Touch Of Soul.zip Today

Using these artifacts to prove the malicious file was actually executed by the user.

Examining keys like HKCU\Software\Microsoft\Windows\CurrentVersion\Run for suspicious entries. Touch of Soul.zip

Searching for Event ID 4624 (Logon) or 4688 (Process Creation) to map the timeline of the attack. Using these artifacts to prove the malicious file