Inside the BHIS SOC: A Conversation with Hayden Covington
ID: 2ca79eb2-e233-54b1-a590-defeda456c60
STIX ID: report--2ca79eb2-e233-54b1-a590-defeda456c60
Feed Name: Black Hills Infosec Blog
Threat Score
This interview describes BHIS’s collaborative, non-tiered SOC model and recounts a recent detection where analysts found domain-admin activity, scheduled-task-triggered PowerShell, a suspicious DLL, VBScript-based payload delivery and an active command-and-control beacon tied to a compromised VMware tool download; the incident was contained before lateral movement or widespread ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
