[AI Soc]

Full-stack agentic SOC.

Perpetual's agentic triage and investigation can serve as an AI SOC, but Perpetual's AI is much more than that. Simba, our agent, has access to all the data, lineage, detections, investigations, and responses. Perpetual doesn't add another layer, it has built the right layer correctly.

[01/Triage]

Triage is no longer your job.

Every alert hits our agent Simba first. With direct access to your security data lake, Simba investigates, decides, and only escalates the cases that need you. When you open your queue, you see actionables, not noise.

ClickFix Attack on desktop-0321: fixer_update.exe C2
Beaconing to 157.230.130.11 (user jl.picard)

Simba Recommendation

This case requires human investigation

Assign to User
Summary
Regenerate

Successful ClickFix social engineering attack on desktop-0321 with active C2 implant beaconing for 2.5+ hours.

What happened:

  • Account jl.picard on desktop-0321 executed encoded PowerShell commands via Windows Terminal, downloading payloads from https://app.fork-it.cc/install to the TEMP directory. Whether this was the result of social engineering or intentional execution is unconfirmed.
  • Two payloads executed sequentially: fixer.exe (17:21–18:29 UTC, 68 min) then fixer_update.exe (19:18 UTC onward, still active at end of telemetry) — both beaconing to 157.230.130.11:443 at ~75-second intervals.
  • No post-exploitation was observed via Sysmon (no child processes, file drops, registry persistence, or lsass access), suggesting the implant was polling for operator tasking.
  • Unmonitored host 192.168.138.248 (theconstant) RDPed to domain controller dilithium-dc as DILITHIUMDATA\Administrator and to desktop-0321 minutes after C2 started — DC session was a 16-second reconnection with no malicious activity, but the source warrants investigation.

Why this matters:

  • The C2 channel was live and uncontained for 2.5+ hours with jl.picard privileges including SeDebugPrivilege; any operator tasking would be invisible inside the encrypted HTTPS tunnel.
123
[02/Cases]

Agent and analyst, on the same case.

Simba investigates alongside your team— every query, every decision, every artifact attached to the case file. No tab-switching, no parallel agent UIs, no separate query languages. One place, one record. Investigation proceeds in the background, and you can always chat with Simba.

ClickFix Attack on desktop-0321: fixer_update.exe C2 Beaconing to 157.230.130.11 (user jl.picard)

11 AnalysesResult
Analysis: Did fixer_update.exe execute on desktop-0321?
Analysis: Network connections from desktop-0321 to external IPs
Analysis: Full activity timeline on desktop-0321
Analysis: ClickFix activity observed on desktop-0321

create an attack flow diagram based on this case

Let me first get the case details to understand the attack flow.

Retrieved blocks for case CAS_1A2OTT6View

Now I have a comprehensive picture of the attack. Let me build the attack flow diagram.

Added note block to case CAS_1A2OTT6

I've created a comprehensive attack flow diagram and added it to the case as a note. Here's a summary of what it captures:

Attach Flow Overview

The diagram maps out the full ClickFix attack chain across two distinct waves:

Wave 1 — Undetected (17:10–18:29 UTC)

  • User jl.picard was socially engineered into pasting obfuscated PowerShell into Windows Terminal
  • Three obfuscation techniques were used (Hex+XOR+Deflate → Plaintext fallback)
  • fixer.exe was downloaded and executed, beaconing to 157.230.130.11:443 for 68 minutes undetected
[03/reflection]

Every case improves the next.

When a case closes, the outcome feeds back into the detection that created it. Simba surfaces noisy detections, suggests tunings, and points to the cases that prove it. The data closes the loop — no more detection engineers and analysts pointing fingers at each other.

Detection

Simba, our AI agent, suggests detections from our library for your environment

Simba continuously suggests new detections from threat intelligence

Simba can assist detection engineers improve detection logic

Investigation

Simba triages and investigates cases and only escalates to an analyst when necessary

Cooperate with agents in the case investigation workflow

Agent and analyst investigation activity is fully tracked in append-only cases

Response

Simba suggests response tasks during triage and investigation

Simba can invoke configured response actions while working cases

Analysts maintain full oversight over suggested response actions

Tuning

Simba continuously reflects on case outcomes to ensure detections are not generating noise

Low value, high false positive detections are flagged for tuning with concrete suggestions

Reflection and tuning close the loop and add compounding value to your SOC

[04/coverage]

Run ahead on the threatmill.

Simba reviews threat reports including from our internal feed, matches new reports against your environment and automatically authors new detections. The threatmill never stops. One down, infinite to go. Simba never gets winded.

Simba Proposals

Mar 9, 2026, 1:15 AM
Simba proposed 1 new detection
Trace

ClickFix via Windows Terminal

Create Detection

Related Threat Report

ClickFix campaign instructions shown in a threat report

New ClickFix Campaign Bypasses Traditional Detection via Windows Terminal

https://x.com/MsftSecIntel/status/202969295118992473

by Microsoft Threat Intelligence - via Feedly - Mar 16, 2026, 12:42 AM

[05/detection]

Alerts that earn your attention.

Perpetual detects end-to-end threat scenarios, not signal soup. The alerts that reach your team carry enough evidence to act on—and the noise that used to flood your queue stays behind.

Scenario - Windows ClickFix Initial Access
deploys
scenario_windows_clickfix_initial_access
queriesqueriesqueries
signal_windows_suspicious_process_creation
signal_windows_suspicious_usage
queriesqueries
signal_windows_suspicious_network_connection
queries
sysmon_events
queries
sysmon
queries
connector.sysmon

MATCH process_near_registry network_event=network_event+AGG event_start = min(timestamp),event_end = max(timestamp),proc_image = first(proc_image),proc_cmd_line = first(proc_cmd_line),proc_parent_image = first(proc_parent_image),proc_user = first(proc_user),reg_key = first(reg_key),reg_value = first(reg_value),dest_ip = last(dest_ip),dest_port = last(dest_port),beacon_count = count(dest_ip)BY hostWITHIN 5s

The agent doesn't sleep. Your analysts get to.

Perpetual platform dashboard
// Built from scratch for AI scale// Your data, in your cloud// Ingest everything, no trade-offs// Built from scratch for AI scale// Your data, in your cloud// Ingest everything, no trade-offs// Built from scratch for AI scale// Your data, in your cloud// Ingest everything, no trade-offs// Built from scratch for AI scale// Your data, in your cloud// Ingest everything, no trade-offs