Skip to main content

A01 — Reactive IR: LifeTech Pharma

Mode: Reactive · Org: LifeTech Pharma · PROJ-2024-001

Scenario

An Israeli pharmaceutical company discovers that 2.4 GB of R&D data was exfiltrated over 3 hours on the night of 14–15 November 2024. The SOC opened a P3 ticket after noticing a log gap — not an alert. Zero detection rules fired during the 52-hour incident.

Your entry point: You receive a case in TheHive with 6 evidence sources, a 4-hour Sysmon gap, and a P1 escalation. Determine who, how, and why — and ensure it doesn't happen again.

Key Facts

FieldValue
Dwell time52 hours 46 minutes (confirmed)
DetectionNone during incident — gap noticed manually
Data stolen2.4 GB R&D data (R&D share, USPartner2024 folder)
Entry vectorAiTM phishing → session token capture → contractor VPN
AssessmentIranian-nexus activity cluster (medium confidence)
Coverage gap0 / 12 techniques detected during incident

Kill Chain Summary

PhaseTechniqueEvidence
Initial AccessT1566.001 SpearphishingLookalike domain lifetechpharma-corp[.]eu
Credential AccessT1557 AiTM session captureVPN logon from Istanbul at 04:05 IST; TOTP bypassed
Lateral MovementT1021.001 RDPEID 4624 Type 10 JUMPHOST-01 → WS-IT-LEVI
Credential AccessT1003.001 LSASS comsvcs.dllGrantedAccess 0x1410; comsvcs.dll MiniDump
Credential AccessT1003.006 DCSyncEID 4662 Replication-Get-Changes-All on DC-01
PersistenceT1547.001 Registry Run key (via service)EID 7045 WindowsUpdateAgent from non-standard path
ExfiltrationT1041 HTTPS multi-chunk2.4 GB to 198.51.100.44 over 3 hours in 8 sessions
Defense EvasionT1070.001 Log clearEID 1102 — wevtutil cl after Sysmon crash window

Assignment Deliverables

  1. Unified incident timeline — all 22 events with source, account, indicator, ATT&CK technique, confidence
  2. ATT&CK mapping — 12 techniques; detection status column; DeTT&CT score per technique
  3. Attribution assessment — Admiralty-rated claim; competing hypotheses; what would change the assessment
  4. 4 Sigma rules — DET-001 (Office→PS child), DET-002 (LSASS comsvcs), DET-003 (DCSync EID 4662), DET-004 (VPN ASN anomaly)
  5. SOC handoff — IOC table, detection deployment status, immediate containment actions
  6. Executive brief — 1-page non-technical; gap statement; 3 recommended actions

Key Learning Objectives

  • Reconstruct a timeline from heterogeneous sources (Winlogbeat, VPN logs, PAM recordings, DNS, firewall) including a 4-hour evidence gap
  • Distinguish "rule missing" from "log source missing" when documenting detection failures
  • Write a DCSync detection rule against EID 4662 with Replication-Get-Changes-All GUID filter
  • Communicate a 0/12 detection coverage failure to a CISO without technical jargon

Evidence Files

01-evidence/raw/
email/ phish-m-cohen-2024-11-15.eml
phish-p-levi-2024-10-22.eml
logs/ sysmon-ws-it-levi.jsonl ← 4-hour gap 03:02–07:14 IST
sysmon-server-fin-01.jsonl
winsec-dc01.jsonl
network/ dns-connections.jsonl

Solution Highlights

The 4-hour Sysmon gap (WS-IT-LEVI) is a critical constraint: the initial staging activity during that window cannot be confirmed from SIEM. Log clearing (EID 1102) occurred at 03:14 IST — inside the gap. The PAM session recording on JUMPHOST-01 is the primary source for the 22:11–02:47 IST window.

DET-003 (DCSync) requires filtering EID 4662 by both ObjectType (computer account or domain) AND the two DS-Replication-Get-Changes GUIDs — without the GUID filter, noise from legitimate replication events makes the rule unusable.