<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jaime Barreto</title>
    <description>The latest articles on DEV Community by Jaime Barreto (@binarybastion).</description>
    <link>https://dev.to/binarybastion</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2905371%2F96a91efe-15d4-4d97-87c6-a125f1f2ce6b.jpeg</url>
      <title>DEV Community: Jaime Barreto</title>
      <link>https://dev.to/binarybastion</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/binarybastion"/>
    <language>en</language>
    <item>
      <title>LetsDefend SIEM Alert: Follina 0-Day Detected EventID: 123</title>
      <dc:creator>Jaime Barreto</dc:creator>
      <pubDate>Mon, 17 Mar 2025 16:26:32 +0000</pubDate>
      <link>https://dev.to/binarybastion/letsdefend-siem-alert-follina-0-day-detected-eventid-123-1fkm</link>
      <guid>https://dev.to/binarybastion/letsdefend-siem-alert-follina-0-day-detected-eventid-123-1fkm</guid>
      <description>&lt;p&gt;Hi there!, we're going to analyze and investigate a zero-day vulnerability: the CVE-2022-30190 a.k.a. Follina.&lt;/p&gt;

&lt;p&gt;The Follina vulnerability affects the Microsoft Office products and represents a critical risk because it enables remote code execution (RCE).&lt;/p&gt;

&lt;p&gt;Key Details of the Follina vulnerability (source &lt;a href="https://owasp.org/www-community/vulnerabilities/follina):" rel="noopener noreferrer"&gt;https://owasp.org/www-community/vulnerabilities/follina):&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;CVE-2022-30190: Officially recognized as CVE-2022-30190 by the National Institute of Standards and Technology (NIST), Follina warrants tracking due to its severity.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Phishing Campaigns: Cybercriminals actively exploit Follina through sophisticated phishing campaigns, luring users into opening malicious Office documents or links that trigger the vulnerability.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;MSDT Protocol: The critical issue lies in the manipulation of the “Microsoft Support Diagnostic Tool” (MSDT) protocol. Attackers leverage this protocol to execute their own PowerShell commands, often without user interaction.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Diverse Attack Vectors: Follina can strike via email-delivered malicious Office documents, USB devices, or even during file previews (e.g., .rtf formats).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Discovery Timeline: Unveiled as a zero-day vulnerability on May 27, 2022, the first known malware exploiting it surfaced on April 7, 2022, suggesting prior exploitation.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Escalation of Phishing Campaigns: With Follina’s discovery, cybersecurity experts noted a surge in phishing campaigns employing this vulnerability.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Let's create the case for the SIEM alert SOC173 - Follina 0-Day Detected, on LetsDefend to begin with the Playbook.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 0 - Define Threat Indicator:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwzrqy9t4q895bj6kuhqd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwzrqy9t4q895bj6kuhqd.png" alt="Incident Details - 123" width="800" height="185"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvekvt6dz1c8ccjffeqe0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvekvt6dz1c8ccjffeqe0.png" alt="Define Threat Indicator - 123" width="800" height="343"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Click on "Other", and continue to the next step on the Playbook.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1 - Check if the malware is quarantined/cleaned:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Let's verify if the malware is quarantined/cleaned&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Log Management&lt;/li&gt;
&lt;li&gt;Endpoint Security&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We're going to check the date to look for any IOCs, so let's go to the Log Managment.&lt;/p&gt;

&lt;p&gt;I'll put here the Event Time that we need to investigate:&lt;br&gt;
Event Time :&lt;br&gt;
Jun, 02, 2022, 03:22 PM&lt;/p&gt;

&lt;p&gt;Here is the Log Management and it show us some interesting things, let's have a look:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4h31dct7gfewtejv26gr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4h31dct7gfewtejv26gr.png" alt="Log Management - 123" width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There is this Ip address that keep repeating in a very short time spam, so it's definitely IOCs, so we take note of this IP for later:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;141.105.65.149&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now we go to the Endpoint Security.&lt;/p&gt;

&lt;p&gt;Just like before I'll put here the Ip Address and the host name:&lt;br&gt;
Source Address :&lt;br&gt;
172.16.17.39&lt;br&gt;
Hostname :&lt;br&gt;
JonasPRD&lt;/p&gt;

&lt;p&gt;It looks like we found something in here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbbaft3lkijp9r4k3h9r6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbbaft3lkijp9r4k3h9r6.png" alt="EDR - 123" width="800" height="493"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This shows us some IOCs in the Processes tab:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;WINWORD.exe&lt;/li&gt;
&lt;li&gt;mstd.exe&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Looking at the alert's details in the alert trigger reason give us that the mstd.exe was executed after a Office document, just like in the report from OWASP about the CVE-2022-30190.&lt;/p&gt;

&lt;p&gt;And looking a bit further in the Terminal History we see the malware in action:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdm1p55xmcmg6ll62olq7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdm1p55xmcmg6ll62olq7.png" alt="Terminal History - 123" width="800" height="212"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The second command chain looks very suspicious and dangerous because it is likely involving file extraction, processing and execution.&lt;/p&gt;

&lt;p&gt;And for last on this part we take a look on the alert details and the AV (AntiVirus) action (Allowed) doesn't stop the attack.&lt;/p&gt;

&lt;p&gt;so we click on Not Quarantined on the Playbook.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2 - Analyze Malware:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Now is the turn to analyze for Malware.&lt;/p&gt;

&lt;p&gt;With VirusTotal:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvjy0dp5gwt8oy92bzfyz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvjy0dp5gwt8oy92bzfyz.png" alt="VirusTotal IP - 123" width="800" height="260"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;VirusTotal says it is malicious, this is a malicious IP address.&lt;/p&gt;

&lt;p&gt;Furthermore, it's seems the malware compromise the host from a phishing email, so we go to the Email Security and search for that email, and we found another IOCs:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwq57c9f82o1eu8q0xd7b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwq57c9f82o1eu8q0xd7b.png" alt="Email Security - 123" width="800" height="397"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can see the sender is from Rusia and come with an attachment, but don't need to open it, in the alert details is a file hash we can use to see if this attachment is malicious.&lt;/p&gt;

&lt;p&gt;File Hash:&lt;br&gt;
52945af1def85b171870b31fa4782e52&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwy9zpegz6upremzogrh5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fwy9zpegz6upremzogrh5.png" alt="VirusTotal - 123" width="800" height="460"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Click on Malicious and let's move on.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3 - Check if Someone Requested the C2:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0io988swxth3cw94sm9r.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F0io988swxth3cw94sm9r.png" alt="Requested C2 - 123" width="800" height="484"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We know the host requested several times the malicious IP address:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frrxr9akc4n3tnt831kyl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frrxr9akc4n3tnt831kyl.png" alt="Log Management - 123" width="800" height="395"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The 141.105.65.149&lt;/p&gt;

&lt;p&gt;Using AbuseIPDB we can scan the IP address we found in the Log Management:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkvz8fs82z8khewuleue1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkvz8fs82z8khewuleue1.png" alt="AbuseIPDB - 123" width="800" height="417"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So click on "Accessed".&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 4 - Containment:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F81m26q4s7fe0lbmsozmj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F81m26q4s7fe0lbmsozmj.png" alt="Contain - 123" width="800" height="428"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The host is compromised and is a risk to our organization, we go to Endpoint Security, search for the compromised host and contain it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy0h65zhxwrsgfqlgxdtb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy0h65zhxwrsgfqlgxdtb.png" alt="Contained - 123" width="800" height="415"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Move forward and hit "Next".&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 5 - Add Artifacts:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ftrm9m8rbp28i5lo5c65m.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ftrm9m8rbp28i5lo5c65m.png" alt="Add Artifacts - 123" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Add here the IOCs you found like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;172.16.17.39 Compromised IP&lt;/li&gt;
&lt;li&gt;52945af1def85b171870b31fa4782e52 Malicious File&lt;/li&gt;
&lt;li&gt;141.105.65.149 C2 IP address&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Next.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 6 - Analyst Notes:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Here is recommended that you write a summary explaining the nature of the malware, in this case the Follina 0-day exploit, how it was detected and the immediate actions taken, your investigation findings, with all the IOCs that you have found, the containment steps, also the future actions that could be done to prevent or mitigate the risk.&lt;/p&gt;

&lt;p&gt;Close the alert and this is True Positive, add your findings and how it was mitigated.&lt;/p&gt;

&lt;p&gt;And we have finished this 0-day vulnerability CVE-2022-30190 a.k.a. Follina.&lt;/p&gt;

&lt;p&gt;See you next time!&lt;/p&gt;

</description>
      <category>letsdefend</category>
      <category>cybersecurity</category>
      <category>blueteam</category>
      <category>siem</category>
    </item>
    <item>
      <title>LetsDefend SIEM Alert: Phishing Mail Detected - Internal to Internal - EventID: 52</title>
      <dc:creator>Jaime Barreto</dc:creator>
      <pubDate>Sun, 09 Mar 2025 18:09:00 +0000</pubDate>
      <link>https://dev.to/binarybastion/letsdefend-siem-alert-phishing-mail-detected-internal-to-internal-eventid-52-567e</link>
      <guid>https://dev.to/binarybastion/letsdefend-siem-alert-phishing-mail-detected-internal-to-internal-eventid-52-567e</guid>
      <description>&lt;p&gt;Hello everyone, today we're going to solve another LetsDefend SIEM alert: Internal to Internal.&lt;/p&gt;

&lt;p&gt;Internal to Internal refers to a type of phishing email that was sent from one internal email address to another internal email address. This suggests that either an employee's account has been compromised or it could be the case that the email originated from within the organization's network.&lt;/p&gt;

&lt;p&gt;This phishing attack is dangerous because internal emails are trusted more than external ones, making it easier for recipients to open attachments or click on embedded links.&lt;/p&gt;

&lt;p&gt;So we have to handle this alert promptly because it is crucial to safeguard our organization's security.&lt;/p&gt;

&lt;p&gt;So we start our investigation by creating the case and starting with the playbook:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjje8f1ziazv3v7so883n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjje8f1ziazv3v7so883n.png" alt="Playbook - 52" width="800" height="191"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Parse Email&lt;/strong&gt;
The first step towards our investigation is to obtain information about the incoming email, and the playbook tells us to get the following:&lt;/li&gt;
&lt;/ol&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;When it was sent?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the email's SMTP address?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the sender address?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the recipient address?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Is the mail content suspicious?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Are there any attachment?&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2xakfz6819o9nk79vbyq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2xakfz6819o9nk79vbyq.png" alt="Parse Email - 52" width="800" height="478"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now we delve into aswering these questions, the first one is in the Event Time:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5i96liv19f72h4ecg9ef.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5i96liv19f72h4ecg9ef.png" alt="EventTime - 52" width="800" height="235"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;When it was sent?
Feb, 07, 2021, 04:24 AM&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now for the second question that is also in the alert overview:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3jb9n4n9uo062uu2qesf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3jb9n4n9uo062uu2qesf.png" alt="SMTP Address - 52" width="800" height="220"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What is the email's SMTP address?
172.16.20.3&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The third question is to know the sender address and is in the Source Address field:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fg7umvjrsx9g20v4n4cbo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fg7umvjrsx9g20v4n4cbo.png" alt="Source Address - 52" width="800" height="236"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What is the sender address?
john@ letsdefend.io&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The next is just below next:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fmdjrdibkmfb99rlh9gn1.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fmdjrdibkmfb99rlh9gn1.png" alt="Destination Address - 52" width="800" height="231"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What is the recipient address?
susie@ letsdefend.io &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The fifth question asked us to investigate whether the content of the email is suspicious. Here we go to the Email Security and search for that email using the date, time, the sender, and recipient, like this:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2wazlhewdici0pkaojfe.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2wazlhewdici0pkaojfe.png" alt="Mail Search - 52" width="800" height="341"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And we click on the corresponding mail:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fex5pajzkhaez087218kh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fex5pajzkhaez087218kh.png" alt="Inside Mail - 52" width="800" height="165"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And know we finally can answer to the last two questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Is the mail content suspicious?&lt;br&gt;
Seems like a normal non-suspicious mail from one coworker to another coworker.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Are there any attachment?&lt;br&gt;
No attachment are included in the email.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now to continue with the Playbook, and click on Next.&lt;/p&gt;

&lt;p&gt;The Playbook now asks us if there were any attachments or any URLs in the email.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F65kf31po8wej1wzius11.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F65kf31po8wej1wzius11.png" alt="Attachments - 52" width="800" height="437"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;There were not attachments or any URLs in the email so we click on "No", and continue with the Playbook.&lt;/p&gt;

&lt;p&gt;Now lets add some artifacts found:&lt;/p&gt;

&lt;p&gt;Source Address: &lt;br&gt;
john@ letsdefend.io&lt;/p&gt;

&lt;p&gt;Destination Address:&lt;br&gt;
susie@ letsdefend.io&lt;/p&gt;

&lt;p&gt;SMTP Address:&lt;br&gt;
172.16.20.3&lt;/p&gt;

&lt;p&gt;Click on Next.&lt;/p&gt;

&lt;p&gt;Add any notes in here.&lt;/p&gt;

&lt;p&gt;Finish the Playbook by clicking on Confirm.&lt;/p&gt;

&lt;p&gt;We have all that we need to close this alert, its a False Positive because there were nothing malicious in the email, no URLs or attachments.&lt;/p&gt;

&lt;p&gt;Close the alert and congratulations!, another alert completed!&lt;/p&gt;

</description>
      <category>letsdefend</category>
      <category>cybersecurity</category>
      <category>blueteam</category>
      <category>siem</category>
    </item>
    <item>
      <title>LetsDefend SIEM Alert: Phising URL Detected - EventID: 86</title>
      <dc:creator>Jaime Barreto</dc:creator>
      <pubDate>Tue, 04 Mar 2025 11:25:38 +0000</pubDate>
      <link>https://dev.to/binarybastion/letsdefend-siem-alert-phising-url-detected-eventid-86-9i2</link>
      <guid>https://dev.to/binarybastion/letsdefend-siem-alert-phising-url-detected-eventid-86-9i2</guid>
      <description>&lt;p&gt;Hey there, &lt;/p&gt;

&lt;p&gt;Here we are going to do a [SIEM] alert, for those who don't know what a [SIEM] is, [SIEM] stands for Security Information and Event Manager, it's a technology -a crucial for modern cybersecurity- that helps organizations to detect, analyze and respond (triage), that aggregate activity from various sources across their entire IT infrastructure. This enables real-time monitoring, analysis, and response to security alerts that are generated by the applications.&lt;/p&gt;

&lt;p&gt;We are going to focus on the LetsDefend SIEM simulator, and would looks like this:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqi6hhazux4usdahre6oz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqi6hhazux4usdahre6oz.png" alt="SIEM Overview - LetsDefend" width="800" height="418"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now, let's take ownership of the alert that the [SIEM] has detected: Phishing URL Detected - EventID: 86&lt;/p&gt;

&lt;p&gt;The Investigation Channel tab will open and we will see this screen:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fub19d9r5zygqjdg6yemz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fub19d9r5zygqjdg6yemz.png" alt="SIEM Investigation Channel - LetsDefend" width="800" height="364"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Have this info for easy access like a note.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;Critical Security Note:&lt;br&gt;
Always exercise caution when handling URL addresses - they may direct to malicious resources.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This information is important to our investigation, so I highly recommend to copy/paste this information, I use free tools to take notes like: Obsidian, Notion, OneNote, even the NotePad is useful.&lt;/p&gt;

&lt;p&gt;Then we proceed to [Create Case] below the [Action] in the [Investigation Channel].&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F6ufktcjpoq7eb88f1jhi.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F6ufktcjpoq7eb88f1jhi.png" alt="Create Case - LetsDefend" width="800" height="418"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Click on [Continue] and proceed.&lt;/p&gt;

&lt;p&gt;Now it will show us with the [Incident Details], but we have more details from the previous page, before we continue here we need to open at least two more browser practice tab for making easer and comfortable analysis.&lt;/p&gt;

&lt;p&gt;[If you prefer to use one browser tab is ok].&lt;/p&gt;

&lt;p&gt;Now we will have a dedicated browser tab for the [Log Management], &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foan1mh667k7fksk997bf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foan1mh667k7fksk997bf.png" alt="Log Management - LetsDefend" width="800" height="417"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;and one for the [Endpoint Security].&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyoc4zrdvwrw5psmig3rz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyoc4zrdvwrw5psmig3rz.png" alt="Endpoint Security - LetsDefend" width="800" height="418"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now lets click on the [Start Playbook] blue button to start the investigation.&lt;/p&gt;

&lt;p&gt;It first dictates to collect data for the investigation, you can see that we already have this info collected even before it was asked!, just take a look on your notes.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpjcd8vlfl27fhwfbicml.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fpjcd8vlfl27fhwfbicml.png" alt="Collecting Data - LetsDefend" width="800" height="384"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The alert info gives the:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fk2fkefe6wiu6wu2wutxg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fk2fkefe6wiu6wu2wutxg.png" alt="Alert Information - LetsDefend" width="800" height="364"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Source address: 172.16.17.49&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Destination Address: 91.189.114.8&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 &lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With these data collected, now we proceed, click on [Next].&lt;/p&gt;

&lt;p&gt;Now the [Playbook] asked us to search into the [Log Management], we already have this opened, now is the time to look into it.&lt;/p&gt;

&lt;p&gt;The [Playbook] does not specify required parameters, but here we are going to use the [Event Time], we can find the [Event Time] in the notes that we already collected.&lt;/p&gt;

&lt;p&gt;Event Time:&lt;br&gt;
Mar, 22, 2021, 09:23 PM&lt;/p&gt;

&lt;p&gt;We also can change the viewing from [Pro] to [Basic]:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fedg5ar19etpp2s0jokkx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fedg5ar19etpp2s0jokkx.png" alt="Pro and Basic - LetsDefend" width="800" height="417"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This is just to view more detailed information [Pro], or just the information that we need and be easily readable [Basic].&lt;/p&gt;

&lt;p&gt;I'll switch to [Basic] because is more simple, yet useful for me and in this case.&lt;/p&gt;

&lt;p&gt;Go now to the blue [Show Filter] button and click on [Select Date] input field.&lt;/p&gt;

&lt;p&gt;Put the [Event Time], but first I recommend to change first the year, because if you change it after selecting the month and the day, it will not give you the chance to change the year.&lt;/p&gt;

&lt;p&gt;*Note: You can't select just one day, select a day before or a day after.&lt;br&gt;
Example:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdxx1uckduudhfoih6394.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fdxx1uckduudhfoih6394.png" alt="EventTime - LetsDefend" width="689" height="413"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Ok, now it will show us this info:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8l0t0owmj2lh7nywox3d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8l0t0owmj2lh7nywox3d.png" alt="Date Filter - LetsDefend" width="800" height="167"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We can see that the [SRC Address] and the [DST Address] are from the ones we are investigating [remember the data collected] and we also see below the [RAW] a magnifying glass with a [+] in it, click on it and lets see what we can find.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy3fw2xs7s8vcc5ed2sop.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy3fw2xs7s8vcc5ed2sop.png" alt="RAW log - LetsDefend" width="630" height="204"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Don't close this pop-up, we will need it in the next step.&lt;/p&gt;

&lt;p&gt;Now go back to the [Playbook] and click on [Next].&lt;/p&gt;

&lt;p&gt;The next step on the [Playbook] is to analyze the URL Address that we have found in our investigation using any of the free services that shown, but I recommend VirusTotal, URLHouse, URLScan and Hybrid Analysis, AnyRun you need a company email to register and to use it.&lt;/p&gt;

&lt;p&gt;In this case we are going to use VirusTotal and paste the [URL Address] the seach field on the top of the page and hit [Enter].&lt;/p&gt;

&lt;p&gt;We see that the [URL Address] is definitely [Malicious], and now we get back at the [Playbook] and click on the [Malicious] button.&lt;/p&gt;

&lt;p&gt;The [Playbook] ask if anyone as accessed the [IP/URL/Domain] to answer the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;When was it accessed?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the source address?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the destination address?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Which user tried to access?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;What is the User Agent?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;is the request blocked?&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now we know where to look, and we go to the [Log Management] again.&lt;/p&gt;

&lt;p&gt;Answering these questions:&lt;br&gt;
When was it accessed?&lt;br&gt;
We have the date and the time: Mar, 21, 2021, 09:23 PM&lt;/p&gt;

&lt;p&gt;What is the source address?&lt;br&gt;
We see it in the [SRC.ADDRESS] section: 172.16.17.49&lt;/p&gt;

&lt;p&gt;What is the destination address?&lt;br&gt;
The same before but below the [DST.ADDRESS] section: 91.189.114.8&lt;/p&gt;

&lt;p&gt;Which user tried to access?&lt;br&gt;
To know which user was, we can use the [Endpoint Security] and put the [SRC.ADDRESS] or in our notes under the [Source Address], the user is EmilyComp.&lt;/p&gt;

&lt;p&gt;What is the User Agent?&lt;br&gt;
This is also can be found in our notes:&lt;br&gt;
User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36&lt;/p&gt;

&lt;p&gt;Is the request blocked?&lt;br&gt;
Again we can see this info in our notes under [Device Action]:&lt;br&gt;
Allowed.&lt;/p&gt;

&lt;p&gt;Let's head back to the [Playbook] and click on [Accessed].&lt;/p&gt;

&lt;p&gt;Now it asked us to [Contain] the infected host machine, under the [Endpoint Security] search for [EmilyComp], and click on [Containment], it changes to [Host Contained].&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fb4ljgtmj0khceor20mea.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fb4ljgtmj0khceor20mea.png" alt="Containment - LetsDefend" width="800" height="257"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now click on [Next] to finish the [Playbook].&lt;/p&gt;

&lt;p&gt;Here we can add artifacts of our findings:&lt;/p&gt;

&lt;p&gt;Source Address : 172.16.17.49&lt;br&gt;
Destination Address : 91.189.114.8&lt;/p&gt;

&lt;p&gt;Request URL : The Malicious Requested URL&lt;/p&gt;

&lt;p&gt;Click on [Next] and submit comprehensive case notes, now go to [Next] again.&lt;/p&gt;

&lt;p&gt;Finish the [Playbook] by clicking [Confirm] and now we are back to the SIEM Monitoring page where we see our alert, go to [Action] and click on the check mark to [close alert].&lt;/p&gt;

&lt;p&gt;Here it ask if this was a [True Positive] or a [False Positive], This was a [True Positive] because the alert correctly identified the security threat.&lt;/p&gt;

&lt;p&gt;Well this is the end for this SIEM alert on the LetsDefend page, hope you all find this useful and understandable.&lt;/p&gt;

&lt;p&gt;If you have any question you are free to comment!&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>soc</category>
      <category>letsdefend</category>
      <category>siem</category>
    </item>
  </channel>
</rss>
