Nov. 7, 2022, 7:06 p.m. | /u/Schaedelbasisbruch

cybersecurity www.reddit.com

Today, MDE captured a file infected with Emotet. It was a file triggered from wininit.exe in a user directory. It also happened in the past and I want to investigate where the file came from. There are no Mails (mailclients) on this particular Endpoint (Server 2016).

What would you recommend?

cybersecurity emotet

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Solution Architect

@ Civica | London, England, United Kingdom

Information Security Officer (80-100%)

@ SIX Group | Zurich, CH

Cloud Information Systems Security Engineer

@ Analytic Solutions Group | Chantilly, Virginia, United States

SRE Engineer & Security Software Administrator

@ Talan | Mexico City, Spain