SentinelOne had quarantined NetSupport before our EDR agent was installed. With the original detection logs unavailable, I used Prefetch, user-profile artefacts and support-session evidence to reconstruct earlier activity and checked them against a common timeline.
Viewed
Growing MSSP with Offensive Services
Investigating after containment
Vishing investigation without the original EDR logs
Return to the full story ←