Welcome! #
- LetsDefend is a Blue Team Training platform.
- This writeup is for an alert on the LetsDefend simulated SOC.
The Alert: #

Actions:
- Copy alert details to notes.
- Check the file hash in VirusTotal to see if it’s known.
- Create Case.

VirusTotal: #

Playbook: #



Log Management: #

Endpoint Security: #


Action:
- Containing the endpoint.
Playbook (continued): #


Hybrid Analysis: #

Playbook (continued): #




- File was verified to be Ransomware via VirusTotal and Hybrid-Analysis.
- Endpoint EDR Agent was removed.
- Endpoint is infected.
- Endpoint Containment has been enabled.
Clean up: #




- File was verified to be Ransomware via VirusTotal and Hybrid-Analysis.
- Endpoint EDR Agent was removed.
- Endpoint is infected.
- Endpoint Containment has been enabled.
Result: #

Hope this helps!