
Incident Response Case Study: Compromised Domain Controller via PowerShell and Stale Service Account
cybersecurityincident_responsePowerShelldomain_controllercompromised_accountRDPscheduled_taskthreat_detection
A medium-severity alert flagged a Base64-encoded PowerShell command on a finance department endpoint, which performed a DNS lookup for a newly registered domain before exiting cleanly. Further investigation revealed the same domain beaconing from a domain controller (DC) via an unusual svchost.exe process. The DC was found to have a malicious scheduled task disguised as a Windows update process, created 11 days prior, leveraging a stale, unprotected service account (svc_backup_old) with no MFA and an unchanged password for four years. The initial alert was traced back to a successful RDP login from an external IP 13 days earlier, using the compromised account.