DFIR: From alert to root cause using Osquery without leaving Elastic Security
ID: 48e97f17-0c4b-599b-bd54-50381bad9f13
STIX ID: report--48e97f17-0c4b-599b-bd54-50381bad9f13
Feed Name: Elastic Security Labs
Threat Score
This technical blog explains a distributed, query-driven DFIR workflow using Osquery and Elastic Defend, demonstrating how investigators can reconstruct an attack chain (phishing → download of discount.zip → extraction → execution of Mimikatz) via live endpoint queries (browser history, file table, Shimcache, Shellbags, UserAssist, Prefetch), operationalize queries into scheduled packs for detection, and move from detection to response without full disk imaging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
