24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Software & Technology · 2026
Software & Technology · Case 2026

200-endpoint software company · PowerShell Empire fileless C2 · undetected for 90 days

At a 200-endpoint software company a SOC analyst had been seeing anomalous PowerShell activity for weeks. AV/EDR kept coming back clean. With memory forensics DSET revealed an Empire C2 beacon, 47 endpoints were fully cleaned; after a ZTNA + EDR + Sysmon + KQL architecture, 12 months clean and a MITRE ATT&CK simulation was passed.

Duration
1 week of eradication · 30 days of architecture
Scope
47 infected endpoints · 90 days of exposure · DA 2 hops
Customer Satisfaction
★★★★★

01 The Challenge

Sysmon: an encoded PowerShell -enc command on 47 endpoints (for weeks). Memory dump: System.Reflection.Assembly.Load patterns (fileless). No disk artifact, only memory; AV/EDR coming back clean. Because Empire is signature-less, signature-based detection does not work. The DA compromise 2 hops away.

02 DSET's Approach

01

T+0 · Memory forensics

Analysis of 3 host memory dumps with Volatility. An Empire C2 server was detected (a PowerShellEmpire/empire-dev fork). A 47-host TTP map + USOM coordination.

02

T+1 week · Passive observation

1 week of TTP collection (without the attacker noticing): the C2 server, the exfil channel, 5 additional beacons revealed.

03

T+2 weeks · Coordinated eradication

Simultaneous cleanup of 47 endpoints (without the attacker's knowledge). Kerberos krbtgt rotation × 2, the Cobalt Strike beacon crew kicked out.

04

T+3 weeks · Constrained Mode

PowerShell Constrained Language Mode + AppLocker active. ZTNA + EDR (CrowdStrike Falcon) + Sysmon installed on all endpoints.

05

T+30 days · Sentinel KQL

47 KQL detection rules in Microsoft Sentinel (Empire + Cobalt Strike + Sliver + Mythic). The Empire detection rule catches it within 5 minutes.

06

T+60 days · MITRE simulation

A quarterly MITRE ATT&CK simulation (Atomic Red Team). A 96% detection rate in 4 simulations.

07

T+12 months · Continuously clean

DSET 24-month annual audit. 12 months clean, the MITRE simulation passed, insurance premium 30% discount.

03 Results in Numbers

47 endpoints
Empire eradication
1 week
Passive observation
5 min
Sentinel detection
96% detection
MITRE simulation
Prevented
DA compromise
30% discount
Insurance premium

04 Customer Testimonial

"

While AV/EDR came back clean, DSET revealed Empire beacons on 47 hosts with memory forensics. The passive observation strategy gave us a full TTP map; with coordinated eradication we kicked the attacker out without triggering them.

SOC Lead
Software & Technology · 200 endpoints
★★★★★

05 Key Takeaways

In fileless attacks memory is the only source of evidence; Volatility + memory acquisition is mandatory
Passive observation provides a 1-week TTP map; early eradication triggers the attacker
PowerShell Constrained Language Mode + AppLocker reduce the fileless attack surface by 85%
Sentinel KQL detection rules + Atomic Red Team simulation build "muscle memory"

06 Services Used in This Case

KAOS Local Artificial Intelligence

Turkey's cyber guardian · local · independent · on the path to world leadership.

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms