Process Injection — Active C2 and Domain Compromise Response
When injection-based active C2 connectivity, lateral movement, or domain-level compromise is detected, executes comprehensive coordinated isolation, removal of injected components, systemic persistence scanning, and full system recovery.
Prepare
4 steps- Active C2 triage threshold
This playbook applies only when at least one of the following conditions is met: injection confirmed in a memory dump + network beacon trace present; lateral movement (SMB/RPC/WMI to a different host) proven; Domain Admin / SYSTEM token in the injection target; persistence mechanism (registry run key, scheduled task, WMI event subscription, service) detected
- Coordinated response team
SOC L2/IR Lead, AD administrator, and CISO must be simultaneously engaged; all host isolation and network blocking decisions require approval from this trio
- Do not begin eradication before evidence and visibility are complete
If cleanup begins before missed hosts or "blind spot" gaps are resolved, the attacker will return via a different access path; this is the most critical sequencing requirement in this playbook
- Forensics capacity
Concurrent memory dump capacity equal to the number of affected hosts must be ready; verify EDR live response multi-host support