Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

in

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

A practical SOC-style investigation walkthrough using Windows telemetry to identify attacker activity and defense evasion techniques.

Introduction

In this write-up, I investigate the TryHackMe room “New Hire, Old Artifacts, which focuses on analyzing malicious activity on a compromised Windows workstation using Sysmon logs and Splunk queries and I explain the methodology I used to identify suspicious artifacts and investigate the actions performed by the attacker.

This type of investigation closely reflects tasks performed by Security Operations Center (SOC) analysts, where log analysis and event correlation are used to detect malicious behavior and reconstruct attacker activity.


Investigation Overview

Platform: TryHackMe
Scenario: Investigating malicious activity on a compromised Windows workstation
Tools Used: Splunk, Sysmon logs
Focus Areas:

  • Process execution investigation
  • Network connection analysis
  • Registry modification detection
  • PowerShell command analysis
  • DLL loading analysis

This investigation demonstrates practical blue team and SOC analyst skills, including log analysis, threat hunting, and attacker behavior identification.


Investigation Walkthrough

A Web Browser Password Viewer executed on the infected machine. What is the name of the binary? Enter the full path.

Process: I queried the Sysmon sourcetype and searched for EventCode=1, which corresponds to process creation events.

I then examined the top results of the CommandLine field to identify suspicious executables.

Among the results, I detected a suspicious binary name.

1_cAMla-G-WpkRVyI2uadoSg.png

Answer: C:\Users\FINANC~1\AppData\Local\Temp\11111.exe


What is listed as the company name?

Process: To investigate further, I isolated one of the events associated with the malicious executable by selecting one of the entries from the CommandLine field that showed its execution.

1_KGJarriDtezvDRcjpqO2pg.png

I then inspected the event fields and located the Company field, which contained the value requested in the question.

1_fag2JdIEoMG2lbPrSn5RLg.png

Answer: NirSoft


Another suspicious binary running from the same folder was executed on the workstation. What was the name of the binary? What is listed as its original filename? (format: file.xyz,file.xyz)

Process: First, I reviewed the ComputerName field of the previous event and noted the system name.

1_4xHzGn7KyN642ZoJiT9Gbg.png

Next, I checked the CurrentDirectory field to determine the folder from which the executable was launched.

1_XQwAZisaSo7Hx05jI7m5DQ.png

Using this information, I created a new Splunk query filtering by both fields and searched again in the Sysmon logs for EventCode=1 to identify additional process executions.

1_nfRI2uBLoX0t4zThtKhbCw.png

Since the question also required the original filename, I inspected the OriginalFileName field and identified a suspicious value: PalitExplorer.exe.

1_UJbvolPYyeSRA4iZ4YFEvQ.png

Using this field to further narrow the search results, I identified the relevant event.

1_g0Jc9fMu7Z5zAOzp1t8H4Q.png

Answer: IonicLarge.exe,PalitExplorer.exe


The binary from the previous question made two outbound connections to a malicious IP address. What was the IP address? Enter the answer in a defang format.

Process: continued investigating the Sysmon logs, this time searching for EventCode=3, which corresponds to network connection events.

I filtered by the same workstation and included the executable name to locate related network activity.

Inspecting the DestinationIp field revealed an external IP address that received two connections, matching the information provided in the question.

1__HWiqJahwMvvq1jjZP0vKQ.png

Since the challenge required a defanged IP address, I used CyberChef to convert the IP to the required format.

1_m4kQ7l1A9EGMXOcxIePABQ.png

Answer: 2[.]56[.]59[.]42


The same binary made some change to a registry key. What was the key path?

Process: To identify registry activity, I kept the ComputerName filter and included the malicious binary name IonicLarge.exe.

I then filtered for registry-related Sysmon events:

EventCode IN (12,13,14)

These event IDs correspond to registry key creation, deletion, and modification.

1_dAYm2_112f_scbBgfJmw3w.png

The results revealed several registry modifications related to Windows Defender policies.

Answer: HKLM\Software\Policies\Microsoft\Windows Defender


Some processes were killed and the associated binaries were deleted. What were the names of the two binaries? (format: file.xyz,file.xyz)

Process: To identify terminated processes, I searched for events where the Image field referenced the Windows utility Taskkill, which is commonly used to terminate running processes.

After locating the relevant events, I inspected the CommandLine field to determine which processes were terminated using this tool.

1_fTlPydgRAU_sJrW5EjfifQ.png

Answer: WvmIOrcfsuILdX6SNwIRmGOJ.exe,phcIAmLJMAIMSa9j9MpgJo1m.exe


The attacker ran several commands within a PowerShell session to change the behaviour of Windows Defender. What was the last command executed in the series of similar commands?

Process: I searched using the keyword Defender to retrieve events related to Windows Defender.

I also included CommandLine=* to ensure the results contained command executions.

Since the activity occurred within a PowerShell session, I narrowed the search by filtering the Image field for PowerShell.

To identify the most recent command, I sorted the results by _time in descending order.

1_F-6M_vcCUdwdzf7-NDhDXg.png

1_uBvG8f-gfB6bkvSJhpRdYw.png

Answer: powershell WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ThreatIDDefaultAction_Ids=2147737394 ThreatIDDefaultAction_Actions=6 Force=True


Based on the previous answer, what were the four IDs set by the attacker? Enter the answer in order of execution. (format: 1st,2nd,3rd,4th)

Process:
Using the results from the previous search, I examined the CommandLine field and identified the IDs set within the commands executed by the attacker.

1_oQK-FqthwIJ_GOLdbbiQ5Q.png

Answer: 2147735503,2147737010,2147737007,2147737394


Another malicious binary was executed on the infected workstation from another AppData location. What was the full path to the binary?

Process:
Since the question referenced another AppData location, I used AppData as a search keyword.

I then sorted the results to display the most recent events, which could correspond to later stages of the attack.

By examining the Image field, I identified another suspicious executable launched from an AppData directory.

1_dG86fSnRApORB5suOd176Q.png

Answer: C:\Users\Finance01\AppData\Roaming\EasyCalc\EasyCalc.exe


What were the DLLs that were loaded from the binary from the previous question? Enter the answers in alphabetical order. (format: file1.dll,file2.dll,file3.dll)

Process: To identify DLL activity, I searched using the Image field corresponding to the previously discovered executable.

I then filtered forEventCode=7 Sysmon Event ID 7 records Image Loaded events, which occur when a process loads a DLL or similar module.

1_0Id5lqlM5bcGN5_huzNF-g.png

To review the modules loaded by the executable, I examined the ImageLoaded field using top statistics.

1_WAOf2MUch6kzUhJSVinz5g.png

Although the executable loaded more than three DLLs, the three most frequently occurring modules matched the ones required by the challenge.

1_Og3ZKxCuGhktcF2ExTfx9A.png

Answer: ffmpeg.dll,nw.dll,nw_elf.dll


Investigation Timeline

Based on the analyzed logs, the attacker activity appears to follow this sequence:

  1. Execution of a password viewer tool.
  2. Execution of another suspicious binary from the same directory.
  3. Outbound network connections to an external IP address.
  4. Registry modifications targeting Windows Defender.
  5. Termination of processes using Taskkill.
  6. PowerShell commands executed to alter Windows Defender behavior.
  7. Execution of an additional binary from an AppData directory.
  8. Loading of multiple DLL modules by the malicious executable.

This sequence highlights common attacker techniques such as defense evasion, credential harvesting, and malicious execution from user directories.


Conclusion

This challenge provided a practical scenario for analyzing malicious activity using Sysmon logs and Splunk queries.

By correlating process execution events, network connections, registry modifications, and PowerShell activity, it was possible to reconstruct the attacker’s actions on the compromised workstation.

Exercises like this are valuable for developing the skills required in Security Operations Center (SOC) environments, where analysts must analyze logs and identify indicators of compromise across multiple telemetry sources.