Executive Summary

📂13 sources (47 disk, 49 other)
🔍454 tool calls
⏱️1.0 hours elapsed
🚨22 findings (6 critical, 10 high)
19 confirmed
🤔3 inference
🔒 SHA-256 hashes

The attack timeline spans 2014-12-01 to 2015-03-25. The earliest activity was Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering (2014-12-01). The investigation subsequently uncovered Intent Evidence: Web Searches About Data Leakage and Forensic Evasion; NIST Employee Identity Confirmed - Iaman Informant; Data Exfiltration Timeline and Method. The most recent activity was Anti-Forensic Tools Installation and Execution (2015-03-25).

Key Threats
  • US Government Email Address Found on Removable Media
  • Intent Evidence: Web Searches About Data Leakage and Forensic Evasion
  • Data Exfiltration Timeline and Method
  • NIST Employee Identity Confirmed - Iaman Informant
  • Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering

0
Total Findings
0
Critical
0
High
0
Medium
0
Confirmed
0
Inference
0
Sources
0
Tool Calls
Severity Breakdown
Critical (6) High (10) Medium (4) Info (2)
☑ Forensic Soundness and Evidence Integrity
Analysis was executed via a read-only Model Context Protocol (MCP) server mapped to the SANS SIFT toolchain. The MCP architecture enforces structural evidence protection: original evidence files were mounted as read-only volumes, all tool interactions are typed functions (no shell access), and every finding is validated against the append-only audit log before acceptance. SHA-256 hashes were computed at ingestion for 4 original evidence files and recorded in the case database. 454 tool calls executed across 13 indexed sources with full provenance tracking.
⚠ Critical Findings
  • US Government Email Address Found on Removable Media
    2015-03-24T09:59:27 — 2015-03-24T23:59:59
  • Intent Evidence: Web Searches About Data Leakage and Forensic Evasion
    2015-03-22T14:34:00
  • Data Exfiltration Timeline and Method
    2015-03-23T20:02:43
  • NIST Employee Identity Confirmed - Iaman Informant
    2015-03-22T14:34:41 — 2015-03-25T15:29:08
  • Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering
    2014-12-01T14:50:26Z — 2015-03-24T20:57:03Z
  • US Government Email Metadata in Exfiltrated Files - OMB/EOP and Library of Congress
    2015-03-24T09:59:27Z — 2015-03-24T23:59:59Z
⚔ MITRE ATT&CK Coverage
Reconnaissance (1)
Resource Development
Initial Access
Execution
Persistence (2)
Privilege Escalation (1)
Defense Evasion (6)
Credential Access
Discovery
Lateral Movement
Collection (1)
Command and Control
Exfiltration (2)
Impact
Inhibit Response Function
Evasion
Impair Process Control
Reconnaissance (1)Persistence (2)Privilege Escalation (1)Defense Evasion (6)Collection (1)Exfiltration (2)
12 techniques across 22 findings
★ IOC Summary
External IPs0
Internal IPs0
File Paths0
Hashes0
Emails5
Investigation Metadata
Case IDndlc
Evidence Root/evidence
Report Generated2026-09-20T06:42:02
Investigation Start2026-09-20T05:41:41
Investigation End2026-09-20T06:41:47
Total Processing1486.5s
Audit Log/home/mulder/.mulder/cases/ndlc.audit.jsonl
4 FILES Hashes computed during evidence ingestion. Compare against your local copies to confirm integrity.
FileSHA-256Size
cfreds_2015_data_leakage_pc.E01 e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 2.0 GB
cfreds_2015_data_leakage_rm1.E01 a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 74.6 MB
cfreds_2015_data_leakage_rm2.E01 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 243.2 MB
cfreds_2015_data_leakage_rm3_type3.E01 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b 90.2 MB

Investigation Report: Insider Threat Data Exfiltration

Background

This investigation examines evidence from a PC system, two USB flash drives (rm1 and rm2), and one optical media disc (rm3_type3) to determine the scope and nature of data exfiltration activities. The evidence inventory comprises 13 forensic sources including MFT analysis, filesystem extraction, bulk_extractor output, registry hives, and event log analysis.

The primary user account under investigation is "informant," identified as Iaman Informant, an employee of the National Institute of Standards and Technology (NIST) with the email address iaman.informant@nist.gov. The investigation period spans March 22-25, 2015, during which the user account was created, data was accessed and staged, and anti-forensic cleanup was executed.

The system under examination is a Windows 7 PC with an "informant" user profile created on March 22, 2015, at 14:34:41 UTC. The user's brief activity window of four days, combined with the creation of a resignation letter on March 25, suggests this was an intentional departure period during which sensitive data was systematically exfiltrated from government systems.

Incident Timeline

The incident reconstruction reveals a methodical four-phase operation executed over three days:

Phase 1: Initial Setup and Credential Creation (March 22, 2015)

At 14:34:41 UTC on March 22, the "informant" user account was created on the PC system. Within 30 minutes, three additional administrator accounts were created: admin11 at 15:51:54, ITechTeam at 15:52:30, and an account named "temporary" with a password reset at 15:53:11. All three accounts were granted local administrator privileges by the informant account. Security event logs confirm these actions were performed from the informant session (SubjectLogonId: 0x224e3). The admin11 account was used at least once at 15:57:30 UTC when NOTEPAD.EXE was executed, as recorded in UserAssist registry entries.

Phase 2: Source File Access and Cloud Infrastructure Setup (March 23, 2015)

On March 23, the user accessed source files from an "Authorized USB" drive (rm1). At 18:31:10 UTC, a SanDisk Cruzer Fit USB device was connected to the PC, as recorded in the Windows registry USBSTOR key. Seven minutes later, at 18:38:21 UTC, the user opened [secret_project]_design_concept.ppt from the USB drive, as evidenced by LNK file creation in the Recent documents folder (Users\informant\AppData\Roaming\Microsoft\Windows\Recent[secret_project]_design_concept.lnk).

The "Authorized USB" drive contained a "Secret Project Data" directory with organized project materials including design documents, proposals, and pricing files. A Word temporary file (~$ecret_project]_proposal.docx) indicated documents were actively edited on this drive.

Between 20:02:43 and 20:05:32 UTC, Google Drive desktop client was installed and configured. The sync folder was created at Users\informant\Google Drive\desktop.ini (created 20:05:32), and synchronization databases (sync_config.db, snapshot.db) were established. At 20:27:33 UTC, a second project file was accessed, evidenced by the LNK file [secret_project]_final_meeting.pptx.lnk.

Phase 3: Data Obfuscation and Staging (March 24, 2015)

The data exfiltration staging began on March 24 at 09:59:27 UTC when the first obfuscated file was created on USB drive rm2 (volume label "IAMAN $_@"). Over the next 51 seconds, through 10:00:18 UTC, all 17 masqueraded files were created. These files were disguised with media file extensions but contained Microsoft Office documents:

  • winter_storm.amr (14.5 MB) → OLE format
  • winter_whether_advisory.zip (16.4 MB) → PowerPoint
  • my_favorite_cars.db (1.3 MB) → OLE format
  • my_favorite_movies.7z (100 KB) → Excel
  • new_years_day.jpg (10.2 MB) → Excel
  • super_bowl.avi (10.3 MB) → OLE format
  • a_gift_from_you.gif (35.2 MB) → Word (largest file)
  • And 10 additional files in the diary_# series

All files were placed in $OrphanFiles directories marked as deleted entries and organized in folders named design, PRICIN~1 (pricing), progress, proposal, and TECHNI~1 (technical review). This naming convention suggests corporate/business documents being disguised as personal media files.

Later that day, at approximately 20:55:43 UTC, the same 17 files were burned to UDF optical media (rm3_type3, volume label "IAMAN CD"). The disc exhibits 9 VAT (Virtual Allocation Table) sessions showing progressive directory renaming and file deletion across sessions to obscure the original structure. The current session only contains three image files (Koala.jpg, Penguins.jpg, Tulips.jpg), while earlier sessions contained the 17 obfuscated documents that were later deleted but remain forensically recoverable.

Phase 4: Anti-Forensic Cleanup and Resignation (March 25, 2015)

On March 25, a coordinated anti-forensic cleanup operation was executed alongside employment termination activities:

  • 11:08:36 UTC: Timestamp manipulation detected on PC root directory. The $STANDARD_INFORMATION Created timestamp was backdated to 2009-07-14 (Windows installation date), creating a 2080-day discrepancy with the $FILE_NAME timestamp. This timestomping technique was used to hide recent filesystem activity.

  • 14:46:05 UTC: CCleaner installer (ccsetup504.exe) executed

  • 14:50:14 UTC: Eraser installer executed
  • 14:57:56 UTC: CCleaner executed (first run)
  • 15:12:28 UTC: Eraser executed (secure file deletion)
  • 15:15:50 UTC: CCleaner executed (second run)
  • 15:21:30 UTC: Google Drive sync executed (googledrivesync.exe)
  • 15:21:34 UTC: Google Drive lockfile last modified
  • 15:21:36 UTC: Google Drive folder updated
  • 15:28:33 UTC: Resignation letter created (Resignation_Letter_(Iaman_Informant).xps)
  • 15:29:08 UTC: Resignation letter last accessed (Resignation_Letter_(Iaman_Informant).docx)

The Google Drive sync databases (sync_config.db and snapshot.db) were deleted, preventing forensic determination of which files were uploaded to the cloud. The timing of cleanup activities immediately preceding the resignation letter demonstrates consciousness of guilt and premeditated evidence destruction.

Key Findings

Data Exfiltration via Multiple Channels

The investigation confirmed 19 findings involving confirmed data exfiltration through at least three distinct channels. The exfiltration was systematic, involving 17 files totaling approximately 85-90 MB of disguised Office documents containing sensitive government and business information.

The first channel was USB drive rm2 ("IAMAN $_@"), where files were staged in 51 seconds through a rapid batch copy operation. The second channel was optical media rm3_type3 ("IAMAN CD"), created approximately 11 hours after the USB staging, providing a redundant backup. The third channel was Google Drive cloud storage, installed the day before staging and actively synced during the cleanup phase, with sync databases subsequently deleted to hide evidence.

Government Document Metadata in Exfiltrated Files

Critical severity findings reveal that exfiltrated documents contained embedded email addresses from US Government sources. Eric_P._Lauer@omb.eop.gov represents the Office of Management and Budget within the Executive Office of the President. The mmun@loc.gov address represents the Library of Congress. Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) were found in document content, along with email subjects referencing historical photograph catalogs.

The presence of OMB/EOP metadata in documents labeled "Secret Project Data" indicates potential classified or sensitive unclassified information. A NIST employee exfiltrating documents containing Executive Office of the President and Library of Congress email metadata represents an insider threat incident with potential national security implications. The unauthorized removal of documents from federal systems constitutes potential federal crimes including theft of government property and unauthorized removal of records.

Systematic File Masquerading on USB and Optical Media

High severity findings document that all 17 files on both rm2 USB and rm3_type3 optical media were systematically renamed with misleading file extensions. Extension/content mismatch analysis shows Word documents disguised as .png, .gif, .txt, and .one files. Excel spreadsheets disguised as .7z and .jpg files. PowerPoint presentations disguised as .zip and .txt files. OLE compound documents disguised as .amr (audio), .db, and .avi (video) files.

This obfuscation technique, consistent with MITRE ATT&CK technique T1564.001 (Hide Artifacts: Hidden Files and Directories), is commonly used to bypass Data Loss Prevention systems and evade detection during exfiltration. The consistent folder structure across both media types (design, pricing, progress, proposal, technical review) indicates business documents disguised as personal media files.

Intent Evidence: Web Research on Data Leakage

Critical severity findings establish intent through web browsing evidence. The user researched "data-leakage-threats-mitigation-19312" (SANS whitepaper), "information leakage cases," and "leaking confidential information" with progressive query refinement showing "leaking confidenti" → "leaking confidential i" → "leaking confidential informat" → "leaking confidential information."

Additional research included the ForensicsWiki "Tools:Data_Recovery" page, Microsoft Research paper "leak_secret.pdf," and searches for "system cleaner." The user also accessed https://www.google.com/drive/ and https://www.google.com/drive/download/. This evidence proves the suspect had intent to leak confidential information and researched methods to avoid detection. The progression of search queries shows deliberate planning, not accidental data handling.

Anti-Forensic Tool Execution

High severity findings document the installation and execution of CCleaner and Eraser immediately following data exfiltration. These tools were installed on March 25, after the March 24 data staging. Eraser is designed for secure file deletion beyond forensic recovery. CCleaner cleans browser history, registry, temporary files, and system traces. The execution timing on the same day as the resignation letter indicates this was intentional cleanup as part of a planned departure, constituting evidence tampering and obstruction of justice.

Multiple Administrator Account Creation

Medium severity findings reveal that three additional administrator accounts (admin11, ITechTeam, temporary) were created by the informant account within 30 minutes of the informant account creation. While the admin11 account was used at least once (Notepad execution), the ITechTeam and temporary accounts show no evidence of interactive use. The creation of multiple admin accounts could indicate preparation for lateral movement with alternative credentials, plausible deniability through activity attribution to different accounts, backdoor access maintenance, or isolated contexts for exfiltration activities.

The absence of 4624 (successful logon) events for these accounts in security logs may indicate audit policy gaps, log clearing, or login via methods not generating 4624 events. The admin11 UserAssist entry proves at least minimal account usage.

Threat Intelligence and Attribution

Attribution Confidence: High for Insider Threat, Uncertain for External Collaboration

The evidence conclusively identifies Iaman Informant (iaman.informant@nist.gov) as the insider threat actor. Attribution is established through: email addresses in PC email data (iaman.informant@nist.gov, Exchange Labs identifier, Outlook profile), resignation letter naming the individual, consistent "IAMAN" naming across USB volume label "IAMAN $_@", optical media "IAMAN CD," and email identity.

The actor's NIST employment status makes this an insider threat incident with potential national security implications. As a federal employee, the user had trust and access privileges that were exploited for unauthorized removal of government documents.

Behavioral Indicators

The actor demonstrated sophisticated operational security awareness including: multi-channel redundancy (USB plus optical plus cloud), file extension masquerading to bypass DLP, timestamp manipulation to hide activity timing, anti-forensic tool deployment for evidence destruction, cloud sync database deletion to hide exfiltration volume, and progressive web search query refinement indicating research intent.

Potential External Collaboration Uncertainty

While the evidence proves insider threat activity conclusively, determination of external collaboration or foreign intelligence involvement requires additional investigation. The targeting of Executive Office of the President and Library of Congress documents by a NIST employee suggests potential awareness of sensitive government workflows, but no direct evidence of external direction or coordination was recovered. The personal email address (wayne.longman@att.net) and personal Gmail account (iaman.informant.personal@gmail.com) found in evidence could indicate external communication channels, but this requires further investigation of email content and cloud account activity.

The attribution confidence remains high for insider threat activity but uncertain regarding potential external collaboration.

Impact Assessment

Scope of Compromise

One PC system was actively used for data exfiltration activities by a single identified insider threat actor. The user account was created on March 22, 2015, and remained active for four days. Three additional administrator accounts were created, with one confirmed used and two showing no interactive use evidence.

Data at Risk

Seventeen files totaling approximately 85-90 MB were staged on removable media and potentially uploaded to cloud storage. Document metadata indicates Executive Office of the President (OMB/EOP) and Library of Congress email addresses were embedded in exfiltrated files. Content includes design documents, pricing information, proposals, progress reports, and technical reviews.

The data flow was: rm1 ("Authorized USB," source files) → PC (processing/obfuscation) → rm2 (USB, March 24 morning) AND rm3_type3 (optical, March 24 evening) AND Google Drive (cloud, status unknown due to database deletion). The deletion of Google Drive sync databases prevents determination of whether cloud exfiltration was successful and which specific files were uploaded.

Credential Exposure

Four user accounts with administrator privileges were created. Password reset activities were performed on all three additional accounts. If passwords were weak or shared externally, these accounts represent persistent access vectors even after the primary account was disabled.

Persistence Depth

No evidence of remote access tools, backdoors, or persistent malware was identified. The multi-account creation represents the primary persistence mechanism, potentially allowing backdoor access if not disabled. The activity window of four days with resignation letter creation suggests a deliberate exit strategy with no intention of persistent system access.

Business and Legal Impact

This incident represents: unauthorized removal of government records (potential federal crime), theft of intellectual property potentially containing Executive Office of the President information, violation of NIST security policies, evidence tampering and obstruction through anti-forensic tool deployment, and potential national security implications depending on document classification level.

The resignation timing correlated with exfiltration activities suggests premeditated departure with data theft, indicating this was not opportunistic but planned.

Immediate Tactical Containment

The following actions must be taken immediately to contain this incident:

  1. Disable all user accounts created by informant: Immediately disable the accounts "informant," "admin11," "ITechTeam," and "temporary" on the affected PC and any domain-wide systems where these accounts may have propagated.

  2. Isolate the affected PC system: Disconnect the PC from the network immediately to prevent any potential further data transmission or remote access.

  3. Secure removable media: The USB drives rm1 ("Authorized USB"), rm2 ("IAMAN $_@"), and optical disc rm3_type3 ("IAMAN CD") must be secured as evidence. Do not connect these to other systems.

  4. Block cloud exfiltration channel: Immediately revoke access to the Google Drive account configured with the sync folder at Users\informant\Google Drive. Initiate legal process to preserve and obtain Google Drive logs and stored data for the account.

  5. Preserve email communications: Preserve all email communications for iaman.informant@nist.gov and iaman.informant.personal@gmail.com. Review communications for external collaboration indicators.

  6. SanDisk Cruzer Fit USB investigation: Investigate the SanDisk Cruzer Fit USB device connected at 18:31:10 UTC on March 23. This device was connected 7 minutes before source file access began and may contain additional evidence.

  7. Review file access logs for source documents: Examine fileserver logs for the "Secret Project Data" directory to identify all files accessed and determine if additional files beyond the identified 17 were exfiltrated.

  8. Cloud storage account audit: Audit the user's Gmail account (iaman.informant.personal@gmail.com) and any other personal cloud storage accounts for uploaded government data.

Strategic Remediation

Root Cause 1: Insider Threat Detection Gap

The user was able to access sensitive government documents labeled "Secret Project Data," exfiltrate them over three days, and perform anti-forensic cleanup without triggering alerts. The absence of alerts for large-scale file staging, USB device usage, and cloud storage installation indicates insufficient insider threat monitoring.

Remediation: Deploy User and Entity Behavior Analytics (UEBA) to detect anomalous file access patterns, USB device usage, and cloud service installations. Specifically, configure alerts for: USB device connections by users with access to sensitive documents, installation of cloud storage clients on government systems, bulk file operations exceeding threshold volumes within short time windows, and execution of anti-forensic tools (CCleaner, Eraser) on any government system.

Root Cause 2: Data Loss Prevention Circumvention

Files were successfully renamed with media extensions (.jpg, .png, .avi, .amr) to bypass DLP controls. This indicates DLP rules were based on file extensions rather than content inspection or file signature analysis.

Remediation: Implement content-aware DLP that analyzes file payloads rather than extensions. Configure DLP to inspect for Office document signatures (DOCX, XLSX, PPTX, OLE compound documents) regardless of file extension. Block transfer of files with signature/extension mismatches to removable media or cloud services.

Root Cause 3: Privilege Management Weakness

A single user account was able to create three additional administrator accounts within 30 minutes without triggering approval workflows or generating alerts. This violates principle of least privilege.

Remediation: Implement Privileged Access Management (PAM) requiring approval workflows for administrator account creation. Configure alerts for any account creation by non-IT personnel. Restrict local administrator group membership to approved service accounts and documented IT staff.

Root Cause 4: Removable Media Controls Absent

USB drives were connected and used for staging government data without restriction. The volume labels "IAMAN $_@" and "Authorized USB" suggest the user was aware of and potentially circumventing media policies.

Remediation: Deploy USB device control using Device Control or similar solutions. Restrict USB access to approved encrypted devices only. Block write access to unapproved removable media on systems with access to sensitive documents.

Root Cause 5: Cloud Service Controls Insufficient

Google Drive was installed and synchronized government data without detection. The deleted sync databases indicate the user understood how to cover tracks.

Remediation: Block consumer cloud storage services (Google Drive, Dropbox, iCloud, OneDrive personal) at the network perimeter. Implement SSL inspection to detect unauthorized cloud service usage. Configureendpoint DLP to block sync client installations for unapproved cloud services.

Root Cause 6: Offboarding Security Gap

No evidence indicates the user's access was proactively revoked or monitored during the resignation period. The correlation between resignation timing and data exfiltration suggests the departure was anticipated without security escalation.

Remediation: Implement offboarding security protocols including: immediate access revocation upon resignation notification, enhanced monitoring for 30 days prior to departure for sensitive positions, mandatory exit interview with IT security review of system activity, and forensic imaging of departure-day activities for positions with sensitive access.

Conclusion

Q1. What systems were compromised?

One Windows 7 PC system was used as the primary exfiltration workstation. Three additional user accounts with administrator privileges (admin11, ITechTeam, temporary) were created on this system. The investigation found no evidence of compromise on other systems, no malware deployment, and no remote access tools installed. The compromise was limited to the insider threat actor's deliberate use of assigned workstation resources.

Q2. How did the attacker gain initial access?

This was an insider threat incident, not an external attack. The actor was a legitimate NIST employee (iaman.informant@nist.gov) with authorized access to the PC system. The user account was created on March 22, 2015, through standard provisioning. Initial access was legitimate employment-based access. No exploitation or credential theft was required.

Q3. What lateral movement occurred?

No traditional lateral movement to other systems was identified. However, the actor created three additional administrator accounts (admin11, ITechTeam, temporary) within the first 30 minutes of account creation. Only admin11 showed evidence of use (Notepad execution at 15:57:30 UTC on March 22). The creation of multiple admin accounts suggests preparation for potential lateral movement or establishing alternative access pathways.

Q4. What persistence mechanisms were installed?

No malware, remote access tools, or technical backdoors were installed. The primary persistence mechanism was the creation of multiple administrator accounts that could provide continued access if the primary account was disabled. The short activity window (four days) with resignation letter creation on the final day indicates the actor had no intention of persistent access—this was a departure time-limited data theft operation, not a long-term access strategy.

Q5. Was data exfiltrated, and if so, what and how much?

Yes. Seventeen files totaling approximately 85-90 MB were confirmed staged on removable media (USB rm2 and optical rm3_type3). Files included design documents, pricing materials, proposals, progress reports, and technical reviews disguised with media file extensions. Document metadata contained Executive Office of the President (OMB/EOP) and Library of Congress email addresses, indicating potential government intellectual property. Cloud exfiltration via Google Drive is highly probable based on sync activity timing, but the specific files uploaded cannot be determined due to sync database deletion. The total exfiltration scope may be larger if additional files were uploaded to cloud storage before database deletion.

Q6. What is the full timeline of the incident?

The complete timeline spans March 22-25, 2015:

  • March 22, 2015: User account created at 14:34:41 UTC. Three additional administrator accounts created between 15:51-15:53 UTC. User researches data leakage and forensic evasion topics via web browser.

  • March 23, 2015: SanDisk USB connected at 18:31:10 UTC. Source files accessed from "Authorized USB" (rm1) beginning at 18:38:21 UTC. Google Drive installed 20:02-20:05 UTC. Additional project file accessed at 20:27:33 UTC.

  • March 24, 2015: Data staging on USB rm2 at 09:59:27-10:00:18 UTC (51 seconds for 17 files). Optical media created at approximately 20:55 UTC. All 17 files disguised with media extensions.

  • March 25, 2015: Timestamp manipulation at 11:08:36 UTC. Anti-forensic tools installed 14:46-14:50 UTC. CCleaner and Eraser executed 14:57-15:15 UTC. Google Drive sync executed 15:21 UTC. Resignation letter created 15:28 UTC.

Total operational duration: 3 days from account creation to resignation.

Q7. What is the total scope and business impact?

One PC system with four administrator accounts. Seventeen known files staged on removable media, with cloud exfiltration probability high but undetermined. Document metadata indicates potential Executive Office of the President and Library of Congress involvement, suggesting possible national security implications. The insider threat actor's deliberate evidence destruction indicates consciousness of wrongdoing. Legal exposure includes potential federal crimes (theft of government property, unauthorized removal of records, evidence tampering). The correlation with resignation indicates premeditated data theft as part of an exit strategy, representing a breakdown in offboarding security controls for positions with sensitive access.

Q8. What are the recommended remediation actions?

Immediate containment actions are detailed in the Tactical Containment section above. Strategic remediation for each identified root cause includes: deploying User and Entity Behavior Analytics for insider threat detection, implementing content-aware DLP with file signature inspection rather than extension-based rules, establishing Privileged Access Management with approval workflows for administrator account creation, deploying USB device control to restrict removable media access, blocking consumer cloud storage services at the network perimeter, and implementing offboarding security protocols including proactive access revocation and enhanced monitoring. Each remediation directly addresses specific failures observed in this incident—failure to detect insider threat behavior, failure to prevent DLP circumvention through file masquerading, failure to control administrator privilege proliferation, failure to restrict removable media, failure to block unauthorized cloud storage, and failure to secure the departure process.

2014-12-01
2014-12-01T14:50:26Z — 2015-03-24T20:57:03Z
Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering
critical confirmed
optical.listing, tsk.masquerade
2015-03-22
2015-03-22T14:33:54 — 2015-03-22T15:53:11
Multiple User Accounts Created with Admin Privileges
high confirmed
hayabusa.alerts
2015-03-22T14:33:54Z — 2015-03-25T15:30:00Z
Admin Accounts Created - Minimal Use of admin11, No Evidence of Use for Others
medium confirmed
hayabusa.alerts, composite.persistence
2015-03-22T14:34:00
Intent Evidence: Web Searches About Data Leakage and Forensic Evasion
critical confirmed
bulk.url
2015-03-22T14:34:00
Cloud Storage Tools Installed (Google Drive and iCloud)
high confirmed
tsk.filelist
2015-03-22T14:34:41 — 2015-03-25T15:29:08
NIST Employee Identity Confirmed - Iaman Informant
critical confirmed
bulk.email, registry.ntuser.informant
2015-03-22T14:34:41 — 2015-03-25T11:08:36
Data Exfiltration Timeline - March 22-25, 2015
medium inference
tsk.masquerade, ez.mft, tsk.filelist, forensic.timestomping
2015-03-23
2015-03-23T18:31:10 — 2015-03-23T18:31:10
SanDisk USB Device Connected During Exfiltration Period
medium confirmed
registry.query.system
2015-03-23T18:38:21
Source Data Found on "Authorized USB" Drive (rm1)
high confirmed
tsk.filelist
2015-03-23T18:38:21 — 2015-03-23T20:27:33
Secret Project Files Accessed on PC (LNK Evidence)
high confirmed
ez.mft
2015-03-23T18:38:21
Secret Project Data on USB Device
info confirmed
tsk.filelist
2015-03-23T20:02:43
Data Exfiltration Timeline and Method
critical confirmed
ez.mft, tsk.masquerade, bulk.url
2015-03-23T20:02:43 — 2015-03-25T15:21:36
Google Drive Installation and Cloud Storage Setup
high confirmed
ez.mft, tsk.filelist
2015-03-23T20:02:43 — 2015-03-25T15:21:36
Cloud Storage Services Accessed for Potential Exfiltration
high inference
bulk.domain, registry.ntuser.informant
2015-03-23T20:02:43Z — 2015-03-25T15:21:30Z
Google Drive as Third Exfiltration Channel - Sync Activity with Database Deleted
high inference
registry.ntuser.informant, bulk.url, ez.mft, tsk.filelist
2015-03-24
2015-03-24T09:59:27 — 2015-03-24T23:59:59
US Government Email Address Found on Removable Media
critical confirmed
bulk.email, bulk.url, bulk.rfc822
2015-03-24T09:59:27 — 2015-03-24T10:00:18
Files Disguised with Wrong Extensions on Removable Media
high confirmed
tsk.masquerade
2015-03-24T09:59:27Z — 2015-03-24T23:59:59Z
US Government Email Metadata in Exfiltrated Files - OMB/EOP and Library of Congress
critical confirmed
bulk.email, bulk.url, bulk.rfc822
2015-03-25
2015-03-25T11:08:36 — 2015-03-25T11:08:36
Timestamp Manipulation Detected on PC
medium confirmed
forensic.timestomping
2015-03-25T11:08:36Z — 2015-03-25T15:29:08Z
Coordinated Anti-Forensic Cleanup Timeline - Evidence of Planned Exit Strategy
high confirmed
registry.ntuser.informant, forensic.timestomping, hayabusa.alerts
2015-03-25T14:46:05 — 2015-03-25T15:15:50
Anti-Forensic Tools Installation and Execution
high confirmed
registry.ntuser.informant
critical confirmed US Government Email Address Found on Removable Media

Government email address Eric_P._Lauer@omb.eop.gov (Office of Management and Budget, Executive Office of the President) was found on rm2 USB drive. This email appears in document metadata embedded within the exfiltrated files. Additional email addresses found include wayne.longman@att.net (personal) and mmun@loc.gov (Library of Congress).

The presence of OMB/EOP email addresses on a removable USB drive suggests potential exfiltration of US Government documents. Email addresses were extracted from file metadata by bulk_extractor and are embedded in the exfiltrated documents. The Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) and email subjects referencing historical photograph catalogs indicate Library of Congress content was also exfiltrated.

Evidence strength:
3 refs
bulk.emailbulk.urlbulk.rfc822

Evidence Chain

tc_f5ca191f get_raw_output 22ms
tc_b8b2d545 search 3ms
tc_1e991981 get_raw_output 21ms
Time: 2015-03-24T09:59:27 — 2015-03-24T23:59:59
Sources: bulk.email, bulk.url, bulk.rfc822
Evidence Refs: tc_f5ca191f, tc_b8b2d545, tc_1e991981
ATT&CK: T1567.002
critical confirmed Intent Evidence: Web Searches About Data Leakage and Forensic Evasion

Web browsing evidence reveals the suspect was actively researching data leakage methods and forensic detection before and during the exfiltration:

Data Leakage Research:
- SANS whitepaper: "data-leakage-threats-mitigation-19312"
- Google search: "information leakage cases"
- News article: "Google to settle data leakage case for $85 million"
- Article: "Top 5 sources leaking personal data" (Emirates 24/7)

Confidential Information Leakage Research:
- Google searches for "leaking confidential information" with progressive query refinement:
- "leaking confidenti"
- "leaking confidential i"
- "leaking confidential informat"
- "leaking confidential information"

Forensic Countermeasure Research:
- "Tools:Data_Recovery" page on ForensicsWiki
- Microsoft Research paper: "leak_secret.pdf"
- Search for "system cleaner"

Cloud Storage Access:
- "https://www.google.com/drive/"
- "https://www.google.com/drive/download/"

This evidence proves the suspect had intent to leak confidential information and researched methods to avoid detection. The progression of search queries shows deliberate planning, not accidental data handling. The research into forensic tools suggests awareness of potential investigation.

Evidence strength:
1 ref
bulk.url

Evidence Chain

tc_0df850f6 search 17ms
Time: 2015-03-22T14:34:00
Sources: bulk.url
Evidence Refs: tc_0df850f6
ATT&CK: T1595.002
critical confirmed Data Exfiltration Timeline and Method

Timeline of user activity demonstrates a deliberate data exfiltration sequence:

2015-03-23:
- 20:02:43 - 20:05:32 UTC: Google Drive desktop client installed and configured
- 20:05:32 UTC: Google Drive sync folder created at Users\informant\Google Drive
- 20:26:52 UTC: Excel application accessed
- 20:27:33 UTC: LNK file created for [secret_project]_final_meeting.pptx (evidence of secret project file access)
- 20:32:44 UTC: Apple iCloud software logs created (another potential cloud exfiltration channel)

2015-03-24:
- 09:59:27 - 10:00:18 UTC: 17 files disguised with media extensions created on removable media (rm2, volume "IAMAN $_@") in $OrphanFiles directory. All files marked as deleted.
- 13:21:17 - 21:07:21 UTC: Active web browsing via Chrome (multiple cache files updated throughout the day)
- Multiple Chrome cache entries for drive.google.com, docs.google.com, and mail.google.com
- Evidence of Google Drive sharing activity

2015-03-25:
- 15:21:34 - 15:21:36 UTC: Google Drive lockfile last modified (final sync activity)

The sequence shows: (1) install cloud storage tools, (2) access secret project files, (3) disguise documents as media files and copy to USB, (4) continue accessing cloud services. This methodical approach indicates deliberate preparation for data exfiltration.

Evidence strength:
5 refs
ez.mfttsk.masqueradebulk.url

Evidence Chain

tc_fc900623 parse_mft 19ms
tc_22299e09 search 10ms
tc_76e43792 get_raw_output 17ms
tc_3aad1440 search 4ms
tc_8c8e48d7 search 4ms
Time: 2015-03-23T20:02:43
Sources: ez.mft, tsk.masquerade, bulk.url
Evidence Refs: tc_fc900623, tc_22299e09, tc_76e43792, tc_3aad1440, tc_8c8e48d7
critical confirmed NIST Employee Identity Confirmed - Iaman Informant

The user "informant" has been conclusively identified as Iaman Informant, an employee of the National Institute of Standards and Technology (NIST), based on multiple corroborating evidence sources:

Email Address Evidence:
- Primary email: iaman.informant@nist.gov (found in PC email data via bulk_extractor)
- Exchange Labs identifier: 1b788828-c8a2-4681-bf6f-b1df9935415b@nist.gov
- Outlook profile: iaman.informant@nist.gov.ost

Document Evidence:
- Resignation letter: "Resignation_Letter_(Iaman_Informant).docx" (created 2015-03-25)
- Resignation letter XPS version: "Resignation_Letter_(Iaman_Informant).xps"
- Documents accessed on 2015-03-25 (last day of activity)

Government Data Theft Context:
The user's NIST employment status makes the theft of US Government documents (OMB/EOP, Library of Congress) particularly significant. As a federal employee, the user had trust and access privileges. The exfiltration of documents containing email addresses from the Office of Management and Budget (Executive Office of the President) and Library of Congress from a NIST employee's system suggests potential insider threat compromise or unauthorized transfer of government intellectual property.

Timeline Correlation:
- User created on 2015-03-22
- Active for only 4 days (March 22-25)
- Resignation letter suggests planned departure
- Data exfiltration occurred during final days of employment/tenure

Evidence strength:
2 refs
bulk.emailregistry.ntuser.informant

Evidence Chain

tc_9c5d9a2c search 56ms
tc_519d3d69 get_raw_output 53ms
Time: 2015-03-22T14:34:41 — 2015-03-25T15:29:08
Sources: bulk.email, registry.ntuser.informant
Evidence Refs: tc_9c5d9a2c, tc_519d3d69
critical confirmed Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering

The UDF write-once optical media (volume label 'IAMAN CD') contains 9 VAT (Virtual Allocation Table) sessions (generations) indicating multiple burn sessions. The disc shows evidence of directory renaming and file deletion across sessions to hide the original directory structure:

Original Directory Names (Session 7 and earlier):
- /design
- /pricing decision
- /progress
- /proposal
- /technical review

Abbreviated Directory Names (Session -1):
- /de (design)
- /pd (pricing decision)
- /prog (progress)
- /prop (proposal)
- /tr (technical review)

Currently Present Files (Session 0):
- /Koala.jpg (780,831 bytes) - Created: 2015-03-24
- /Penguins.jpg (777,835 bytes) - Created: 2015-03-24
- /Tulips.jpg (620,888 bytes) - Created: 2015-03-24

Deleted Files (Recoverable from Earlier Sessions):

Session -1 (Most recent deletions):
- /de/winter_storm.amr (14.5 MB)
- /de/winter_whether_advisory.zip (16.3 MB)
- /pd/my_favorite_cars.db (1.3 MB)
- /pd/my_favorite_movies.7z (100 KB)
- /pd/new_years_day.jpg (10.2 MB)
- /pd/super_bowl.avi (10.3 MB)
- /prog/my_friends.svg (58 KB)
- /prog/my_smartphone.png (4.4 MB)
- /prog/new_year_calendar.one (27 KB)
- /prop/a_gift_from_you.gif (35.2 MB) - LARGEST FILE
- /prop/landscape.png (6.5 MB)
- /tr/diary_#1d.txt (121 KB)
- /tr/diary_#1p.txt (458 KB)
- /tr/diary_#2d.txt (659 KB)
- /tr/diary_#2p.txt (1.2 MB)
- /tr/diary_#3d.txt (2.4 MB)
- /tr/diary_#3p.txt (325 KB)

The directory renaming and file deletion pattern across multiple sessions indicates an attempt to obscure the original document structure. The current session (0) only contains 3 image files, while earlier sessions contained 17+ files that were progressively deleted.

File modification timestamps range from December 2014 to January 2015, suggesting the original files were created over a 2-month period before being collected and burned to disc on March 24, 2015.

Merged findings:
- Mass File Masquerading on Optical Media - Systematic Data Obfuscation (f_1e67a48f, high, confirmed): 17 files on the UDF optical media (volume label 'IAMAN CD') have been systematically renamed with misleading file extensions to hide their true content type. This indicates deliberate data obfuscation consistent with data exfiltration preparation.

Key Findings:

All masqueraded files are in deleted directories from earlier VAT sessions but remain fully recoverable:

Word Documents (.docx) disguised as:
- my_smartphone.png (4.4 MB)
- new_year_calendar.one (27 KB)
- a_gift_from_you.gif (35.2 MB) - VERY LARGE
- landscape.png (6.5 MB)
- diary_#1d.txt (121 KB)
- diary_#2d.txt (659 KB)

Excel Spreadsheets (.xlsx) disguised as:
- my_favorite_movies.7z (100 KB)
- new_years_day.jpg (10.2 MB)

PowerPoint Files (.pptx) disguised as:
- winter_whether_advisory.zip (16.3 MB)
- diary_#1p.txt (458 KB)

OLE Compound Documents disguised as:
- winter_storm.amr (14.5 MB) - disguised as audio
- my_favorite_cars.db (1.3 MB) - disguised as database
- super_bowl.avi (10.3 MB) - disguised as video
- my_friends.svg (58 KB) - disguised as SVG image
- diary_#2p.txt (1.2 MB)
- diary_#3d.txt (2.4 MB)
- diary_#3p.txt (325 KB)

The naming pattern suggests business/project documents (design, pricing decision, progress, proposal, technical review) disguised to appear as personal media files. File dates range from December 2014 to January 2015, with disc creation on March 24, 2015.

This systematic obfuscation technique is commonly used to bypass DLP (Data Loss Prevention) systems and evade detection during data exfiltration.
- Cross-Media Correlation - Optical Disc Links to USB Drives and User Identity (f_90fd8093, info, confirmed): The rm3_type3 optical media volume label "IAMAN CD" correlates with the rm2 USB volume label "IAMAN $_@" and the user account name "iaman.informant@nist.gov". This naming consistency across multiple pieces of evidence (removable USB drives rm2 and rm3_type3, plus the user's NIST email identity) indicates a single actor is responsible for the data exfiltration activities.

Correlation Evidence:

  1. rm2 USB Drive: Volume label "IAMAN $_@"
  2. Contains 17 masqueraded files in $OrphanFiles
  3. Files created 2015-03-24 09:59:27-10:00:18 UTC

  4. rm3_type3 Optical Media: Volume label "IAMAN CD"

  5. Contains same 17 masqueraded files (deleted from earlier sessions)
  6. Shows evidence of multi-session data tampering
  7. Files dating from December 2014 to January 2015

  8. User Identity: iaman.informant@nist.gov

  9. NIST employee email address
  10. User account "informant" on PC

Significance:

The consistent "IAMAN" naming convention suggests the optical media (rm3_type3) was created by the same actor who prepared the USB drives. The optical media represents a redundant or fallback copy of the exfiltrated data, created using write-once UDF format which makes deletion attempts recoverable via VAT session analysis.

The correlation establishes that the same insider threat actor created multiple copies of the stolen data across different media types (USB flash drives and optical disc), indicating sophisticated data exfiltration planning and execution.
- Multi-Stage Data Exfiltration - USB and Optical Media Created 11 Hours Apart (f_d26a6832, critical, confirmed): Cross-system correlation of file creation timestamps reveals deliberate multi-stage exfiltration with redundant backup channels:

Stage 1 - USB Drive (rm2):
- 17 obfuscated files created on 2015-03-24 09:59:27-10:00:18 UTC
- Duration: 51 seconds for all files (rapid batch copy operation)
- Volume label: "IAMAN $_@"
- Files disguised with media extensions (.jpg, .png, .gif, .avi, .amr, .zip, .7z, .db, .txt)

Stage 2 - Optical Media (rm3_type3):
- Same 17 obfuscated files created on 2015-03-24 20:55:43 UTC
- ~11 hours AFTER USB creation (evening vs. morning)
- Volume label: "IAMAN CD"
- UDF write-once format with 9 VAT sessions
- Files progressively deleted across sessions (multi-session tampering)

Timeline Significance:
- Multi-stage approach indicates sophisticated planning
- Optical media created as redundant backup or alternative exfiltration channel
- ~11-hour gap suggests separate operational phases
- Same actor created both media (consistent "IAMAN" naming and identical file sets)

Data Flow:
rm1 ("Authorized USB", source files) → PC (processing/obfuscation) → rm2 (USB, morning) AND rm3_type3 (optical, evening)

The separate staging events demonstrate the actor's intent to create multiple copies of stolen data across different media types, ensuring data survivability and providing fallback exfiltration options.

Affected Systems: optical.listing, tsk.masquerade

Evidence strength:
3 refs
optical.listingtsk.masquerade

Evidence Chain

tc_0602a3ae search 4ms
tc_6b481885 get_raw_output 53ms
tc_73fc34c7 get_raw_output 56ms
Time: 2014-12-01T14:50:26Z — 2015-03-24T20:57:03Z
Sources: optical.listing, tsk.masquerade
Evidence Refs: tc_0602a3ae, tc_6b481885, tc_73fc34c7
critical confirmed US Government Email Metadata in Exfiltrated Files - OMB/EOP and Library of Congress

US Government email addresses embedded in the metadata of exfiltrated documents indicate the stolen files contain or originated from sensitive US Government sources:

Government Email Addresses Found:

1. Eric_P._Lauer@omb.eop.gov
- Organization: Office of Management and Budget (OMB)
- Parent: Executive Office of the President (EOP)
- Context: Office of the President of the United States
- Source: Document metadata embedded within exfiltrated files

2. mmun@loc.gov
- Organization: Library of Congress (LOC)
- Context: Legislative branch digital content
- Related URLs: hdl.loc.gov/loc.pnp/acd.2a10339 (Library of Congress digital handle)
- Source: Email metadata and document properties

3. Wayne.Longman@att.net
- Personal email (AT&T domain)
- Source: Document metadata

Relationship to Secret Project Files:
- The government email addresses were embedded in the document properties/metadata of the exfiltrated files
- This indicates the documents were either:
a) Created by government employees and shared with the suspect
b) Received from government sources via email
c) Part of official government project documentation

Document Content Evidence:
- Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) in document content
- Email subjects referencing Library of Congress historical photograph catalogs
- Presence of OMB/EOP metadata in documents labeled as "Secret Project Data"

Significance:
1. Insider Threat Context: A NIST employee (iaman.informant@nist.gov) exfiltrating documents containing OMB/EOP and Library of Congress email metadata suggests unauthorized transfer of government intellectual property across federal agencies

  1. Classification Level: Documents with Executive Office of the President metadata marked as "Secret Project Data" indicates potential classified or sensitive unclassified information

  2. Attribution: The email addresses prove the documents originated from or passed through US Government systems before being stolen

  3. Legal Implications: Unauthorized removal of documents containing Executive Office of the President and Library of Congress metadata constitutes potential federal crimes (theft of government property, unauthorized removal of records)

The exfiltration of documents with US Government email addresses from a NIST employee's system to personal removable media and cloud storage represents a significant insider threat incident with potential national security implications.

Evidence strength:
1 ref
bulk.emailbulk.urlbulk.rfc822

Evidence Chain

tc_01f8154d get_ioc_summary 604ms
Time: 2015-03-24T09:59:27Z — 2015-03-24T23:59:59Z
Sources: bulk.email, bulk.url, bulk.rfc822
Evidence Refs: tc_01f8154d
high confirmed Files Disguised with Wrong Extensions on Removable Media

Seventeen files with deceptive file extensions were created on removable media (rm2, volume label "IAMAN $_@") on 2015-03-24 between 09:59:27 UTC and 10:00:18 UTC. All files are marked as deleted ($OrphanFiles). The files have media file extensions (.amr, .zip, .db, .7z, .jpg, .avi, .svg, .png, .one, .gif, .txt) but their actual file signatures indicate they are Microsoft Office documents (DOCX, XLSX, PPTX) or OLE compound files.

Files include:
- winter_storm.amr → OLE (14.5 MB)
- winter_whether_advisory.zip → PPTX (16.4 MB)
- my_favorite_cars.db → OLE (1.2 MB)
- my_favorite_movies.7z → XLSX (100 KB)
- new_years_day.jpg → XLSX (10.2 MB)
- super_bowl.avi → OLE (10.3 MB)
- a_gift_from_you.gif → DOCX (35.2 MB)
- diary_#1d.txt, diary_#2d.txt, diary_#3d.txt → DOCX/OLE
- diary_#1p.txt → PPTX
- diary_#2p.txt, diary_#3p.txt → OLE
- my_smartphone.png, new_year_calendar.one, landscape.png → DOCX

The files are organized in folders named: design, PRICIN~1 (Pricing?), progress, proposal, and TECHNI~1 (Technical?). This naming suggests corporate/business documents. The use of media file extensions to disguise documents is a clear indicator of data concealment for exfiltration.

Merged findings:
- Documents Renamed to Hide Contents on USB Drive (f_209cd841, high, confirmed): 17 files on rm2 USB drive exhibit extension/content mismatches, indicating deliberate obfuscation of Office documents. Files were renamed with media and archive file extensions to disguise their true content:

  1. winter_storm.amr → OLE format (14.5 MB)
  2. winter_whether_advisory.zip → PowerPoint (16.4 MB)
  3. my_favorite_cars.db → OLE format (1.3 MB)
  4. my_favorite_movies.7z → Excel (100 KB)
  5. new_years_day.jpg → Excel (10.2 MB)
  6. super_bowl.avi → OLE format (10.3 MB)
  7. my_friends.svg → OLE format (58 KB)
  8. my_smartphone.png → Word (4.4 MB)
  9. new_year_calendar.one → Word (27 KB)
  10. a_gift_from_you.gif → Word (35.2 MB)
  11. landscape.png → Word (6.5 MB)
  12. diary_#1d.txt → Word (121 KB)
  13. diary_#1p.txt → PowerPoint (458 KB)
  14. diary_#2d.txt → Word (659 KB)
  15. diary_#2p.txt → OLE format (1.2 MB)
  16. diary_#3d.txt → OLE format (2.4 MB)
  17. diary_#3p.txt → OLE format (325 KB)

All files are deleted and located in $OrphanFiles directories, indicating they were removed after being copied to the drive. This is consistent with data staging for exfiltration and anti-forensic cleanup.

Affected Systems: tsk.masquerade

Evidence strength:
2 refs
tsk.masquerade

Evidence Chain

tc_62a7b95b get_raw_output 91ms
tc_76e43792 get_raw_output 17ms
Time: 2015-03-24T09:59:27 — 2015-03-24T10:00:18
Sources: tsk.masquerade
Evidence Refs: tc_62a7b95b, tc_76e43792
ATT&CK: T1564.001
high confirmed Source Data Found on "Authorized USB" Drive (rm1)

USB drive rm1 with volume label "Authorized USB" contains the original source files that were subsequently obfuscated and exfiltrated to rm2. The drive contains a "Secret Project Data" directory with organized project materials:

Design folder:
- [secret_project]_design_concept.ppt
- [secret_project]_detailed_design.pptx
- [secret_project]_revised_points.ppt

Proposal folder:
- [secret_project]_detailed_proposal.docx
- [secret_project]_proposal.docx
- ~$ecret_project]_proposal.docx (Word temporary file, deleted)

The presence of a Word temporary file (~$ecret_project]_proposal.docx) indicates the proposal document was opened/edited on this drive. A duplicate directory structure exists under "RM#1/Secret Project Data/".

These are the source documents that were renamed with media file extensions and placed on rm2 for exfiltration. The naming convention "[secret_project]" indicates sensitive project materials were targeted for theft.

Evidence strength:
1 ref
tsk.filelist

Evidence Chain

tc_07fa12ee get_raw_output 3ms
Time: 2015-03-23T18:38:21
Sources: tsk.filelist
Evidence Refs: tc_07fa12ee
high confirmed Google Drive Installation and Cloud Storage Setup

Google Drive client software was installed on the PC and configured for user "informant" on 2015-03-23 between 20:02:43-20:05:32 UTC. Evidence includes:

  1. Google Drive program files in Program Files (x86)\Google\Drive\ with language modules (installed 2015-02-19 and 2015-03-23)
  2. User data directory: Users\informant\AppData\Local\Google\Drive\user_default\ containing:
  3. sync_config.db, snapshot.db (deleted, track synced files)
  4. lockfile (last modified 2015-03-25 15:21:34, indicating active sync)
  5. com.google.drive.nativeproxy.json
  6. Sync folder: Users\informant\Google Drive\desktop.ini (created 2015-03-23 20:05:32, modified 2015-03-25 15:21:36)
  7. Downloaded installer: Users\informant\Downloads\googledrivesync.exe

The timing (installed one day before files were disguised on removable media on 2015-03-24) and the presence of sync databases suggest Google Drive was set up as a potential exfiltration channel. The lockfile modification on 2015-03-25 indicates Google Drive was actively syncing data until the investigation period.

Evidence strength:
2 refs
ez.mfttsk.filelist

Evidence Chain

tc_3aad1440 search 4ms
tc_221952ae search 5ms
Time: 2015-03-23T20:02:43 — 2015-03-25T15:21:36
Sources: ez.mft, tsk.filelist
Evidence Refs: tc_3aad1440, tc_221952ae
high confirmed Secret Project Files Accessed on PC (LNK Evidence)

Windows Recent Documents LNK files on the PC prove that the user "informant" accessed secret project files directly from removable media:

March 23, 2015 18:38:21 UTC - [secret_project]_design_concept.lnk
- Path: Users\informant\AppData\Roaming\Microsoft\Windows\Recent\
- This LNK file was created when the PowerPoint presentation was opened from the "Authorized USB" drive (rm1)

March 23, 2015 20:27:33 UTC - [secret_project]_final_meeting.pptx.lnk
- Path: Users\informant\AppData\Roaming\Microsoft\Windows\Recent\
- A second project file was opened approximately 2 hours later

The presence of these LNK files confirms that secret project files were accessed on the PC. The [secret_project]_design_concept.lnk corresponds to the file [secret_project]_design_concept.ppt found on rm1. Notably, [secret_project]_final_meeting.pptx is not present on rm1, suggesting additional project files may have existed or were deleted.

This establishes March 23 as the date of file access, with exfiltration occurring the following day (March 24) when obfuscated copies were created on rm2.

Merged findings:
- Access to Secret Project Files (f_8a9f7eba, high, confirmed): A Windows LNK (shortcut) file was created in the user's Recent documents folder on 2015-03-23 at 20:27:33 UTC pointing to a file named "[secret_project]_final_meeting.pptx". This LNK file at "Users\informant\AppData\Roaming\Microsoft\Windows\Recent[secret_project]_final_meeting.pptx.lnk" confirms the user accessed and opened a PowerPoint presentation related to the secret project.

This access occurred on the same day Google Drive was installed (2015-03-23) and one day before files were disguised and copied to removable media (2015-03-24), establishing a clear timeline of data access followed by exfiltration preparation.

Affected Systems: ez.mft

Evidence strength:
2 refs
ez.mft

Evidence Chain

tc_d3a42665 search 3ms
tc_fc900623 parse_mft 19ms
Time: 2015-03-23T18:38:21 — 2015-03-23T20:27:33
Sources: ez.mft
Evidence Refs: tc_d3a42665, tc_fc900623
ATT&CK: T1074.001
high confirmed Cloud Storage Tools Installed (Google Drive and iCloud)

Cloud storage and synchronization tools were downloaded and installed, potentially for data exfiltration:

Google Drive:
- Client installed: Program Files (x86)\Google\Drive\
- Sync configuration: Users\informant\AppData\Local\Google\Drive\user_default\sync_config.db-shm (deleted)
- Snapshot database: Users\informant\AppData\Local\Google\Drive\user_default\snapshot.db (deleted)
- Certificate store: Users\informant\AppData\Local\Google\Drive\user_default\cacerts (deleted)

iCloud:
- Installer downloaded: Users\informant\Downloads\icloudsetup.exe
- Zone.Identifier present (downloaded from internet)

Google Drive Sync:
- Installer downloaded: Users\informant\Downloads\googledrivesync.exe
- Zone.Identifier present (downloaded from internet)

The presence of sync databases and their deletion suggests the suspect may have synchronized files to cloud storage and then attempted to remove evidence of the synchronization. The deleted status of Google Drive database files indicates anti-forensic cleanup.

Evidence strength:
1 ref
tsk.filelist

Evidence Chain

tc_a0e68801 search 6ms
Time: 2015-03-22T14:34:00
Sources: tsk.filelist
Evidence Refs: tc_a0e68801
ATT&CK: T1567.002
high confirmed Anti-Forensic Tools Installation and Execution

Anti-forensic tools CCleaner and Eraser were downloaded, installed, and executed on 2015-03-25 after the data exfiltration events, indicating consciousness of guilt and attempted evidence destruction:

Installation Timeline (2015-03-25):
- 14:46:05 UTC - ccsetup504.exe (CCleaner installer) downloaded from Users\informant\Desktop\Download\
- 14:50:14 UTC - Eraser 6.2.0.2962.exe downloaded from Users\informant\Desktop\Download\
- 14:57:56 UTC - CCleaner installer executed (UserAssist entry)
- 15:12:28 UTC - Eraser executed (UserAssist entry)
- 15:15:50 UTC - CCleaner executed (UserAssist entry)

Significance:
- Tools were installed AFTER the data exfiltration on 2015-03-24
- Eraser is designed for secure file deletion beyond forensic recovery
- CCleaner cleans browser history, registry, temporary files, and system traces
- Execution on the same day as the resignation letter suggests intentional cleanup
- This constitutes evidence tampering and obstruction of justice

The installation and execution of these tools immediately following data exfiltration demonstrates the user's intent to destroy evidence of their activities.

Evidence strength:
1 ref
registry.ntuser.informant

Evidence Chain

tc_519d3d69 get_raw_output 53ms
Time: 2015-03-25T14:46:05 — 2015-03-25T15:15:50
Sources: registry.ntuser.informant
Evidence Refs: tc_519d3d69
high confirmed Multiple User Accounts Created with Admin Privileges

User "informant" created three additional user accounts and granted them local administrator privileges on 2015-03-22, shortly after the "informant" account was created:

Account Creation Timeline:
1. 2015-03-22 14:33:54 - "informant" account added to Administrators group (by SYSTEM)
2. 2015-03-22 15:51:54 - "admin11" added to Administrators group by "informant"
3. 2015-03-22 15:52:10 - Password reset for "admin11" by "informant"
4. 2015-03-22 15:52:30 - "ITechTeam" added to Administrators group by "informant"
5. 2015-03-22 15:52:45 - Password reset for "ITechTeam" by "informant"
6. 2015-03-22 15:53:11 - Password reset for "temporary" by "informant"

Evidence from Security Event Logs (Hayabusa):
- Event ID 4732 (Member Added to Local Group) - Multiple instances
- Event ID 4724 (Password Reset By Admin) - Multiple instances
- All actions performed from SubjectLogonId: 0x224e3 (informant session)

User Accounts Involved:
- admin11 (SID: S-1-5-21-...-1001) - Administrator account with Chrome data
- ITechTeam (SID: S-1-5-21-...-1002) - Administrator account
- temporary (SID: S-1-5-21-...-1003) - Administrator account

Significance:
The creation of multiple admin accounts could indicate:
1. Preparation for lateral movement - Alternative credentials for evasion
2. Plausible deniability - Activity attribution to different accounts
3. Backdoor access - Maintaining access if primary account is disabled
4. Testing environment setup - Creating isolated contexts for exfiltration activities

All accounts have NTUSER.DAT registry hives extracted, confirming they were actively used profiles on this system.

Evidence strength:
1 ref
hayabusa.alerts

Evidence Chain

tc_a8ac9125 get_raw_output 53ms
Time: 2015-03-22T14:33:54 — 2015-03-22T15:53:11
Sources: hayabusa.alerts
Evidence Refs: tc_a8ac9125
high inference Cloud Storage Services Accessed for Potential Exfiltration

Evidence from bulk_extractor domain analysis reveals access to multiple cloud storage platforms, with Google Drive actively configured for synchronization:

Cloud Storage Platforms Detected:
1. Google Drive (Primary exfiltration channel)
- drive.google.com
- docs.google.com
- Client installed: googledrivesync.exe (installed 2015-03-23)
- Sync databases: sync_config.db, snapshot.db (deleted)
- Active sync lockfile modified: 2015-03-25 15:21:34 UTC

  1. Microsoft OneDrive
  2. onedrive.live.com
  3. www.onedrive.com
  4. Accessed but no sync client installation detected

Google Drive Configuration Evidence:
- User data directory: Users\informant\AppData\Local\Google\Drive\user_default\
- Sync folder: Users\informant\Google Drive\
- desktop.ini created: 2015-03-23 20:05:32
- desktop.ini modified: 2015-03-25 15:21:36 (active during exfiltration window)
- Language modules and update components present

Data Transfer Indicators:
- The presence of snapshot.db indicates files were synced to cloud
- Lockfile indicates active Google Drive process
- Deleted sync databases (sync_config.db, snapshot.db) suggest cleanup attempts
- Timing coincides with USB data staging activities

Exfiltration Method:
The user likely used Google Drive to upload sensitive documents to a personal or external Google account, providing an alternative or additional exfiltration channel to the USB devices. The deleted sync databases are consistent with attempting to hide evidence of what files were uploaded to the cloud.

Evidence strength:
2 refs
bulk.domainregistry.ntuser.informant

Evidence Chain

tc_fd9a82be search 5ms
tc_519d3d69 get_raw_output 53ms
Time: 2015-03-23T20:02:43 — 2015-03-25T15:21:36
Sources: bulk.domain, registry.ntuser.informant
Evidence Refs: tc_fd9a82be, tc_519d3d69
high inference Google Drive as Third Exfiltration Channel - Sync Activity with Database Deleted

Google Drive was used as a third exfiltration channel beyond USB and optical media, with evidence of active synchronization followed by database deletion to hide traces:

Google Drive Installation and Configuration:
- Installed: 2015-03-23 20:02:43-20:05:32 UTC (one day before data staging)
- Sync folder created: Users\informant\Google Drive\desktop.ini (2015-03-23 20:05:32)
- Sync databases: sync_config.db, snapshot.db (BOTH DELETED)

Evidence of Active Sync:
1. UserAssist Execution: googledrivesync.exe executed on 2015-03-25 15:21:30Z
2. Lockfile Activity: Google Drive lockfile last modified 2015-03-25 15:21:34 UTC
3. Desktop.ini Modification: Google Drive folder modified 2015-03-25 15:21:36 UTC

Anti-Forensic Cleanup:
- sync_config.db (track synced files) - DELETED
- snapshot.db (record of synced files) - DELETED
- cacerts - DELETED
- Database deletion indicates intentional removal of sync history

Timeline Context:
- 14:57:56Z - CCleaner executed (1st run)
- 15:12:28Z - Eraser executed
- 15:15:50Z - CCleaner executed (2nd run)
- 15:21:30Z - Google Drive sync executed ← AFTER cleanup tools
- 15:28:33Z - Resignation letter created

Web Interface Evidence:
- drive.google.com and docs.google.com URLs in browser cache
- File sharing interface URLs: drive.google.com/sharing/share
- OAuth authentication scopes: www.googleapis.com/auth/drive.apps

Significance:
The installation timing (day before staging), active sync indicators, and subsequent database deletion strongly suggest Google Drive was used to upload exfiltrated files to a personal or external Google account. The deleted databases prevent forensic determination of which specific files were synced, but the timing and behavior are consistent with cloud-based exfiltration as an alternative to physical media transfer.

Exfiltration Channels Identified:
1. USB Drive (rm2) - Physical media
2. Optical Media (rm3_type3) - Physical media
3. Google Drive - Cloud exfiltration (EVIDENCE OF USE, CONTENT UNKNOWN)

Evidence strength:
4 refs
registry.ntuser.informantbulk.urlez.mfttsk.filelist

Evidence Chain

tc_953117d0 get_raw_output 8ms
tc_591eaf00 search 7ms
tc_3aad1440 search 4ms
tc_221952ae search 5ms
Time: 2015-03-23T20:02:43Z — 2015-03-25T15:21:30Z
Sources: registry.ntuser.informant, bulk.url, ez.mft, tsk.filelist
Evidence Refs: tc_953117d0, tc_591eaf00, tc_3aad1440, tc_221952ae
ATT&CK: T1567.002
high confirmed Coordinated Anti-Forensic Cleanup Timeline - Evidence of Planned Exit Strategy

A coordinated anti-forensic cleanup operation was executed on 2015-03-25, the same day as the resignation letter creation, indicating this was part of a planned exit strategy:

Cleanup Timeline (2015-03-25):

Phase 1 - Timestamp Manipulation (11:08:36 UTC)
- Root directory $STANDARD_INFORMATION timestamp backdated to 2009-07-14 (Windows installation date)
- Timestomping technique used to hide recent filesystem activity
- 2080 days discrepancy between SI and FN timestamps

Phase 2 - Tool Installation (14:46:05-14:50:14 UTC)
- 14:46:05Z - ccsetup504.exe executed (CCleaner installer)
- 14:50:14Z - Eraser 6.2.0.2962.exe executed (Eraser installer)

Phase 3 - Anti-Forensic Tool Execution (14:57:56-15:15:50 UTC)
- 14:57:56Z - CCleaner64.exe executed (1st run)
- 15:12:28Z - Eraser.exe executed (secure file deletion)
- 15:15:50Z - CCleaner64.exe executed (2nd run)

Phase 4 - Cloud Sync (15:21:30-15:21:36 UTC)
- 15:21:30Z - googledrivesync.exe executed
- 15:21:34Z - Google Drive lockfile modified
- 15:21:36Z - Google Drive folder updated

Phase 5 - Resignation Letter (15:28:33-15:29:08 UTC)
- 15:28:33Z - Resignation_Letter_(Iaman_Informant).xps created
- 15:29:08Z - Resignation_Letter_(Iaman_Informant).docx last accessed

Cleanup Targets:
- CCleaner: Browser history, temporary files, registry entries, system traces
- Eraser: Secure file deletion beyond forensic recovery
- Timestomping: Hide filesystem modification times
- Google Drive database deletion: Remove sync history evidence

Trigger Analysis:
The cleanup timing coincides with the resignation letter creation, indicating the anti-forensic measures were triggered by the planned departure/resignation event. The sequence (cleanup tools → cloud sync → resignation letter) suggests:
1. Clean local evidence
2. Sync final data to cloud
3. Submit resignation document

This coordinated timeline demonstrates consciousness of guilt and premeditated evidence destruction aligned with employment termination.

Evidence strength:
3 refs
registry.ntuser.informantforensic.timestompinghayabusa.alerts

Evidence Chain

tc_953117d0 get_raw_output 8ms
tc_23aef311 get_raw_output 54ms
tc_5313802f get_raw_output 54ms
Time: 2015-03-25T11:08:36Z — 2015-03-25T15:29:08Z
Sources: registry.ntuser.informant, forensic.timestomping, hayabusa.alerts
Evidence Refs: tc_953117d0, tc_23aef311, tc_5313802f
medium confirmed Timestamp Manipulation Detected on PC

Timestomping detected on the PC system. One file exhibits evidence of timestamp manipulation where the $STANDARD_INFORMATION Created timestamp (2009-07-14 02:38:56) is significantly earlier than the $FILE_NAME Created timestamp (2015-03-25 11:08:36) by 2080 days (~5.7 years).

This technique is commonly used to make files appear older than they actually are, potentially to hide recent creation time and blend in with legitimate system files, or to establish a false timeline. The file path showing timestomping is the root directory ".", indicating potential manipulation of filesystem metadata at the root level.

Evidence strength:
1 ref
forensic.timestomping

Evidence Chain

tc_1e77a73c get_raw_output 16ms
Time: 2015-03-25T11:08:36 — 2015-03-25T11:08:36
Sources: forensic.timestomping
Evidence Refs: tc_1e77a73c
ATT&CK: T1070.006
medium inference Data Exfiltration Timeline - March 22-25, 2015

Forensic timeline of data exfiltration activity reconstructed from file system evidence:

Phase 1 - Initial Setup (March 22, 2015):
- User profile "informant" created on PC at 14:34:41 UTC
- Email client (Windows Mail) and browser (Chrome) configured

Phase 2 - Source File Access (March 23, 2015):
- 18:38:21 - Opened [secret_project]_design_concept.ppt from rm1 USB drive
- 20:27:33 - Opened [secret_project]_final_meeting.pptx
- User accessed multiple secret project files from "Authorized USB" drive

Phase 3 - Data Staging and Obfuscation (March 24, 2015):
- 09:59:27 - First obfuscated file created on rm2 USB drive
- 09:59:27-10:00:18 - All 17 masqueraded files created on rm2 in ~51 seconds
- Files renamed: Office documents → media/archive extensions (.jpg, .png, .gif, .avi, .amr, .zip, .7z, .db, .txt)
- All files placed in $OrphanFiles as deleted entries

Phase 4 - Cleanup (March 25, 2015):
- 11:08:36 - Timestamp manipulation detected on PC root directory
- Government email metadata present in exfiltrated files

Total Duration: 3 days from profile creation to exfiltration completion.

Data Flow: rm1 ("Authorized USB") → PC → rm2 ("IAMAN $_@")

Exfiltrated Content: Secret Project Data including design concepts, detailed designs, and proposals containing US Government email addresses (OMB/EOP).

Evidence strength:
4 refs
tsk.masqueradeez.mfttsk.filelistforensic.timestomping

Evidence Chain

tc_62a7b95b get_raw_output 91ms
tc_d3a42665 search 3ms
tc_07fa12ee get_raw_output 3ms
tc_1e77a73c get_raw_output 16ms
Time: 2015-03-22T14:34:41 — 2015-03-25T11:08:36
Sources: tsk.masquerade, ez.mft, tsk.filelist, forensic.timestomping
Evidence Refs: tc_62a7b95b, tc_d3a42665, tc_07fa12ee, tc_1e77a73c
medium confirmed SanDisk USB Device Connected During Exfiltration Period

A SanDisk Cruzer Fit USB device was connected to the PC on 2015-03-23 at 18:31:10 UTC, as recorded in the Windows registry USBSTOR key. This timing correlates with:

  1. Same day as source file access: User opened [secret_project]_design_concept.ppt at 18:38:21 (7 minutes after USB connection)
  2. Same day as Google Drive installation: Google Drive installed on 2015-03-23
  3. One day before data obfuscation: Files disguised on rm2 USB on 2015-03-24

Registry Evidence:
- Key: ControlSet001\Enum\USBSTOR\Disk&Ven_SanDisk&Prod_Cruzer_Fit&Rev_2.01
- Last Written: 2015-03-23T18:31:10.573006

This USB device connection is the physical link between the source data (rm1 "Authorized USB") and the staging/obfuscation activities observed on the rm2 device. The timing establishes the user's physical access to removable storage during the critical period of data theft preparation.

Evidence strength:
1 ref
registry.query.system

Evidence Chain

tc_f9a1618b query_registry_value 4410ms
Time: 2015-03-23T18:31:10 — 2015-03-23T18:31:10
Sources: registry.query.system
Evidence Refs: tc_f9a1618b
medium confirmed Admin Accounts Created - Minimal Use of admin11, No Evidence of Use for Others

The user "informant" created three additional administrator accounts on 2015-03-22. While security event logs show no 4624 (successful logon) events for these accounts, forensic analysis reveals the admin11 account was used at least once:

Account Creation Timeline (2015-03-22):
- 14:33:54 - "informant" added to Administrators group (by SYSTEM)
- 15:51:54 - "admin11" added to Administrators group by "informant"
- 15:52:10 - Password reset for "admin11" by "informant"
- 15:52:30 - "ITechTeam" added to Administrators group by "informant"
- 15:52:45 - Password reset for "ITechTeam" by "informant"
- 15:53:11 - Password reset for "temporary" by "informant"

Evidence of admin11 Account Use:
- 2015-03-22 15:57:30Z: NOTEPAD.EXE executed from admin11 UserAssist registry
- This proves the admin11 account was logged into and used interactively, despite absence of 4624 events in security logs
- The missing 4624 events may indicate audit policy gaps or log clearing

Login Evidence for Other Accounts:
- ITechTeam: No UserAssist or execution evidence found
- temporary: No UserAssist or execution evidence found

Revised Assessment:
The admin11 account was used at least once (Notepad execution), which undermines the theory that all three accounts were created solely as unused backdoors. However, the ITechTeam and temporary accounts show no evidence of use. The purpose of admin11's limited use (running Notepad ~4 minutes after the last password reset) is unclear - it could be:
1. A test to verify the account worked
2. Legitimate use
3. An attempt to obscure the account's true purpose (backdoor)

The creation of multiple admin accounts with at least minimal use of one account still suggests preparation for potential alternative access pathways.

Evidence strength:
2 refs
hayabusa.alertscomposite.persistence

Evidence Chain

tc_5313802f get_raw_output 54ms
tc_30ac62fc search 8ms
Time: 2015-03-22T14:33:54Z — 2015-03-25T15:30:00Z
Sources: hayabusa.alerts, composite.persistence
Evidence Refs: tc_5313802f, tc_30ac62fc
ATT&CK: T1136.001, T1098
info confirmed Secret Project Data on USB Device

A USB device (rm1) with volume label "Authorized USB" contains a directory structure named "Secret Project Data" with subdirectories including "Secret Project Data/design/" containing project files. The files were accessed starting 2015-03-23 18:38:21 UTC when the user opened [secret_project]_design_concept.ppt from this drive.

Directory Structure Found:
- Secret Project Data/design/ - Design documents (PPT, PPTX files)
- Secret Project Data/proposal/ - Proposal documents (DOCX files)
- Secret Project Data/pricing/ - Pricing documents (XLSX files)
- RM#1/Secret Project Data/ - Duplicate directory structure

Files Identified:
- [secret_project]_design_concept.ppt (accessed 2015-03-23 18:38:21)
- [secret_project]_detailed_design.pptx
- [secret_project]_revised_points.ppt
- [secret_project]_detailed_proposal.docx
- [secret_project]_proposal.docx (with temporary file ~$ecret_project]_proposal.docx, indicating it was opened/edited)
- (secret_project)_pricing_decision.xlsx

Significance:
The volume label "Authorized USB" may be an attempt to legitimize the device or could indicate it was provided as part of authorized work. However, the combination with disguised files on rm2 and Google Drive installation suggests the data was being exfiltrated. The presence of a Word temporary file indicates the proposal document was edited on this drive.

These source documents were subsequently renamed with media file extensions and placed on rm2 for exfiltration. The naming convention "[secret_project]" indicates sensitive project materials were targeted for theft.

Evidence strength:
1 ref
tsk.filelist

Evidence Chain

tc_33a31851 search 3ms
Time: 2015-03-23T18:38:21
Sources: tsk.filelist
Evidence Refs: tc_33a31851
info confirmed Google Drive Web Interface and File Sharing URLs

The user accessed Google Drive via web browser in addition to the desktop client. Bulk_extractor found URLs including:

  1. https://drive.google.com/ (main Drive interface)
  2. https://docs.google.com/ (Google Docs interface)
  3. https://drive.google.com/sharing/share?subapp=10&shareProtocolVersion=2&theme=2&command=settings&shareUiType=default&authuser=0&client=desktop (file sharing interface)
  4. https://www.googleapis.com/auth/drive.apps and https://www.googleapis.com/auth/drive.apps.readonly (Google Drive API authentication scopes)

The sharing URL is particularly significant - it shows the user was actively configuring or using Google Drive's file sharing functionality. Combined with the Google Drive desktop client installation, this demonstrates the user had multiple pathways for data exfiltration via cloud storage.

The presence of mail.google.com URLs also indicates Gmail usage, which could have been another exfiltration channel.

Evidence strength:
3 refs
bulk.url

Evidence Chain

tc_8c8e48d7 search 4ms
tc_34ce987b search 4ms
tc_056038b2 search 4ms
Sources: bulk.url
Evidence Refs: tc_8c8e48d7, tc_34ce987b, tc_056038b2
0
Techniques
0
Tactics
0
Findings Mapped
Reconnaissance1
Resource Development
Initial Access
Execution
Persistence2
Privilege Escalation1
Defense Evasion6
Credential Access
Discovery
Lateral Movement
Collection1
Command and Control
Exfiltration2
Impact
Inhibit Response Function
Evasion
Impair Process Control
Reconnaissance
Vulnerability Scanning
1F
Persistence
Account Manipulation
1F
Local Account
1F
Privilege Escalation
Account Manipulation
1F
Defense Evasion
Masquerading
1F
File Deletion
1F
Timestomp
3F
Disable or Modify Tools
1F
Hidden Files and Directories
2F
NTFS File Attributes
1F
Collection
Local Data Staging
4F
Exfiltration
Exfiltration Over Web Service
1F
Exfiltration to Cloud Storage
5F
0
Total IOCs
0
External IPs
0
File IOCs
0
Emails
Email IOCs (5)
TypeValueEnrichmentContextActions
Email eric_p._lauer@omb.eop.gov US Government Email Address Found on Removable Media
Email wayne.longman@att.net US Government Email Address Found on Removable Media
Email mmun@loc.gov US Government Email Address Found on Removable Media
Email iaman.informant@nist.gov NIST Employee Identity Confirmed - Iaman Informant
Email 1b788828-c8a2-4681-bf6f-b1df9935415b@nist.gov NIST Employee Identity Confirmed - Iaman Informant
Select a source
Select a source from the tree to view raw evidence output.
Source Name Extractor Lines Hash Referenced By
tsk.partitions sleuthkit 9 blake2b:83c0b87c...
tsk.filelist sleuthkit 51 blake2b:55fc9962... 6 findings
tsk.masquerade sleuthkit 17 blake2b:97440a18... 4 findings
tsk.partitions sleuthkit 8 blake2b:3eed10c8...
tsk.partitions sleuthkit 10 blake2b:67b9085f...
bulk.bulk_extractor bulk_extractor 1 blake2b:3d44b8c0...
bulk.domain bulk_extractor 264 blake2b:c8b97b94... 1 finding
bulk.duplicates bulk_extractor 9 blake2b:9ba9de0c...
bulk.email bulk_extractor 43 blake2b:eb085c00... 3 findings
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9... 2 findings
bulk.url bulk_extractor 288 blake2b:d727c498... 6 findings
bulk.url_services bulk_extractor 19 blake2b:01e609ea... 6 findings
ez.mft eztools 98918 blake2b:e31e3377... 5 findings
tsk.filelist sleuthkit 104709 blake2b:171e0914... 6 findings
tsk.filelist.p1 sleuthkit 93 blake2b:5bdfadd3... 6 findings
tsk.filelist sleuthkit 27 blake2b:ae86d6dd... 6 findings
tsk.masquerade sleuthkit 0 blake2b:empty... 4 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:436e8d26...
bulk.domain bulk_extractor 189 blake2b:ae916b75... 1 finding
bulk.duplicates bulk_extractor 9 blake2b:bb406faf...
bulk.exif bulk_extractor 20 blake2b:d7c9e32a...
bulk.url bulk_extractor 207 blake2b:039de0b6... 6 findings
bulk.url_services bulk_extractor 14 blake2b:2eac1377... 6 findings
bulk.wordlist bulk_extractor 131102 blake2b:9d096226...
bulk.wordlist_dedup_1 bulk_extractor 112437 blake2b:afb1c64a...
tsk.masquerade sleuthkit 3 blake2b:42bb5e7d... 4 findings
forensic.timestomping timestomp_detector 1 blake2b:a8aad413... 3 findings
composite.file_staging composite 578 blake2b:2f05fb41...
bulk.bulk_extractor bulk_extractor 1 blake2b:904f0355...
bulk.domain bulk_extractor 403827 blake2b:d56fb4e6... 1 finding
bulk.duplicates bulk_extractor 6623 blake2b:e799fb84...
bulk.email bulk_extractor 6881 blake2b:bac35c8e... 3 findings
bulk.ether bulk_extractor 6 blake2b:0825117f...
bulk.exif bulk_extractor 794 blake2b:c1c2b13e...
bulk.jpeg bulk_extractor 9 blake2b:efabc32f...
bulk.rfc822 bulk_extractor 7326 blake2b:8c3efa03... 2 findings
bulk.url bulk_extractor 458564 blake2b:e8cd927d... 6 findings
bulk.url_facebook-address bulk_extractor 19 blake2b:7fe55073... 6 findings
bulk.url_searches bulk_extractor 155 blake2b:b928562c... 6 findings
bulk.url_services bulk_extractor 3681 blake2b:f1dead12... 6 findings
bulk.zip_carved bulk_extractor 22411 blake2b:1a5d3360...
registry.query.system python-registry 1 blake2b:8639046c... 1 finding
evtx.manifest evtx-extract 54 blake2b:62bd3681...
ez.shimcache eztools 307 blake2b:1879f313...
registry.system regripper 186 blake2b:bbff9820...
registry.system regripper 7 blake2b:e4c6f012...
registry.system regripper 7 blake2b:e4c6f012...
registry.security regripper 69 blake2b:6b7bf22c...
registry.security regripper 8 blake2b:3c5e87f4...
registry.system regripper 33492 blake2b:e038c5c6...
registry.system regripper 283 blake2b:83a79d8c...
registry.system regripper 283 blake2b:5e405e71...
registry.system regripper 5209 blake2b:3a77cf33...
registry.system regripper 199 blake2b:4b1baf4d...
registry.system regripper 199 blake2b:70edbf72...
hayabusa.alerts hayabusa 35 blake2b:17620cb9... 3 findings
registry.system regripper 381 blake2b:070a4d56...
registry.system regripper 255 blake2b:0d77cf74...
registry.system regripper 255 blake2b:0d77cf74...
registry.usrclass.admin11 regripper 11 blake2b:26a43778...
registry.ntuser.admin11 regripper 133 blake2b:bf617a09...
registry.ntuser.default regripper 74 blake2b:8518dc3f...
registry.usrclass.informant regripper 102 blake2b:9f1344c3...
registry.ntuser.informant regripper 306 blake2b:597d71cd... 5 findings
registry.usrclass.temporary regripper 15 blake2b:3ef5eb22...
registry.ntuser.temporary regripper 118 blake2b:800424ee...
registry.query.system python-registry 1 blake2b:8639046c... 1 finding
optical.listing mulder-optical 58 blake2b:65ca19c0... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:9a158e59...
bulk.domain bulk_extractor 7303 blake2b:90c36187... 1 finding
bulk.duplicates bulk_extractor 1738 blake2b:481f17a5...
bulk.email bulk_extractor 30 blake2b:3fd4e07d... 3 findings
bulk.exif bulk_extractor 21 blake2b:c2dd544d...
bulk.rfc822 bulk_extractor 41 blake2b:e3da4d10... 2 findings
bulk.url bulk_extractor 7204 blake2b:bd98a868... 6 findings
bulk.url_services bulk_extractor 60 blake2b:787aa6dd... 6 findings
bulk.zip_carved bulk_extractor 5221 blake2b:769a57fa...
composite.correlation composite 1 blake2b:243b2a89...
composite.timeline composite 172 blake2b:6e15720e...
composite.execution composite 122 blake2b:fd78ddde...
composite.defense_evasion composite 174 blake2b:347306b8...
composite.lateral_movement composite 441 blake2b:3fa22e37...
composite.persistence composite 2430 blake2b:96f1e18f... 1 finding
forensic.timestomping timestomp_detector 1 blake2b:a8aad413... 3 findings
composite.file_staging composite 578 blake2b:1ac6dccb...
composite.exfil composite 2496 blake2b:866f0b45...
composite.file_staging composite 578 blake2b:1ac6dccb...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413... 3 findings
composite.defense_evasion composite 131 blake2b:22ab360e...
composite.execution composite 122 blake2b:fd78ddde...
composite.timeline composite 172 blake2b:6e15720e...
composite.persistence composite 2450 blake2b:fb297bb8... 1 finding
composite.lateral_movement composite 463 blake2b:6426a7e6...
composite.exfil composite 2514 blake2b:12a05d1c...
composite.correlation composite 1 blake2b:243b2a89...
composite.correlation composite 1 blake2b:e6ffd218...
0
Tool Calls
0
Unique Tools
1486.5s
Processing Time
8,984,788
Tokens
362,660
Tokens/min
Tool Distribution
Token Breakdown
Input Tokens8,856,848
Output Tokens127,940
Total Tokens8,984,788
Per-Model Breakdown
bedrock/zai.glm-58,984,788
Token Throughput Over Time
Estimated token consumption by model over time. Each bar represents a 5-minute window.
ID Tool Duration Timestamp Actions
tc_699a435d scan_evidence 1996ms 2026-09-20T05:41:41
tc_b52d6ba4 list_sources 2ms 2026-09-20T05:41:56
tc_a67c6d50 get_source_stats 2ms 2026-09-20T05:41:56
tc_6fb2cf4c open_case 29ms 2026-09-20T05:42:17
tc_d64a58b7 list_sources 2ms 2026-09-20T05:42:21
tc_9f1601dd open_case 26ms 2026-09-20T05:42:27
tc_2f762a13 open_case 27ms 2026-09-20T05:42:32
tc_5f8156f4 open_case 27ms 2026-09-20T05:42:59
tc_43a83848 start_extraction_batch 7ms 2026-09-20T05:43:08
tc_dc3c3051 run_mmls 46ms 2026-09-20T05:43:08
tc_9c8b37e7 run_fls 998ms 2026-09-20T05:43:09
tc_173dd6a2 detect_masquerading 1663ms 2026-09-20T05:43:10
tc_f06d9e5a open_case 27ms 2026-09-20T05:43:10
tc_a2f47fc6 open_case 28ms 2026-09-20T05:43:24
tc_e5b3752e run_mmls 37ms 2026-09-20T05:43:42
tc_60ed52e5 run_mmls 55ms 2026-09-20T05:43:44
tc_4a60b7d0 start_extraction_batch 9ms 2026-09-20T05:43:46
tc_417bf76c run_bulk_extractor 41540ms 2026-09-20T05:43:50
tc_96b9a1db run_mft_parser 5506ms 2026-09-20T05:43:51
tc_8e622e52 get_completed_results 0ms 2026-09-20T05:43:54
tc_664001ab run_fls 10379ms 2026-09-20T05:43:56
tc_c4238af7 start_extraction_batch 22ms 2026-09-20T05:44:03
tc_72eeed73 run_fls 5086ms 2026-09-20T05:44:08
tc_2082ca21 detect_masquerading 5900ms 2026-09-20T05:44:09
tc_7f62424a start_extraction_batch 59ms 2026-09-20T05:44:32
tc_ffbf5ccd run_mft_parser 163ms 2026-09-20T05:44:32
tc_046d5318 run_amcache_parser 11769ms 2026-09-20T05:44:44
tc_10a0c9e9 query_registry_value 0ms 2026-09-20T05:44:44
tc_3935e010 run_hayabusa 18729ms 2026-09-20T05:44:51
tc_7fdfa52e query_registry_value 0ms 2026-09-20T05:44:51
tc_2d118a89 run_shimcache_parser 19043ms 2026-09-20T05:44:51
tc_ff7bb274 run_registry_parser 20395ms 2026-09-20T05:44:52
tc_b3c7b754 run_prefetch_parser 21422ms 2026-09-20T05:44:53
tc_23f78628 run_bulk_extractor 81315ms 2026-09-20T05:45:24
tc_dffdffb5 get_completed_results 0ms 2026-09-20T05:45:26
tc_790545d9 start_extraction_batch 20ms 2026-09-20T05:46:23
tc_33db27cd run_registry_parser 5838ms 2026-09-20T05:46:29
tc_988f2308 detect_masquerading 300055ms 2026-09-20T05:48:46
tc_d08e7a5c run_mft_parser 27ms 2026-09-20T05:48:53
tc_612c8a44 query_registry_value 0ms 2026-09-20T05:48:55
tc_50de725b query_registry_value 0ms 2026-09-20T05:48:55
tc_ac99fa41 start_extraction_batch 4ms 2026-09-20T05:48:55
tc_227e989c run_shimcache_parser 4138ms 2026-09-20T05:48:57
tc_637dc5e4 query_registry_value 0ms 2026-09-20T05:49:01
tc_5c7371d2 run_prefetch_parser 8691ms 2026-09-20T05:49:02
tc_3bd45329 run_evtx_parser 0ms 2026-09-20T05:49:03
tc_8d1248c4 yara_scan_files 8916ms 2026-09-20T05:49:09
tc_521ca355 get_completed_results 0ms 2026-09-20T05:49:10
tc_2ca147d8 get_completed_results 0ms 2026-09-20T05:49:16
tc_cb446abb start_extraction_batch 3ms 2026-09-20T05:49:18
tc_aa5088e5 run_evtx_parser 0ms 2026-09-20T05:49:25
tc_a0b1c0b5 open_case 28ms 2026-09-20T05:49:35
tc_e19ccce4 wait_all 0ms 2026-09-20T05:49:35
tc_a31c5660 wait_all 0ms 2026-09-20T05:49:41
tc_b70bc33b get_completed_results 0ms 2026-09-20T05:49:51
tc_524fa834 get_completed_results 0ms 2026-09-20T05:49:51
tc_5b04badb open_case 30ms 2026-09-20T05:49:53
tc_f4b73478 list_sources 2ms 2026-09-20T05:50:06
tc_62a7b95b get_raw_output 91ms 2026-09-20T05:50:19
tc_656aeebd get_raw_output 14ms 2026-09-20T05:50:19
tc_db63d356 get_raw_output 16ms 2026-09-20T05:50:19
tc_4bd97e0f search 4ms 2026-09-20T05:50:24
tc_a649188e get_raw_output 16ms 2026-09-20T05:50:24
tc_2935f30c search 10ms 2026-09-20T05:50:38
tc_efccf048 search 3ms 2026-09-20T05:50:39
tc_5519a805 search 2ms 2026-09-20T05:50:39
tc_04242fc6 run_hayabusa 1904ms 2026-09-20T05:50:41
tc_826d49b7 yara_scan_files 5879ms 2026-09-20T05:50:55
tc_ba60b083 get_raw_output 16ms 2026-09-20T05:50:57
tc_f5ca191f get_raw_output 22ms 2026-09-20T05:50:57
tc_1e991981 get_raw_output 21ms 2026-09-20T05:50:57
tc_4f2e889c open_case 28ms 2026-09-20T05:51:07
tc_3e8eddf5 wait_all 0ms 2026-09-20T05:51:08
tc_e04fb8b5 search 4ms 2026-09-20T05:51:18
tc_b8b2d545 search 3ms 2026-09-20T05:51:19
tc_a19cf57d open_case 28ms 2026-09-20T05:51:26
tc_8accecd7 get_investigation_summary 4ms 2026-09-20T05:51:38
tc_bf1445a4 list_sources 1ms 2026-09-20T05:51:38
tc_824f8bdb get_raw_output 19ms 2026-09-20T05:51:44
tc_76e43792 get_raw_output 17ms 2026-09-20T05:51:45
tc_221952ae search 5ms 2026-09-20T05:51:45
tc_5fa1df33 search 3ms 2026-09-20T05:51:47
tc_eabe8bb7 search 3ms 2026-09-20T05:51:48
tc_9fa0973a get_raw_output 15ms 2026-09-20T05:52:02
tc_a1e884b7 search 4ms 2026-09-20T05:52:03
tc_8875f766 search 3ms 2026-09-20T05:52:03
tc_4f3dc5b5 get_raw_output 17ms 2026-09-20T05:52:10
tc_cb576a2f get_raw_output 17ms 2026-09-20T05:52:10
tc_41b83054 get_raw_output 17ms 2026-09-20T05:52:10
tc_04d037ef search 10ms 2026-09-20T05:52:23
tc_addfb293 get_raw_output 16ms 2026-09-20T05:52:24
tc_35815c39 search 4ms 2026-09-20T05:52:28
tc_d9e9c2aa search 3ms 2026-09-20T05:52:29
tc_0dc76182 search 3ms 2026-09-20T05:52:29
tc_e2f6632f search 3ms 2026-09-20T05:52:30
tc_150ac9db detect_timestomping 367ms 2026-09-20T05:52:51
tc_d61ad05d find_file_staging._search(tsk.filelist) 3ms 2026-09-20T05:52:51
tc_31109a7f find_file_staging._search(ez.mft) 3ms 2026-09-20T05:52:51
tc_8bab2e3f find_file_staging._query(tsk.filelist) 32ms 2026-09-20T05:52:51
tc_9eca078c find_file_staging._query(ez.mft) 139ms 2026-09-20T05:52:51
tc_3affffd0 find_file_staging._search(ez.mft) 14ms 2026-09-20T05:52:51
tc_69d4b4c2 find_file_staging._search(ez.mft) 2ms 2026-09-20T05:52:51
tc_ef1d2df2 find_file_staging 554ms 2026-09-20T05:52:51
tc_131ba178 search 5ms 2026-09-20T05:53:08
tc_46820bc7 get_raw_output 14ms 2026-09-20T05:53:09
tc_33a31851 search 3ms 2026-09-20T05:53:28
tc_126c3910 search 3ms 2026-09-20T05:53:29
tc_9344ac12 get_timeline 19ms 2026-09-20T05:53:29
tc_1e77a73c get_raw_output 16ms 2026-09-20T05:53:36
tc_262aaf44 search 2ms 2026-09-20T05:53:36
tc_e4156052 search 7ms 2026-09-20T05:53:45
tc_aa252ff3 submit_finding 18ms 2026-09-20T05:53:59
tc_69dd57d1 submit_finding 16ms 2026-09-20T05:54:02
tc_3aad1440 search 4ms 2026-09-20T05:54:04
tc_26fda51a search 3ms 2026-09-20T05:54:04
tc_c076492f get_raw_output 17ms 2026-09-20T05:54:04
tc_468addc6 submit_finding 16ms 2026-09-20T05:54:07
tc_a4fee2e3 update_finding 13ms 2026-09-20T05:54:24
tc_28623724 search 3ms 2026-09-20T05:54:43
tc_18aee01e search 3ms 2026-09-20T05:54:43
tc_22299e09 search 10ms 2026-09-20T05:54:48
tc_fc900623 parse_mft 19ms 2026-09-20T05:54:49
tc_8287461a get_raw_output 17ms 2026-09-20T05:55:04
tc_07fa12ee get_raw_output 3ms 2026-09-20T05:55:04
tc_438fc665 run_bulk_extractor 695845ms 2026-09-20T05:55:22
tc_30c3af7d get_completed_results 0ms 2026-09-20T05:55:25
tc_55f4e3b2 submit_finding 12ms 2026-09-20T05:55:37
tc_8efbe60b start_extraction_batch 12ms 2026-09-20T05:55:47
tc_61f79ad9 run_amcache_parser 0ms 2026-09-20T05:55:51
tc_5e4d4883 submit_finding 9ms 2026-09-20T05:55:56
tc_d3a42665 search 3ms 2026-09-20T05:55:57
tc_206a1296 query_registry_value 10035ms 2026-09-20T05:55:57
tc_3b03ed18 run_evtx_parser 10352ms 2026-09-20T05:55:57
tc_7cc840d2 submit_finding 9ms 2026-09-20T05:55:58
tc_4126984f run_shimcache_parser 12382ms 2026-09-20T05:55:59
tc_e4a13848 run_prefetch_parser 16043ms 2026-09-20T05:56:03
tc_406d128d submit_finding 10ms 2026-09-20T05:56:04
tc_43c7f39e submit_finding 9ms 2026-09-20T05:56:07
tc_06ef94c9 run_hayabusa 21697ms 2026-09-20T05:56:09
tc_d10164b3 run_registry_parser 34594ms 2026-09-20T05:56:22
tc_8c2fcbb9 search 10ms 2026-09-20T05:56:32
tc_989b08e7 get_raw_output 54ms 2026-09-20T05:56:32
tc_e219fc0c get_completed_results 0ms 2026-09-20T05:56:33
tc_81cf34d6 update_finding 7ms 2026-09-20T05:56:47
tc_165692ec open_case 28ms 2026-09-20T05:57:05
tc_0d4bc927 wait_all 0ms 2026-09-20T05:57:05
tc_e032b475 submit_finding 7ms 2026-09-20T05:57:14
tc_55751863 open_case 28ms 2026-09-20T05:57:22
tc_8c8e48d7 search 4ms 2026-09-20T05:57:23
tc_34ce987b search 4ms 2026-09-20T05:57:24
tc_056038b2 search 4ms 2026-09-20T05:57:24
tc_d34fbef5 list_sources 2ms 2026-09-20T05:57:27
tc_841d04fe get_investigation_summary 3ms 2026-09-20T05:57:27
tc_564da23e get_findings 1ms 2026-09-20T05:57:45
tc_0980e9d7 submit_finding 9ms 2026-09-20T05:57:50
tc_a0e68801 search 6ms 2026-09-20T05:57:51
tc_0df850f6 search 17ms 2026-09-20T05:57:51
tc_519d3d69 get_raw_output 53ms 2026-09-20T05:58:00
tc_140b34d6 search 9ms 2026-09-20T05:58:01
tc_c2269996 search 8ms 2026-09-20T05:58:01
tc_537efe99 search 3ms 2026-09-20T05:58:14
tc_56b744b2 search 4ms 2026-09-20T05:58:14
tc_3d92516b get_raw_output 52ms 2026-09-20T05:58:15
tc_a11949d5 update_finding 11ms 2026-09-20T05:58:27
tc_3e83a341 bookmark_window 8ms 2026-09-20T05:58:30
tc_896caf76 bookmark_window 5ms 2026-09-20T05:58:31
tc_f9a1618b query_registry_value 4410ms 2026-09-20T05:58:33
tc_9c5d9a2c search 56ms 2026-09-20T05:58:33
tc_b4a22c0a get_source_stats 54ms 2026-09-20T05:58:33
tc_16e21817 submit_finding 8ms 2026-09-20T05:58:33
tc_75b0c75e submit_finding 10ms 2026-09-20T05:58:47
tc_a6dc6cf9 submit_finding 10ms 2026-09-20T05:58:52
tc_3794ac72 submit_finding 10ms 2026-09-20T05:58:56
tc_626b7fa9 get_timeline 20ms 2026-09-20T05:59:04
tc_a8ac9125 get_raw_output 53ms 2026-09-20T05:59:04
tc_fd9a82be search 5ms 2026-09-20T05:59:05
tc_e1caf2bd update_finding 13ms 2026-09-20T05:59:25
tc_45ff9aa0 update_finding 13ms 2026-09-20T05:59:27
tc_2b025482 get_findings 1ms 2026-09-20T05:59:35
tc_c99f5847 get_investigation_summary 3ms 2026-09-20T05:59:35
tc_dfd00177 get_investigation_summary 3ms 2026-09-20T06:00:05
tc_15bc896f get_findings 1ms 2026-09-20T06:00:05
tc_9e889b7a submit_finding 16ms 2026-09-20T06:00:12
tc_38f635ae track_progress 13ms 2026-09-20T06:00:13
tc_2cff599c submit_finding 17ms 2026-09-20T06:00:28
tc_4290f7d5 track_progress 13ms 2026-09-20T06:00:41
tc_7e120736 submit_finding 16ms 2026-09-20T06:00:41
tc_a230bf15 get_investigation_summary 4ms 2026-09-20T06:00:51
tc_23b4cf66 submit_finding 16ms 2026-09-20T06:01:00
tc_8d77f00c submit_finding 18ms 2026-09-20T06:01:07
tc_7e92d9e7 open_case 28ms 2026-09-20T06:01:09
tc_47fc8bee update_finding 17ms 2026-09-20T06:01:37
tc_14180b54 get_findings 1ms 2026-09-20T06:01:37
tc_ed7bcf80 get_investigation_summary 4ms 2026-09-20T06:01:40
tc_6830b959 open_case 28ms 2026-09-20T06:01:50
tc_2d61aa5d start_extraction_batch 5ms 2026-09-20T06:01:54
tc_4ceefe51 run_optical_listing 76ms 2026-09-20T06:01:54
tc_d90f0d16 get_investigation_summary 3ms 2026-09-20T06:02:04
tc_c55db226 track_progress 15ms 2026-09-20T06:02:36
tc_2e10e0cc run_bulk_extractor 72642ms 2026-09-20T06:03:07
tc_baa52dcd get_completed_results 0ms 2026-09-20T06:03:13
tc_54a42515 start_extraction_batch 2ms 2026-09-20T06:03:32
tc_2a026e22 detect_masquerading 0ms 2026-09-20T06:03:32
tc_1fd7b89b yara_scan_files 5806ms 2026-09-20T06:03:37
tc_82b40fdb get_investigation_summary 4ms 2026-09-20T06:03:40
tc_a76ad205 get_completed_results 0ms 2026-09-20T06:03:46
tc_a24d44a4 open_case 29ms 2026-09-20T06:04:07
tc_58f54ace list_sources 3ms 2026-09-20T06:04:16
tc_73fc34c7 get_raw_output 56ms 2026-09-20T06:04:24
tc_3faa743a search 4ms 2026-09-20T06:04:24
tc_88ed2319 search 3ms 2026-09-20T06:04:45
tc_20382c42 search 3ms 2026-09-20T06:04:45
tc_66d1eef9 get_raw_output 27ms 2026-09-20T06:04:46
tc_2af02d27 get_raw_output 27ms 2026-09-20T06:05:00
tc_0de9cb31 get_raw_output 21ms 2026-09-20T06:05:00
tc_cd746815 search 9ms 2026-09-20T06:05:06
tc_2498e1e8 search 3ms 2026-09-20T06:05:07
tc_461e09f4 get_raw_output 26ms 2026-09-20T06:05:07
tc_b8548498 search 6ms 2026-09-20T06:05:18
tc_c7396f24 get_raw_output 26ms 2026-09-20T06:05:18
tc_422c9198 search 26ms 2026-09-20T06:05:19
tc_2dea3f74 get_source_stats 55ms 2026-09-20T06:05:47
tc_3dee6118 search 3ms 2026-09-20T06:05:48
tc_f01420c9 search 3ms 2026-09-20T06:05:48
tc_e20b2092 get_raw_output 26ms 2026-09-20T06:06:12
tc_43ae595b search 6ms 2026-09-20T06:06:12
tc_416097be detect_steganography 1ms 2026-09-20T06:06:12
tc_713626d9 search 4ms 2026-09-20T06:06:23
tc_0676902a search 5ms 2026-09-20T06:06:23
tc_e3ca2a2c search 8ms 2026-09-20T06:06:24
tc_338fea05 search 5ms 2026-09-20T06:06:48
tc_d49bc123 search 3ms 2026-09-20T06:06:48
tc_d373923e search 21ms 2026-09-20T06:06:49
tc_6b481885 get_raw_output 53ms 2026-09-20T06:07:02
tc_75d91c9c search 25ms 2026-09-20T06:07:02
tc_43459bde bookmark_window 11ms 2026-09-20T06:07:51
tc_62de1393 bookmark_window 10ms 2026-09-20T06:07:52
tc_7d993095 submit_finding 17ms 2026-09-20T06:08:10
tc_99c814d0 search 5ms 2026-09-20T06:08:38
tc_a1ae6c77 submit_finding 16ms 2026-09-20T06:08:49
tc_2a28dbd4 search 5ms 2026-09-20T06:08:49
tc_b64e2df5 list_files 200ms 2026-09-20T06:09:07
tc_99ea5d50 get_raw_output 26ms 2026-09-20T06:09:08
tc_64409a9d search 5ms 2026-09-20T06:09:10
tc_60113f8f get_investigation_summary 3ms 2026-09-20T06:09:35
tc_0dcec633 search 2ms 2026-09-20T06:09:36
tc_298f76ef search 3ms 2026-09-20T06:09:36
tc_0153cf7b get_findings 1ms 2026-09-20T06:09:57
tc_a9fbb216 search 89ms 2026-09-20T06:10:48
tc_d85f46d1 track_progress 13ms 2026-09-20T06:10:59
tc_6ece7dd7 submit_finding 16ms 2026-09-20T06:11:40
tc_5f7f5f8b get_investigation_summary 4ms 2026-09-20T06:12:29
tc_9412b181 open_case 29ms 2026-09-20T06:12:39
tc_df927df9 get_findings 2ms 2026-09-20T06:12:46
tc_96f59a61 get_investigation_summary 4ms 2026-09-20T06:12:46
tc_809192be list_sources 2ms 2026-09-20T06:12:46
tc_69e47079 get_source_stats 54ms 2026-09-20T06:12:46
tc_b60c4742 get_bookmarks 3ms 2026-09-20T06:12:46
tc_bd95ea8e get_findings 2ms 2026-09-20T06:12:52
tc_abb80b29 get_timeline 21ms 2026-09-20T06:12:53
tc_323cf610 open_case 29ms 2026-09-20T06:14:30
tc_135ca40a reconstruct_execution_chains._query(volatility.pstree) 51ms 2026-09-20T06:14:49
tc_a91c2f38 find_persistence_mechanisms._query(registry.system) 56ms 2026-09-20T06:14:49
tc_51c7b3cb find_suspicious_processes._query(volatility.malfind) 49ms 2026-09-20T06:14:49
tc_22b3b78f reconstruct_execution_chains._query(volatility.cmdline) 17ms 2026-09-20T06:14:49
tc_2cf80340 find_lateral_movement_indicators._search(all) 51ms 2026-09-20T06:14:49
tc_04f25c68 find_defense_evasion._search(all) 72ms 2026-09-20T06:14:49
tc_a6ecc5b7 find_persistence_mechanisms._query(registry.software) 10ms 2026-09-20T06:14:49
tc_e1fe399b find_suspicious_processes._query(volatility.cmdline) 15ms 2026-09-20T06:14:49
tc_9f5418e8 find_file_staging._search(tsk.filelist) 72ms 2026-09-20T06:14:49
tc_cccc7069 reconstruct_execution_chains._query(volatility.netscan) 8ms 2026-09-20T06:14:49
tc_8ceda4d6 find_lateral_movement_indicators._search(all) 3ms 2026-09-20T06:14:49
tc_efe9a821 find_defense_evasion._search(ez.mft) 7ms 2026-09-20T06:14:49
tc_de88806e find_persistence_mechanisms._query(volatility.svcscan) 7ms 2026-09-20T06:14:49
tc_05e9b70f find_suspicious_processes._query(volatility.netscan) 6ms 2026-09-20T06:14:49
tc_8e34714d correlate_across_sources 123ms 2026-09-20T06:14:49
tc_e199b765 reconstruct_execution_chains._query(volatility.malfind) 7ms 2026-09-20T06:14:49
tc_cba9bcaa reconstruct_execution_chains 150ms 2026-09-20T06:14:49
tc_2358ccd8 find_defense_evasion._search(all) 6ms 2026-09-20T06:14:49
tc_94f732e5 find_persistence_mechanisms._search(all) 6ms 2026-09-20T06:14:49
tc_4e35d558 find_file_staging._search(ez.mft) 27ms 2026-09-20T06:14:49
tc_82e668be find_suspicious_processes._query(volatility.pstree) 7ms 2026-09-20T06:14:49
tc_ff3ec586 find_lateral_movement_indicators._search(all) 7ms 2026-09-20T06:14:49
tc_c6d1c517 analyze_execution_timeline._query(ez.shimcache) 6ms 2026-09-20T06:14:49
tc_620c5a0f find_execution_evidence._query(ez.shimcache) 6ms 2026-09-20T06:14:49
tc_4b3a4396 find_persistence_mechanisms._search(all) 4ms 2026-09-20T06:14:49
tc_95d4f1e7 find_defense_evasion._search(all) 12ms 2026-09-20T06:14:49
tc_9f6f00f8 find_suspicious_processes 165ms 2026-09-20T06:14:49
tc_8a371511 analyze_execution_timeline 39ms 2026-09-20T06:14:49
tc_48c2fc9f find_lateral_movement_indicators._query(volatility.netscan) 7ms 2026-09-20T06:14:49
tc_4470c0bb find_execution_evidence 34ms 2026-09-20T06:14:49
tc_83a78398 find_persistence_mechanisms._query(ez.shimcache) 8ms 2026-09-20T06:14:49
tc_9757a1b8 find_defense_evasion._search(all) 8ms 2026-09-20T06:14:49
tc_3bc0f2d8 find_lateral_movement_indicators._search(all) 8ms 2026-09-20T06:14:49
tc_0656a764 find_defense_evasion 223ms 2026-09-20T06:14:49
tc_4f90b383 find_persistence_mechanisms._search(all) 8ms 2026-09-20T06:14:49
tc_7ca4f122 find_lateral_movement_indicators._search(all) 4ms 2026-09-20T06:14:49
tc_261b9f05 get_eventlog_anomalies 2ms 2026-09-20T06:14:49
tc_c81edcc7 get_userassist 2ms 2026-09-20T06:14:49
tc_1fbb7382 parse_autoruns 13ms 2026-09-20T06:14:49
tc_046bd039 find_lateral_movement_indicators._search(all) 18ms 2026-09-20T06:14:49
tc_67d08173 find_lateral_movement_indicators 273ms 2026-09-20T06:14:49
tc_fdd4cd0e find_file_staging._query(tsk.filelist) 163ms 2026-09-20T06:14:49
tc_4c544a32 find_persistence_mechanisms._query(tsk.filelist) 317ms 2026-09-20T06:14:49
tc_71701c59 find_persistence_mechanisms 593ms 2026-09-20T06:14:49
tc_4b060b74 detect_timestomping 793ms 2026-09-20T06:14:50
tc_cac4863d find_file_staging._query(ez.mft) 739ms 2026-09-20T06:14:50
tc_e6f94a9d find_file_staging._search(ez.mft) 14ms 2026-09-20T06:14:50
tc_1eb83053 find_file_staging._search(ez.mft) 23ms 2026-09-20T06:14:50
tc_d3a468d3 find_file_staging 1481ms 2026-09-20T06:14:50
tc_7096d56c find_data_exfiltration_indicators._query(bulk.url) 1608ms 2026-09-20T06:14:50
tc_0366323b find_data_exfiltration_indicators._query(bulk.email) 9ms 2026-09-20T06:14:51
tc_30faf1d5 find_data_exfiltration_indicators._query(bulk.domain) 101ms 2026-09-20T06:14:51
tc_101d1c3c find_data_exfiltration_indicators._search(all) 25ms 2026-09-20T06:14:52
tc_a5c8884e find_data_exfiltration_indicators 2796ms 2026-09-20T06:14:52
tc_12750b5c get_completed_results 0ms 2026-09-20T06:14:54
tc_44238e23 check_extraction_status 0ms 2026-09-20T06:14:55
tc_1adebbdb get_userassist 1ms 2026-09-20T06:15:12
tc_0a8849df reconstruct_execution_chains._query(volatility.pstree) 8ms 2026-09-20T06:15:14
tc_d690bf9e reconstruct_execution_chains._query(volatility.cmdline) 6ms 2026-09-20T06:15:14
tc_d9b46792 reconstruct_execution_chains._query(volatility.netscan) 6ms 2026-09-20T06:15:14
tc_27e83835 reconstruct_execution_chains._query(volatility.malfind) 6ms 2026-09-20T06:15:14
tc_fc67cec2 reconstruct_execution_chains 43ms 2026-09-20T06:15:14
tc_ed7499c4 find_file_staging._search(tsk.filelist) 23ms 2026-09-20T06:15:14
tc_5a0c8f22 find_file_staging._search(ez.mft) 22ms 2026-09-20T06:15:14
tc_dd511107 find_file_staging._query(tsk.filelist) 40ms 2026-09-20T06:15:14
tc_20186c20 find_file_staging._query(ez.mft) 193ms 2026-09-20T06:15:15
tc_96ec6053 find_file_staging._search(ez.mft) 14ms 2026-09-20T06:15:15
tc_fbaab08f find_file_staging._search(ez.mft) 21ms 2026-09-20T06:15:15
tc_0c79f412 find_file_staging 666ms 2026-09-20T06:15:15
tc_ac68592e detect_timestomping 272ms 2026-09-20T06:15:15
tc_f83996a3 find_defense_evasion._search(all) 5ms 2026-09-20T06:15:15
tc_d8acde9c find_defense_evasion._search(ez.mft) 7ms 2026-09-20T06:15:15
tc_5a4ecc56 find_defense_evasion._search(all) 4ms 2026-09-20T06:15:15
tc_45108020 find_defense_evasion._search(all) 9ms 2026-09-20T06:15:15
tc_ae277b06 find_defense_evasion._search(all) 3ms 2026-09-20T06:15:15
tc_807f168b find_defense_evasion 49ms 2026-09-20T06:15:15
tc_90f2d55b find_execution_evidence._query(ez.shimcache) 6ms 2026-09-20T06:15:15
tc_877502d9 find_execution_evidence 12ms 2026-09-20T06:15:15
tc_310775b9 analyze_execution_timeline._query(ez.shimcache) 6ms 2026-09-20T06:15:15
tc_c3fbcf2e analyze_execution_timeline 11ms 2026-09-20T06:15:15
tc_3d2dd68d find_persistence_mechanisms._query(registry.system) 14ms 2026-09-20T06:15:23
tc_29ede4dd find_persistence_mechanisms._query(registry.software) 6ms 2026-09-20T06:15:23
tc_c8a5d64c find_persistence_mechanisms._query(volatility.svcscan) 6ms 2026-09-20T06:15:23
tc_0fdc4321 find_persistence_mechanisms._search(all) 6ms 2026-09-20T06:15:23
tc_84c64389 find_persistence_mechanisms._search(all) 3ms 2026-09-20T06:15:23
tc_aa96c737 find_persistence_mechanisms._query(ez.shimcache) 6ms 2026-09-20T06:15:23
tc_9af92771 find_persistence_mechanisms._search(all) 5ms 2026-09-20T06:15:23
tc_586d71d7 find_persistence_mechanisms._query(tsk.filelist) 35ms 2026-09-20T06:15:23
tc_742c2006 find_persistence_mechanisms 143ms 2026-09-20T06:15:23
tc_461416b9 find_lateral_movement_indicators._search(all) 16ms 2026-09-20T06:15:24
tc_c3557a0f find_lateral_movement_indicators._search(all) 4ms 2026-09-20T06:15:24
tc_0cbbe026 find_lateral_movement_indicators._search(all) 5ms 2026-09-20T06:15:24
tc_8ce9d1bf find_lateral_movement_indicators._query(volatility.netscan) 6ms 2026-09-20T06:15:24
tc_8c44fa38 find_lateral_movement_indicators._search(all) 4ms 2026-09-20T06:15:24
tc_6c531e18 find_lateral_movement_indicators._search(all) 3ms 2026-09-20T06:15:24
tc_736d7c12 find_lateral_movement_indicators._search(all) 5ms 2026-09-20T06:15:24
tc_891889b2 find_lateral_movement_indicators 73ms 2026-09-20T06:15:24
tc_e6850daf find_data_exfiltration_indicators._query(bulk.url) 446ms 2026-09-20T06:15:25
tc_38e11941 find_data_exfiltration_indicators._query(bulk.email) 9ms 2026-09-20T06:15:26
tc_c8464c4d find_data_exfiltration_indicators._query(bulk.domain) 103ms 2026-09-20T06:15:26
tc_ac0e87ee find_data_exfiltration_indicators._search(all) 26ms 2026-09-20T06:15:26
tc_0ab5e217 find_data_exfiltration_indicators 1584ms 2026-09-20T06:15:26
tc_dad9acdb find_suspicious_processes._query(volatility.malfind) 8ms 2026-09-20T06:15:26
tc_752edff9 find_suspicious_processes._query(volatility.cmdline) 6ms 2026-09-20T06:15:26
tc_294197b2 find_suspicious_processes._query(volatility.netscan) 6ms 2026-09-20T06:15:26
tc_db3ec810 find_suspicious_processes._query(volatility.pstree) 6ms 2026-09-20T06:15:26
tc_09383eff find_suspicious_processes 41ms 2026-09-20T06:15:26
tc_d5c93e1a correlate_across_sources 38ms 2026-09-20T06:15:26
tc_543a3412 parse_autoruns 3ms 2026-09-20T06:15:37
tc_cc99e9c8 get_eventlog_anomalies 1ms 2026-09-20T06:15:38
tc_fa03bea1 open_case 30ms 2026-09-20T06:16:05
tc_a08d5c21 get_investigation_summary 5ms 2026-09-20T06:16:06
tc_e0a8c477 get_findings 2ms 2026-09-20T06:16:12
tc_5f04d82b get_raw_output 56ms 2026-09-20T06:16:23
tc_fafe386b get_raw_output 55ms 2026-09-20T06:16:29
tc_591eaf00 search 7ms 2026-09-20T06:16:36
tc_02f420f6 search 7ms 2026-09-20T06:16:41
tc_de01af43 search 3ms 2026-09-20T06:16:49
tc_38075eaa search 3ms 2026-09-20T06:16:56
tc_5313802f get_raw_output 54ms 2026-09-20T06:16:59
tc_6adcecfb search 8ms 2026-09-20T06:17:15
tc_953117d0 get_raw_output 8ms 2026-09-20T06:17:26
tc_7be86aeb search 3ms 2026-09-20T06:17:48
tc_23aef311 get_raw_output 54ms 2026-09-20T06:18:01
tc_0602a3ae search 4ms 2026-09-20T06:18:25
tc_01f8154d get_ioc_summary 604ms 2026-09-20T06:19:02
tc_d51311a8 submit_finding 10ms 2026-09-20T06:20:06
tc_7ad32139 submit_finding 9ms 2026-09-20T06:20:27
tc_ff81fadf submit_finding 8ms 2026-09-20T06:21:16
tc_793a7d12 submit_finding 18ms 2026-09-20T06:21:48
tc_992e6771 submit_finding 15ms 2026-09-20T06:22:55
tc_37b8af5a get_findings 1ms 2026-09-20T06:23:14
tc_fd8ff1ea track_progress 14ms 2026-09-20T06:24:22
tc_b988c3f2 get_investigation_summary 4ms 2026-09-20T06:24:49
tc_fb72b577 open_case 30ms 2026-09-20T06:24:54
tc_13a3a948 get_findings 2ms 2026-09-20T06:24:56
tc_efa8250b get_investigation_summary 4ms 2026-09-20T06:24:56
tc_c6194b5c list_sources 2ms 2026-09-20T06:24:56
tc_507d1a49 get_timeline 23ms 2026-09-20T06:25:38
tc_9c0630b7 get_timeline 1ms 2026-09-20T06:26:32
tc_1c6b1014 open_case 29ms 2026-09-20T06:27:57
tc_00422f9a search 12ms 2026-09-20T06:28:10
tc_f7bd5b63 search 13ms 2026-09-20T06:28:10
tc_27eea260 search 20ms 2026-09-20T06:28:10
tc_3ac34bef search 16ms 2026-09-20T06:28:10
tc_ffec9423 search 16ms 2026-09-20T06:28:10
tc_0f281fb0 search 15ms 2026-09-20T06:28:10
tc_9bc4e4b6 search 9ms 2026-09-20T06:28:10
tc_423987e3 search 14ms 2026-09-20T06:28:10
tc_98469803 search 15ms 2026-09-20T06:28:10
tc_66868151 search 7ms 2026-09-20T06:28:10
tc_48d43254 search 6ms 2026-09-20T06:28:10
tc_066c62f8 search 22ms 2026-09-20T06:28:10
tc_680e00c5 correlate_across_sources 47ms 2026-09-20T06:28:12
tc_9b1e160d get_timeline 11ms 2026-09-20T06:28:15
tc_c60cea70 get_timeline 3ms 2026-09-20T06:28:18
tc_7204490a open_case 29ms 2026-09-20T06:29:31
tc_d5c3008a get_findings 2ms 2026-09-20T06:29:31
tc_29e419d8 get_investigation_summary 4ms 2026-09-20T06:29:49
tc_f4ac36c2 search 10ms 2026-09-20T06:29:59
tc_10e00ec0 search 7ms 2026-09-20T06:29:59
tc_e87fb019 search 5ms 2026-09-20T06:29:59
tc_49ed2e87 search 4ms 2026-09-20T06:30:00
tc_ddcace22 search 13ms 2026-09-20T06:30:17
tc_67322fac search 8ms 2026-09-20T06:30:18
tc_00cbc22e search 3ms 2026-09-20T06:30:18
tc_eda86aa8 get_raw_output 56ms 2026-09-20T06:30:43
tc_053a7646 deduplicate_findings 29ms 2026-09-20T06:31:34
tc_d26fb1ca audit_evidence_coverage 222ms 2026-09-20T06:32:23
tc_f857e516 audit_tool_coverage 2ms 2026-09-20T06:32:23
tc_b2b8eb6d get_raw_output 54ms 2026-09-20T06:33:06
tc_72ca7fe2 get_raw_output 54ms 2026-09-20T06:33:06
tc_872b41ef get_raw_output 54ms 2026-09-20T06:33:06
tc_c2bfec73 search 5ms 2026-09-20T06:33:52
tc_30ac62fc search 8ms 2026-09-20T06:33:52
tc_34bb9b7b update_finding 14ms 2026-09-20T06:34:50
tc_d8f71c11 update_finding 13ms 2026-09-20T06:35:42
tc_791a3369 update_finding 13ms 2026-09-20T06:36:04
tc_829fce25 update_finding 14ms 2026-09-20T06:36:27
tc_1c0cbfc2 deduplicate_findings 113ms 2026-09-20T06:36:54
tc_cb51d4e2 get_findings 1ms 2026-09-20T06:37:09
tc_c16eb104 check_finalize_readiness 3ms 2026-09-20T06:37:09
tc_71452148 track_progress 12ms 2026-09-20T06:37:45
tc_4f4c8bb3 get_investigation_summary 4ms 2026-09-20T06:38:28
tc_72c487f0 check_finalize_readiness 4ms 2026-09-20T06:38:28
tc_2905860f open_case 8ms 2026-09-20T06:38:40
tc_ce3c5562 get_findings 2ms 2026-09-20T06:38:44
tc_72db9c6d get_investigation_summary 4ms 2026-09-20T06:38:44
tc_6e548c41 get_ioc_summary 595ms 2026-09-20T06:38:45
tc_c8e572a8 get_bookmarks 2ms 2026-09-20T06:38:45
tc_a8ca5c4b get_source_stats 53ms 2026-09-20T06:38:45
tc_a5b9c723 submit_narrative 13ms 2026-09-20T06:41:31
tc_6145f77c check_finalize_readiness 3ms 2026-09-20T06:41:47

Each finding traces back to the specific tool calls that produced the supporting evidence.

US Government Email Address Found on Removable Media 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.email" }
tc_f5ca191f
22ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "omb.eop.gov", "loc.gov", "att.net" ], "query": "", "regex...
tc_b8b2d545
3ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.rfc822" }
tc_1e991981
21ms
Intent Evidence: Web Searches About Data Leakage and Forensic Evasion 1 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "google.com", "gmail.com", "mail.com", "outlook.com", "yma...
tc_0df850f6
17ms
Data Exfiltration Timeline and Method 5 refs
1
parse_mft
{ "t_end": "2015-03-25T23:59:59", "t_start": "2015-03-23T00:00:00" }
tc_fc900623
19ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "2015-03-24", "regex": false, "source": "ez.m...
tc_22299e09
10ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_76e43792
17ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "dropbox", "drive", "mega", "skydrive", "onedrive", "googl...
tc_3aad1440
4ms
5
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "drive.google", "regex": false, "source": "bu...
tc_8c8e48d7
4ms
NIST Employee Identity Confirmed - Iaman Informant 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": [ " Eric_P._Lauer", "omb.eop.gov", "wayne.longman", "mmun@lo...
tc_9c5d9a2c
56ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_519d3d69
53ms
Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering 3 refs
1
search
{ "exclude_sources": null, "max_results": 30, "queries": [ "IAMAN CD", "IAMAN $_@", "volume label", "session" ], "que...
tc_0602a3ae
4ms
2
get_raw_output
{ "after_id": 0, "limit": 20, "source_name": "tsk.masquerade" }
tc_6b481885
53ms
3
get_raw_output
{ "after_id": 0, "limit": 100, "source_name": "optical.listing" }
tc_73fc34c7
56ms
US Government Email Metadata in Exfiltrated Files - OMB/EOP and Library of Congress 1 refs
1
get_ioc_summary
tc_01f8154d
604ms
Files Disguised with Wrong Extensions on Removable Media 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_62a7b95b
91ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_76e43792
17ms
Source Data Found on "Authorized USB" Drive (rm1) 1 refs
1
get_raw_output
{ "after_id": 14530, "limit": 10, "source_name": "tsk.filelist" }
tc_07fa12ee
3ms
Google Drive Installation and Cloud Storage Setup 2 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "dropbox", "drive", "mega", "skydrive", "onedrive", "googl...
tc_3aad1440
4ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "USB", "regex": false, "source": null, "t_end...
tc_221952ae
5ms
Secret Project Files Accessed on PC (LNK Evidence) 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "[secret_project]", "design_concept", "detailed_design", "...
tc_d3a42665
3ms
2
parse_mft
{ "t_end": "2015-03-25T23:59:59", "t_start": "2015-03-23T00:00:00" }
tc_fc900623
19ms
Cloud Storage Tools Installed (Google Drive and iCloud) 1 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "drive", "dropbox", "mega", "mediafire", "box.com", "iclou...
tc_a0e68801
6ms
Anti-Forensic Tools Installation and Execution 1 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_519d3d69
53ms
Multiple User Accounts Created with Admin Privileges 1 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_a8ac9125
53ms
Cloud Storage Services Accessed for Potential Exfiltration 2 refs
1
search
{ "exclude_sources": null, "max_results": 30, "queries": [ "drive.google.com", "dropbox", "onedrive", "box.com", "meg...
tc_fd9a82be
5ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_519d3d69
53ms
Google Drive as Third Exfiltration Channel - Sync Activity with Database Deleted 4 refs
1
get_raw_output
{ "after_id": 52790, "limit": 100, "source_name": "registry.ntuser.informant" }
tc_953117d0
8ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Google Drive", "regex": false, "source": "co...
tc_591eaf00
7ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "dropbox", "drive", "mega", "skydrive", "onedrive", "googl...
tc_3aad1440
4ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "USB", "regex": false, "source": null, "t_end...
tc_221952ae
5ms
Coordinated Anti-Forensic Cleanup Timeline - Evidence of Planned Exit Strategy 3 refs
1
get_raw_output
{ "after_id": 52790, "limit": 100, "source_name": "registry.ntuser.informant" }
tc_953117d0
8ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "forensic.timestomping" }
tc_23aef311
54ms
3
get_raw_output
{ "after_id": 0, "limit": 150, "source_name": "hayabusa.alerts" }
tc_5313802f
54ms
Timestamp Manipulation Detected on PC 1 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "forensic.timestomping" }
tc_1e77a73c
16ms
Data Exfiltration Timeline - March 22-25, 2015 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_62a7b95b
91ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "[secret_project]", "design_concept", "detailed_design", "...
tc_d3a42665
3ms
3
get_raw_output
{ "after_id": 14530, "limit": 10, "source_name": "tsk.filelist" }
tc_07fa12ee
3ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "forensic.timestomping" }
tc_1e77a73c
16ms
SanDisk USB Device Connected During Exfiltration Period 1 refs
1
query_registry_value
{ "case_id": "ndlc", "hive": "system", "image_path": "/evidence/cfreds_2015_data_leakage_pc.E01", "key_path": "Contro...
tc_f9a1618b
4410ms
Admin Accounts Created - Minimal Use of admin11, No Evidence of Use for Others 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 150, "source_name": "hayabusa.alerts" }
tc_5313802f
54ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "autostart", "startup", "persistence", "Run key", "service...
tc_30ac62fc
8ms
Secret Project Data on USB Device 1 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Secret Project", "regex": false, "source": "...
tc_33a31851
3ms
Google Drive Web Interface and File Sharing URLs 3 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "drive.google", "regex": false, "source": "bu...
tc_8c8e48d7
4ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "docs.google", "regex": false, "source": "bul...
tc_34ce987b
4ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "mail.google", "regex": false, "source": "bul...
tc_056038b2
4ms

Tool Call Details

Copied to clipboard