criticalSplunk Enterprise Security · 20 minutes
A domain admin logon from a workstation that has never had one
The alert, as it arrived
Splunk Enterprise Security
[03:02:48] NOTABLE · Splunk ES · Urgency: Critical
Search: Privileged logon to non-privileged asset
host=WKS-4417 (asset category: standard_workstation)
EventCode=4624 Logon_Type=3 (Network)
Account_Name=svc_backup_adm
Account_Domain=CORP
Source_Network_Address=10.***.12.88
Logon_Process=NtLmSsp
Authentication_Package=NTLM
Asset history: 0 prior logons by any member of Domain Admins (365d lookback)
Account history: svc_backup_adm last interactive logon 412 days ago
Preceding on same host (02:58:31):
EventCode=4688 New_Process_Name=C:\Windows\System32\cmd.exe
Creator_Process_Name=C:\Program Files\<redacted>\updater.exeYour turn
Twenty minutes. Is this lateral movement, a misconfiguration, or a backup job nobody documented? Name the three pieces of evidence that would settle it, and say what you would do if you could not get any of them.
Write it down before you scroll. The value of this is in committing to an answer you can be wrong about, and reading the breakdown first removes it entirely.
Analyst breakdown
ProUnlock the expert breakdown and hunting queries with a Pro membership.
5 steps in order, each with the reasoning and a runnable query, plus the trap most responders fall into on this one and what the incident actually turns out to be. The scenario above stays free and complete: work it first, and the breakdown is worth more.