I investigated a remote-support intrusion after SentinelOne quarantined NetSupport remote-management software. The MSSP EDR agent was installed after containment, and SentinelOne's original detection logs were unavailable. I therefore reconstructed the earlier activity from the Windows artefacts that remained.
Windows Prefetch records showed execution involving curl, tar and rundll32, alongside filenames associated with malicious .bat and .dll files. I correlated their timestamps and checked the indicators in VirusTotal and ANY.RUN. This supplied leads about the dropper and remote-access behaviour despite the missing early EDR history.
I examined the user profile, Downloads, Desktop and Documents locations, browser history and Outlook data files for an entry point. The inbox contained an unusual volume of spam, but I could not directly connect an email attachment or phishing message to the infection. Quick Assist session evidence and Microsoft WebView activity instead placed remote-support setup immediately before the malicious execution.
I took that timeline back to the client. The affected user described a flood of spam followed by a call from someone impersonating IT support, corroborating the likely vishing entry path. I produced a report covering the reconstruction, reversal of unauthorised changes and control recommendations, while retaining the limits imposed by the missing early logs.
Closer to the work
Working without early endpoint logs
SentinelOne had quarantined NetSupport before the MSSP EDR agent was installed. With no access to the original SentinelOne detection logs, the investigation could not rely on a complete endpoint execution history. Prefetch, profile artefacts and remote-support session evidence supplied the earlier timeline.
Open this detail ↗Windows and support-session artefacts
I correlated Prefetch execution records for curl, tar and rundll32 with associated .bat/.dll filenames, then used VirusTotal and ANY.RUN to contextualise the indicators. I also reviewed browser history, Outlook data files and user-profile locations. Quick Assist session logs and Microsoft WebView activity connected remote-support setup to the time immediately before infection.
Open this detail ↗The reconstructed timeline
The technical timeline and the user's account of spam flooding followed by a fake IT-support call supported a likely vishing entry path. The report documented the remote-support sequence and recovery recommendations. Neither the indicator review nor the absence of further artefacts established that all possible data access or attacker actions had been observed.
Open this detail ↗Skills established through this work