DOMAIN: APEXCORP.LOCAL โ SOC ANALYST PERSPECTIVE
Microsoft Defender for Identity has fired an alert on the APEXCORP.LOCAL domain at 09:14 UTC. Windows Security Event logs show anomalous Kerberos and LDAP activity originating from an internal workstation. Your job as a SOC analyst is to investigate, identify the attack chain, and document the incident.
| Asset | Detail |
|---|---|
| Domain | APEXCORP.LOCAL |
| Domain Controller | DC01 โ 10.10.18.10 |
| Affected workstation | Investigate from logs |
| Alert time | 2026-05-08 09:14:02 UTC |
| Your role | SOC Analyst โ Tier 2 |
| Event ID | Technique |
|---|---|
| 4769 | Kerberos Service Ticket โ look for RC4 (0x17) |
| 4624 | Logon โ look for Type 3, NtLmSsp package |
| 4662 | Object access โ DS-Replication-Get-Changes-All |
| 4672 | Special privileges assigned to new logon |
| 4768 | Kerberos TGT request โ baseline activity |