Investigating Darktrace alerts for lateral movement
ID: 5cbee92e-c2be-52c8-bb35-ea1a1bff8317
STIX ID: report--5cbee92e-c2be-52c8-bb35-ea1a1bff8317
Feed Name: Expel Blog
This post describes how Expel analysts leverage Darktrace to triage and investigate model-breach alerts, focusing on detecting and analyzing lateral movement via SMB (remote file copy, T1105). It details useful Darktrace features (advanced log search, full packet capture, asset identification), a step-by-step investigation of a Scheduled Task model breach, and how to validate findings with historical logs and PCAP extraction, ultimately concluding the observed activity was legitimate administrative behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
