Threat Hunting Malspam Japan Office Infected
You work as a security analyst for a company with locations worldwide, and recently, corporate headquarters opened a field office in Japan. On Tuesday 2017-06-27, you notice several high-priority alerts from two different Intrusion Detection Systems (IDS). One IDS is running Snort using the Snort subscription ruleset, and the other is running Suricata, using the EmergingThreats Pro ruleset. The results indicate a Windows computer was infected at the Japan field office, and you been asked to investigate this security breach....