logo

DFIR: From alert to root cause using Osquery without leaving Elastic Security

ID: 48e97f17-0c4b-599b-bd54-50381bad9f13

STIX ID: report--48e97f17-0c4b-599b-bd54-50381bad9f13

Feed Name: Elastic Security Labs

Threat Score
45/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

...
...

This technical blog explains a distributed, query-driven DFIR workflow using Osquery and Elastic Defend, demonstrating how investigators can reconstruct an attack chain (phishing → download of discount.zip → extraction → execution of Mimikatz) via live endpoint queries (browser history, file table, Shimcache, Shellbags, UserAssist, Prefetch), operationalize queries into scheduled packs for detection, and move from detection to response without full disk imaging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.