Full-stack agentic SOC.
Perpetual's agentic triage and investigation can serve as an AI SOC, but Perpetual's AI is much more than that. Simba, our agent, has access to all the data, lineage, detections, investigations, and responses. Perpetual doesn't add another layer, it has built the right layer correctly.
Triage is no longer your job.
Every alert hits our agent Simba first. With direct access to your security data lake, Simba investigates, decides, and only escalates the cases that need you. When you open your queue, you see actionables, not noise.
ClickFix Attack on desktop-0321: fixer_update.exe C2
Beaconing to 157.230.130.11 (user jl.picard)
Simba Recommendation
This case requires human investigation
Successful ClickFix social engineering attack on desktop-0321 with active C2 implant beaconing for 2.5+ hours.
What happened:
- Account jl.picard on desktop-0321 executed encoded PowerShell commands via Windows Terminal, downloading payloads from https://app.fork-it.cc/install to the TEMP directory. Whether this was the result of social engineering or intentional execution is unconfirmed.
- Two payloads executed sequentially: fixer.exe (17:21–18:29 UTC, 68 min) then fixer_update.exe (19:18 UTC onward, still active at end of telemetry) — both beaconing to 157.230.130.11:443 at ~75-second intervals.
- No post-exploitation was observed via Sysmon (no child processes, file drops, registry persistence, or lsass access), suggesting the implant was polling for operator tasking.
- Unmonitored host 192.168.138.248 (theconstant) RDPed to domain controller dilithium-dc as DILITHIUMDATA\Administrator and to desktop-0321 minutes after C2 started — DC session was a 16-second reconnection with no malicious activity, but the source warrants investigation.
Why this matters:
- The C2 channel was live and uncontained for 2.5+ hours with jl.picard privileges including SeDebugPrivilege; any operator tasking would be invisible inside the encrypted HTTPS tunnel.
Agent and analyst, on the same case.
Simba investigates alongside your team— every query, every decision, every artifact attached to the case file. No tab-switching, no parallel agent UIs, no separate query languages. One place, one record. Investigation proceeds in the background, and you can always chat with Simba.
ClickFix Attack on desktop-0321: fixer_update.exe C2 Beaconing to 157.230.130.11 (user jl.picard)




create an attack flow diagram based on this case
Let me first get the case details to understand the attack flow.
Now I have a comprehensive picture of the attack. Let me build the attack flow diagram.
I've created a comprehensive attack flow diagram and added it to the case as a note. Here's a summary of what it captures:
Attach Flow Overview
The diagram maps out the full ClickFix attack chain across two distinct waves:
Wave 1 — Undetected (17:10–18:29 UTC)
- User
jl.picardwas socially engineered into pasting obfuscated PowerShell into Windows Terminal - Three obfuscation techniques were used (Hex+XOR+Deflate → Plaintext fallback)
fixer.exewas downloaded and executed, beaconing to157.230.130.11:443for 68 minutes undetected
Every case improves the next.
When a case closes, the outcome feeds back into the detection that created it. Simba surfaces noisy detections, suggests tunings, and points to the cases that prove it. The data closes the loop — no more detection engineers and analysts pointing fingers at each other.
Simba, our AI agent, suggests detections from our library for your environment
Simba continuously suggests new detections from threat intelligence
Simba can assist detection engineers improve detection logic
Simba triages and investigates cases and only escalates to an analyst when necessary
Cooperate with agents in the case investigation workflow
Agent and analyst investigation activity is fully tracked in append-only cases
Simba suggests response tasks during triage and investigation
Simba can invoke configured response actions while working cases
Analysts maintain full oversight over suggested response actions
Simba continuously reflects on case outcomes to ensure detections are not generating noise
Low value, high false positive detections are flagged for tuning with concrete suggestions
Reflection and tuning close the loop and add compounding value to your SOC
Run ahead on the threatmill.
Simba reviews threat reports including from our internal feed, matches new reports against your environment and automatically authors new detections. The threatmill never stops. One down, infinite to go. Simba never gets winded.
Simba Proposals
ClickFix via Windows Terminal
Related Threat Report
New ClickFix Campaign Bypasses Traditional Detection via Windows Terminal
by Microsoft Threat Intelligence - via Feedly - Mar 16, 2026, 12:42 AM
Alerts that earn your attention.
Perpetual detects end-to-end threat scenarios, not signal soup. The alerts that reach your team carry enough evidence to act on—and the noise that used to flood your queue stays behind.
MATCH process_near_registry network_event=network_event+AGG event_start = min(timestamp),event_end = max(timestamp),proc_image = first(proc_image),proc_cmd_line = first(proc_cmd_line),proc_parent_image = first(proc_parent_image),proc_user = first(proc_user),reg_key = first(reg_key),reg_value = first(reg_value),dest_ip = last(dest_ip),dest_port = last(dest_port),beacon_count = count(dest_ip)BY hostWITHIN 5s
The agent doesn't sleep. Your analysts get to.
