Persistence report
i-0aa608f5a5afbf06e·b96d5aaa-7b53-59a9-af3f-f4503b67585fCRITICAL suspicionHIGH confidence
- Anchor
- 2023-02-09T10:58:30.3285501Z
- Detected
- 2026-10-07T00:00:00Z
- Report
- pursuit-20261007-win-host-1
Gate 4 critical: multiple independent Gate 3 mechanisms form an attacker-controlled chain. A machine Group Policy startup script is present and executed, launches Frida against lsass.exe, extracts TLS secrets, and writes them to a remote share; a hidden PowerShell Scheduled Job executes the same packet-buffer chain; and a common Startup shortcut targets disable_defender.ps1. The chain is corroborated by Sysmon process telemetry and repeated Elastic Agent service crashes.
Overall Assessment
Host: WIN-HOST-1
Network name: win-host-1.asgard.corp
Severity: CRITICAL
Confidence: HIGH
Gate 4 is met. Multiple independent persistence mechanisms form an
attacker-controlled chain:
- - Machine Group Policy Startup contains and executes
packet_buffer.ps1. - - The script launches Frida against
lsass.exe, hooks TLS APIs through tls.js, captures session secrets, and writes them to \\10.10.200.40. - - A hidden PacketBuffer PowerShell Scheduled Job repeatedly launches the chain.
- - A common Startup shortcut targets a missing
disable_defender.ps1, and Sysmon records execution of that exact temporary script. - - Elastic Agent has repeated service termination events near the execution activity.
Key hashes:
- -
packet_buffer.ps1 MD5 1c80e6cdb3ca6e7147e04748ea33df4d; SHA256 e9776adb64a83154e447d9f359338997825a92d25b86f1a94f02cbdeb3b71ba7 - -
tls.js MD5 d96a6e6a8a663e5b8a3ec03bc7e9ea4d; SHA256 9fd39e27ee523a7a583d26190b0c3feb3e7668611d21055c9f32ab7970c1df6a - -
disable-defender.lnk MD5 b2ed0e2a1db37d46c556e681907f0c53; SHA256 2ece48f52de6150cf65a0a49cb39e0771ffa1285e515e72c4a27ea53a0824279
Findings
F-001: High. The persisted Group Policy script is malicious: it launches Frida against lsass.exe, extracts TLS secrets, and writes them remotely. Credential assessment is present for TLS session secrets, but no fixed password or token value was found.
F-002: High. The hidden PacketBuffer Scheduled Job is present and repeatedly executed under the Administrator context.
F-003: Medium. disable-defender.lnk is present and points to an executed but missing temporary PowerShell script. The target behavior is unverified.