 LetsDefend Event ID 292\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"Analyst Note Sample &#8211; LetsDefend Event ID 292","link":"https:\/\/victorcoil.tech\/?page_id=1189"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1189"}],"version-history":[{"count":2,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1189\/revisions"}],"predecessor-version":[{"id":1200,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1189\/revisions\/1200"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}