A detailed analysis of three real-world cyberattack incidents reveals that threat actors are far from the polished, sophisticated operators often portrayed in security reports. Using EDR telemetry, IIS web server logs, and Windows Event Log records, Huntress analysts trace how attackers repeatedly fumbled — mistyping commands, failing to start malicious Windows services, and getting blocked by Windows Defender. Across the three incidents (targeting a residential developer, a manufacturer, and an enterprise shared services org), the same threat actor appears to have iterated on their approach: after Windows Defender quarantined their tools in Incident 1, they added Defender exclusions in Incidents 2 and 3 — yet still failed to establish persistence via a Windows service. The post includes full IOCs and argues that understanding attacker failures and pivots is as valuable for defenders as understanding their successes.

11m read timeFrom huntress.com
Post cover image
Table of contents
Windows Event Log reality: behind-the-scenesIncident 1Incident 2Incident 3SummaryIndicators of Compromise (IOCs)