Prefetch linked execution of curl, tar and rundll32 with associated .bat and .dll filenames. I checked those indicators in VirusTotal and ANY.RUN, then correlated browser and Outlook artefacts with Quick Assist logs and Microsoft WebView activity. The support session preceded malicious execution.
Viewed
Growing MSSP with Offensive Services
The artefacts that connected the sequence
Vishing investigation without the original EDR logs
Return to the full story ←