All playbooks
Alert response · Execution / Initial Access responders
Unexpected execution
Code ran somewhere code does not normally run — a document, a signed utility, an interpreter.
The command line is the least interesting part. What launched it, and what it wrote, decide whether a lure worked.
What this does not establish
- Whether the payload worked. Execution is an attempt with an exit code you do not have.
- Whether a person clicked. Automation and a user look identical here.
- Whether it is the first stage. Most chains run several before anything is noisy.
0 of 10 ticked
Selected step
DetectStep 1 of 10
Walk the parent chain to a human action
- Office, browser or mail client as ancestor means a lure, not a service.
- A scheduler or service parent means something already had a foothold.
- Record the whole chain now; a process tree does not survive a reboot.
- Start the timeline now: every action, who took it, when.