Something need to be noted
Is there a malware that is actively in the system?
Is there any suspicious internal or external communication?
Is there any persistence?
Tools That Can Be Used
Process Hacker
Autoruns
FullEventLogView
LastActivityView
BrowsingHistoryView
Procedures That Must be Conducted for Memory Analysis
Process Tree
Web Connections
Signature Status
Net user
Lusrmgr.msc
%SystemRoot%\Temp
%UserProfile%\AppData\Local\Temp
C:\Users<user_name>\AppData\Roaming\Temp
%ProgramData%\Temp
Image Identification
Processes and Threads
Network Connections
Registry Analysis
File Analysis
Malware Analysis
Service Analysis
Linux Bash History / User Activities
This knowledge has been compiled from resources provided by LetsDefendarrow-up-right.
Last updated 10 months ago