Compromised Endpoints · Security Incidents · Post-Incident Review
Endpoint investigations
Something is wrong on a machine, and the questions arrive in a fixed order. What ran. When. What else it touched. The artifacts that answer those questions are overwriting themselves while the first meeting is still going.
An incident is a question about sequence.
That a host was compromised is usually the easy finding. Order is the hard one. Which event came first, what followed from it, which systems the activity reached after that, and where the chain stops. The answer gets assembled out of records that were never written to serve as evidence: registry hives, prefetch, event logs, shellbags, journal entries, scheduled task definitions, service and driver registrations. Each holds a fragment. None of them was designed for an investigator.
Putting those fragments back in order is the work. The report is what is left over.
Engagement model
How 4n6PI engages on an incident
4n6PI is the forensic specialist on an incident, not the first responder. Engagements are activated per matter by written work authorization and performed inside the environment the client already runs, alongside internal security teams, outside counsel, or the managed service provider already under contract.
- Per matter, not standing. There is no continuous coverage, no security operations center function, and no response time commitment. The engagement begins when the authorization is signed and ends when the record is delivered.
- Containment and remediation stay with the client. Isolating hosts, resetting credentials, rebuilding systems, and deciding when services come back are calls for the client and its response lead. 4n6PI does not make them and does not execute them.
- Inside your environment, next to your people. Work runs on the access and tooling the organization already has, with a named internal contact. Nothing new gets installed to make the engagement possible.
- The deliverable is the forensic record. What happened, on which systems, in what order, documented so it holds up when someone sets out to challenge it.
Two roles, cleanly separated. One team stops the bleeding. The other establishes what happened, and can say later how it knows.
Scope
What gets examined
Endpoint artifact analysis
Registry, prefetch and application compatibility data, Windows event logs, browser history, link files and jump lists, file system metadata, and volatile memory where a capture exists. Windows, macOS, and Linux hosts.
Process execution and persistence
What executed, from where, under which account, and what it left behind to survive a reboot. Scheduled tasks, run keys, services, WMI event subscriptions, startup folders, and signed binaries used to load unsigned code.
Timeline reconstruction
File system, registry, event log, and application artifacts correlated into one ordered sequence, normalized to a single time zone, with the source of every entry retained so any line in the timeline can be traced back to the artifact it came from.
Indicators of compromise
Hashes, file paths, registry values, account names, scheduled task names, and network destinations, extracted in a form the internal team can search across the rest of the fleet without waiting on us.
Lateral movement and credential harvesting
Remote logon activity, service and admin share use, remote execution frameworks, and access to credential material. Which accounts were used, from which hosts, and which of that activity is consistent with normal administration.
Data staging and exfiltration
Collection into archives, staging directories, transfer to removable media or cloud storage, and the artifacts that show volume and timing. Where evidence supports only that data was gathered, that is what the report says.
Method
How findings are stated
Findings are written as indicators of compromise unless the evidence directly supports the stronger claim. An artifact consistent with credential theft is reported as an artifact consistent with credential theft, not as a confirmed credential theft. Where the record supports a definite conclusion, the report states it plainly and identifies the evidence that carries it.
- One host, one record. Each system is examined as its own evidentiary universe. A finding on one endpoint is not carried across to another because the two look similar.
- Absence is reported as absence. Logs that had already rotated, telemetry retention that had expired, and artifacts that never existed on the host are documented, not quietly stepped around.
- Method recorded with result. Tools, versions, queries, and the parsing performed are written down so another examiner working from the same source could repeat the analysis.
- Certified examiners, one set of hands. The examiner who performs the analysis writes the report and signs it.
The difference that matters most
An indicator of compromise is not a compromise. Reports that blur those two read well on the day they are issued and fail the first time anyone tests them.
Engage
When to call
- An alert or a user report suggests a host is compromised and someone needs to establish what actually ran on it
- Ransomware has been identified and the entry point, dwell time, and blast radius are still unknown
- A breach notification decision depends on whether data was accessed, gathered, or moved
- Your response lead has stabilized the environment and now needs a defensible account of how the intrusion started
- An insurer, regulator, or outside counsel has asked for a forensic examination the internal team cannot perform on its own systems
- A remediation is complete and the organization needs an independent read on whether the activity actually stopped
Preservation comes first in every one of those. Forensic collection can proceed on day one while the scope of the investigation is still being decided.
Bring in the record keeper early
The evidence that answers the hardest question in an incident has the shortest life. Call while the artifacts are still on the disk.