Does this alert warrant an investigation? What may seem like benign or normal traffic can be your worst nightmare. Maybe it's an APT doing some type of DNS C2 or maybe it's a malicious piece of JavaScript on a web page. What if the script/file/data is obfuscated? As an Analyst how would we approach this? Would we simply follow the same cut and dry analysis that we follow for every investigation? Join me on a journey through the ups and downs of dealing with this type of investigation, and how changing our thought processes and mind set can lead us to better identify nefarious actions.