The document summarizes a security investigation conducted using Splunk software. The investigation began by detecting threat intelligence related network activity from an employee's system. Further investigation across endpoint, email, web, and DNS data sources traced the activity back to a targeted phishing email containing a weaponized PDF file. The file exploited a vulnerable PDF reader and installed Zeus malware. The root cause was determined to be a brute force attack on the company's website that stole the weaponized file. The investigation disrupted the cyber kill chain from reconnaissance to actions on objectives.