PowerShell masquerading, SOC Analyst Walkthrough, VirusTotal false negative

LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server

A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.