Agentic Triage
The assistant assembles a provisional picture — what we know, what we are assuming, and what is still unknown — then names the affected identities, assets, services, and the evidence that must survive containment.
AI assessment
Correlating signals across identity, endpoint and mailbox telemetry.
—
- Resolve: Whether the payment gateway has actually been accessed or only is reachable.
- Resolve: Whether lateral movement to FIN-FS-01 resulted in data staging or exfiltration.
- Resolve: Whether the batch service account (svc-finbatch) has been reused.
- Preserve 4 volatile evidence items before any containment action.
Known facts
5- Anomalous, encoded PowerShell executed on FIN-EP-204 under P. Martin's session.
- Identity provider shows failed logins from an unusual geography, then one success.
- A new mailbox rule auto-forwards payment-related threads to an external address.
- An SMB session opened from FIN-EP-204 to the shared finance file server (FIN-FS-01).
- P. Martin holds privileged access to payroll and payment-initiation systems.
Assumptions
3- The PowerShell activity is attacker-driven rather than sanctioned admin tooling.
- The forwarding rule was created by the threat actor, not the user.
- Credentials for P. Martin should be treated as compromised until proven otherwise.
Unknowns
4- Whether the payment gateway has actually been accessed or only is reachable.
- Whether lateral movement to FIN-FS-01 resulted in data staging or exfiltration.
- Whether the batch service account (svc-finbatch) has been reused.
- The full scope of mailbox data already forwarded externally.
Affected identities
Suspicious PowerShell spawned under this session; failed logins from new geo.
Non-interactive account; potential target for privilege reuse.
Delegate on the affected mailbox; forwarding rule references this inbox.
Affected assets
Origin of anomalous PowerShell; encoded command + outbound beacon attempt.
Shared finance file server; SMB session from FIN-EP-204 in last 20 min.
New inbox rule auto-forwarding payment threads to external address.
Failed logins from unusual geography, then one success for P. Martin.
No confirmed access yet; reachable from the compromised identity.
Affected business services
Run completes by 18:00; salaries settle next business day
Same-day payment cutoff 15:00
Month-end close in progress
Evidence to preserve before containment
Capture before isolation/power actions; holds in-memory payload + injected handles.
Decoded command line and module-load history; export before any reimage.
Snapshot rules and audit log before disabling the rule, to retain attribution.
Retained centrally; export at convenience for the timeline.
Confirms or refutes lateral movement; preserve before session teardown.