criticalSplunk Enterprise Security · 20 minutes

A domain admin logon from a workstation that has never had one

The alert, as it arrived

Splunk Enterprise Security
[03:02:48] NOTABLE · Splunk ES · Urgency: Critical
Search: Privileged logon to non-privileged asset

  host=WKS-4417  (asset category: standard_workstation)
  EventCode=4624  Logon_Type=3  (Network)
  Account_Name=svc_backup_adm
  Account_Domain=CORP
  Source_Network_Address=10.***.12.88
  Logon_Process=NtLmSsp
  Authentication_Package=NTLM

  Asset history: 0 prior logons by any member of Domain Admins (365d lookback)
  Account history: svc_backup_adm last interactive logon 412 days ago

  Preceding on same host (02:58:31):
    EventCode=4688  New_Process_Name=C:\Windows\System32\cmd.exe
    Creator_Process_Name=C:\Program Files\<redacted>\updater.exe

Your turn

Twenty minutes. Is this lateral movement, a misconfiguration, or a backup job nobody documented? Name the three pieces of evidence that would settle it, and say what you would do if you could not get any of them.

Write it down before you scroll. The value of this is in committing to an answer you can be wrong about, and reading the breakdown first removes it entirely.

Analyst breakdown

Pro

Unlock the expert breakdown and hunting queries with a Pro membership.

5 steps in order, each with the reasoning and a runnable query, plus the trap most responders fall into on this one and what the incident actually turns out to be. The scenario above stays free and complete: work it first, and the breakdown is worth more.