Investigation Dashboard
The attack timeline spans 2014-12-01 to 2015-03-25. The earliest activity was Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering (2014-12-01). The investigation subsequently uncovered Intent Evidence: Web Searches About Data Leakage and Forensic Evasion; NIST Employee Identity Confirmed - Iaman Informant; Data Exfiltration Timeline and Method. The most recent activity was Anti-Forensic Tools Installation and Execution (2015-03-25).
- US Government Email Address Found on Removable Media
- Intent Evidence: Web Searches About Data Leakage and Forensic Evasion
- Data Exfiltration Timeline and Method
- NIST Employee Identity Confirmed - Iaman Informant
- Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering
-
US Government Email Address Found on Removable Media
2015-03-24T09:59:27 — 2015-03-24T23:59:59
-
Intent Evidence: Web Searches About Data Leakage and Forensic Evasion
2015-03-22T14:34:00
-
Data Exfiltration Timeline and Method
2015-03-23T20:02:43
-
NIST Employee Identity Confirmed - Iaman Informant
2015-03-22T14:34:41 — 2015-03-25T15:29:08
-
Deleted Files on UDF Optical Media - Evidence of Multi-Session Data Tampering
2014-12-01T14:50:26Z — 2015-03-24T20:57:03Z
-
US Government Email Metadata in Exfiltrated Files - OMB/EOP and Library of Congress
2015-03-24T09:59:27Z — 2015-03-24T23:59:59Z
| Case ID | ndlc |
| Evidence Root | /evidence |
| Report Generated | 2026-09-20T06:42:02 |
| Investigation Start | 2026-09-20T05:41:41 |
| Investigation End | 2026-09-20T06:41:47 |
| Total Processing | 1486.5s |
| Audit Log | /home/mulder/.mulder/cases/ndlc.audit.jsonl |
Evidence Hashes
sha256sum <file>| File | SHA-256 | Size |
|---|---|---|
| cfreds_2015_data_leakage_pc.E01 | e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 | 2.0 GB |
| cfreds_2015_data_leakage_rm1.E01 | a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 | 74.6 MB |
| cfreds_2015_data_leakage_rm2.E01 | 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 | 243.2 MB |
| cfreds_2015_data_leakage_rm3_type3.E01 | 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b | 90.2 MB |
Investigation Report
Investigation Report: Insider Threat Data Exfiltration
Background
This investigation examines evidence from a PC system, two USB flash drives (rm1 and rm2), and one optical media disc (rm3_type3) to determine the scope and nature of data exfiltration activities. The evidence inventory comprises 13 forensic sources including MFT analysis, filesystem extraction, bulk_extractor output, registry hives, and event log analysis.
The primary user account under investigation is "informant," identified as Iaman Informant, an employee of the National Institute of Standards and Technology (NIST) with the email address iaman.informant@nist.gov. The investigation period spans March 22-25, 2015, during which the user account was created, data was accessed and staged, and anti-forensic cleanup was executed.
The system under examination is a Windows 7 PC with an "informant" user profile created on March 22, 2015, at 14:34:41 UTC. The user's brief activity window of four days, combined with the creation of a resignation letter on March 25, suggests this was an intentional departure period during which sensitive data was systematically exfiltrated from government systems.
Incident Timeline
The incident reconstruction reveals a methodical four-phase operation executed over three days:
Phase 1: Initial Setup and Credential Creation (March 22, 2015)
At 14:34:41 UTC on March 22, the "informant" user account was created on the PC system. Within 30 minutes, three additional administrator accounts were created: admin11 at 15:51:54, ITechTeam at 15:52:30, and an account named "temporary" with a password reset at 15:53:11. All three accounts were granted local administrator privileges by the informant account. Security event logs confirm these actions were performed from the informant session (SubjectLogonId: 0x224e3). The admin11 account was used at least once at 15:57:30 UTC when NOTEPAD.EXE was executed, as recorded in UserAssist registry entries.
Phase 2: Source File Access and Cloud Infrastructure Setup (March 23, 2015)
On March 23, the user accessed source files from an "Authorized USB" drive (rm1). At 18:31:10 UTC, a SanDisk Cruzer Fit USB device was connected to the PC, as recorded in the Windows registry USBSTOR key. Seven minutes later, at 18:38:21 UTC, the user opened [secret_project]_design_concept.ppt from the USB drive, as evidenced by LNK file creation in the Recent documents folder (Users\informant\AppData\Roaming\Microsoft\Windows\Recent[secret_project]_design_concept.lnk).
The "Authorized USB" drive contained a "Secret Project Data" directory with organized project materials including design documents, proposals, and pricing files. A Word temporary file (~$ecret_project]_proposal.docx) indicated documents were actively edited on this drive.
Between 20:02:43 and 20:05:32 UTC, Google Drive desktop client was installed and configured. The sync folder was created at Users\informant\Google Drive\desktop.ini (created 20:05:32), and synchronization databases (sync_config.db, snapshot.db) were established. At 20:27:33 UTC, a second project file was accessed, evidenced by the LNK file [secret_project]_final_meeting.pptx.lnk.
Phase 3: Data Obfuscation and Staging (March 24, 2015)
The data exfiltration staging began on March 24 at 09:59:27 UTC when the first obfuscated file was created on USB drive rm2 (volume label "IAMAN $_@"). Over the next 51 seconds, through 10:00:18 UTC, all 17 masqueraded files were created. These files were disguised with media file extensions but contained Microsoft Office documents:
- winter_storm.amr (14.5 MB) → OLE format
- winter_whether_advisory.zip (16.4 MB) → PowerPoint
- my_favorite_cars.db (1.3 MB) → OLE format
- my_favorite_movies.7z (100 KB) → Excel
- new_years_day.jpg (10.2 MB) → Excel
- super_bowl.avi (10.3 MB) → OLE format
- a_gift_from_you.gif (35.2 MB) → Word (largest file)
- And 10 additional files in the diary_# series
All files were placed in $OrphanFiles directories marked as deleted entries and organized in folders named design, PRICIN~1 (pricing), progress, proposal, and TECHNI~1 (technical review). This naming convention suggests corporate/business documents being disguised as personal media files.
Later that day, at approximately 20:55:43 UTC, the same 17 files were burned to UDF optical media (rm3_type3, volume label "IAMAN CD"). The disc exhibits 9 VAT (Virtual Allocation Table) sessions showing progressive directory renaming and file deletion across sessions to obscure the original structure. The current session only contains three image files (Koala.jpg, Penguins.jpg, Tulips.jpg), while earlier sessions contained the 17 obfuscated documents that were later deleted but remain forensically recoverable.
Phase 4: Anti-Forensic Cleanup and Resignation (March 25, 2015)
On March 25, a coordinated anti-forensic cleanup operation was executed alongside employment termination activities:
-
11:08:36 UTC: Timestamp manipulation detected on PC root directory. The $STANDARD_INFORMATION Created timestamp was backdated to 2009-07-14 (Windows installation date), creating a 2080-day discrepancy with the $FILE_NAME timestamp. This timestomping technique was used to hide recent filesystem activity.
-
14:46:05 UTC: CCleaner installer (ccsetup504.exe) executed
- 14:50:14 UTC: Eraser installer executed
- 14:57:56 UTC: CCleaner executed (first run)
- 15:12:28 UTC: Eraser executed (secure file deletion)
- 15:15:50 UTC: CCleaner executed (second run)
- 15:21:30 UTC: Google Drive sync executed (googledrivesync.exe)
- 15:21:34 UTC: Google Drive lockfile last modified
- 15:21:36 UTC: Google Drive folder updated
- 15:28:33 UTC: Resignation letter created (Resignation_Letter_(Iaman_Informant).xps)
- 15:29:08 UTC: Resignation letter last accessed (Resignation_Letter_(Iaman_Informant).docx)
The Google Drive sync databases (sync_config.db and snapshot.db) were deleted, preventing forensic determination of which files were uploaded to the cloud. The timing of cleanup activities immediately preceding the resignation letter demonstrates consciousness of guilt and premeditated evidence destruction.
Key Findings
Data Exfiltration via Multiple Channels
The investigation confirmed 19 findings involving confirmed data exfiltration through at least three distinct channels. The exfiltration was systematic, involving 17 files totaling approximately 85-90 MB of disguised Office documents containing sensitive government and business information.
The first channel was USB drive rm2 ("IAMAN $_@"), where files were staged in 51 seconds through a rapid batch copy operation. The second channel was optical media rm3_type3 ("IAMAN CD"), created approximately 11 hours after the USB staging, providing a redundant backup. The third channel was Google Drive cloud storage, installed the day before staging and actively synced during the cleanup phase, with sync databases subsequently deleted to hide evidence.
Government Document Metadata in Exfiltrated Files
Critical severity findings reveal that exfiltrated documents contained embedded email addresses from US Government sources. Eric_P._Lauer@omb.eop.gov represents the Office of Management and Budget within the Executive Office of the President. The mmun@loc.gov address represents the Library of Congress. Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) were found in document content, along with email subjects referencing historical photograph catalogs.
The presence of OMB/EOP metadata in documents labeled "Secret Project Data" indicates potential classified or sensitive unclassified information. A NIST employee exfiltrating documents containing Executive Office of the President and Library of Congress email metadata represents an insider threat incident with potential national security implications. The unauthorized removal of documents from federal systems constitutes potential federal crimes including theft of government property and unauthorized removal of records.
Systematic File Masquerading on USB and Optical Media
High severity findings document that all 17 files on both rm2 USB and rm3_type3 optical media were systematically renamed with misleading file extensions. Extension/content mismatch analysis shows Word documents disguised as .png, .gif, .txt, and .one files. Excel spreadsheets disguised as .7z and .jpg files. PowerPoint presentations disguised as .zip and .txt files. OLE compound documents disguised as .amr (audio), .db, and .avi (video) files.
This obfuscation technique, consistent with MITRE ATT&CK technique T1564.001 (Hide Artifacts: Hidden Files and Directories), is commonly used to bypass Data Loss Prevention systems and evade detection during exfiltration. The consistent folder structure across both media types (design, pricing, progress, proposal, technical review) indicates business documents disguised as personal media files.
Intent Evidence: Web Research on Data Leakage
Critical severity findings establish intent through web browsing evidence. The user researched "data-leakage-threats-mitigation-19312" (SANS whitepaper), "information leakage cases," and "leaking confidential information" with progressive query refinement showing "leaking confidenti" → "leaking confidential i" → "leaking confidential informat" → "leaking confidential information."
Additional research included the ForensicsWiki "Tools:Data_Recovery" page, Microsoft Research paper "leak_secret.pdf," and searches for "system cleaner." The user also accessed https://www.google.com/drive/ and https://www.google.com/drive/download/. This evidence proves the suspect had intent to leak confidential information and researched methods to avoid detection. The progression of search queries shows deliberate planning, not accidental data handling.
Anti-Forensic Tool Execution
High severity findings document the installation and execution of CCleaner and Eraser immediately following data exfiltration. These tools were installed on March 25, after the March 24 data staging. Eraser is designed for secure file deletion beyond forensic recovery. CCleaner cleans browser history, registry, temporary files, and system traces. The execution timing on the same day as the resignation letter indicates this was intentional cleanup as part of a planned departure, constituting evidence tampering and obstruction of justice.
Multiple Administrator Account Creation
Medium severity findings reveal that three additional administrator accounts (admin11, ITechTeam, temporary) were created by the informant account within 30 minutes of the informant account creation. While the admin11 account was used at least once (Notepad execution), the ITechTeam and temporary accounts show no evidence of interactive use. The creation of multiple admin accounts could indicate preparation for lateral movement with alternative credentials, plausible deniability through activity attribution to different accounts, backdoor access maintenance, or isolated contexts for exfiltration activities.
The absence of 4624 (successful logon) events for these accounts in security logs may indicate audit policy gaps, log clearing, or login via methods not generating 4624 events. The admin11 UserAssist entry proves at least minimal account usage.
Threat Intelligence and Attribution
Attribution Confidence: High for Insider Threat, Uncertain for External Collaboration
The evidence conclusively identifies Iaman Informant (iaman.informant@nist.gov) as the insider threat actor. Attribution is established through: email addresses in PC email data (iaman.informant@nist.gov, Exchange Labs identifier, Outlook profile), resignation letter naming the individual, consistent "IAMAN" naming across USB volume label "IAMAN $_@", optical media "IAMAN CD," and email identity.
The actor's NIST employment status makes this an insider threat incident with potential national security implications. As a federal employee, the user had trust and access privileges that were exploited for unauthorized removal of government documents.
Behavioral Indicators
The actor demonstrated sophisticated operational security awareness including: multi-channel redundancy (USB plus optical plus cloud), file extension masquerading to bypass DLP, timestamp manipulation to hide activity timing, anti-forensic tool deployment for evidence destruction, cloud sync database deletion to hide exfiltration volume, and progressive web search query refinement indicating research intent.
Potential External Collaboration Uncertainty
While the evidence proves insider threat activity conclusively, determination of external collaboration or foreign intelligence involvement requires additional investigation. The targeting of Executive Office of the President and Library of Congress documents by a NIST employee suggests potential awareness of sensitive government workflows, but no direct evidence of external direction or coordination was recovered. The personal email address (wayne.longman@att.net) and personal Gmail account (iaman.informant.personal@gmail.com) found in evidence could indicate external communication channels, but this requires further investigation of email content and cloud account activity.
The attribution confidence remains high for insider threat activity but uncertain regarding potential external collaboration.
Impact Assessment
Scope of Compromise
One PC system was actively used for data exfiltration activities by a single identified insider threat actor. The user account was created on March 22, 2015, and remained active for four days. Three additional administrator accounts were created, with one confirmed used and two showing no interactive use evidence.
Data at Risk
Seventeen files totaling approximately 85-90 MB were staged on removable media and potentially uploaded to cloud storage. Document metadata indicates Executive Office of the President (OMB/EOP) and Library of Congress email addresses were embedded in exfiltrated files. Content includes design documents, pricing information, proposals, progress reports, and technical reviews.
The data flow was: rm1 ("Authorized USB," source files) → PC (processing/obfuscation) → rm2 (USB, March 24 morning) AND rm3_type3 (optical, March 24 evening) AND Google Drive (cloud, status unknown due to database deletion). The deletion of Google Drive sync databases prevents determination of whether cloud exfiltration was successful and which specific files were uploaded.
Credential Exposure
Four user accounts with administrator privileges were created. Password reset activities were performed on all three additional accounts. If passwords were weak or shared externally, these accounts represent persistent access vectors even after the primary account was disabled.
Persistence Depth
No evidence of remote access tools, backdoors, or persistent malware was identified. The multi-account creation represents the primary persistence mechanism, potentially allowing backdoor access if not disabled. The activity window of four days with resignation letter creation suggests a deliberate exit strategy with no intention of persistent system access.
Business and Legal Impact
This incident represents: unauthorized removal of government records (potential federal crime), theft of intellectual property potentially containing Executive Office of the President information, violation of NIST security policies, evidence tampering and obstruction through anti-forensic tool deployment, and potential national security implications depending on document classification level.
The resignation timing correlated with exfiltration activities suggests premeditated departure with data theft, indicating this was not opportunistic but planned.
Immediate Tactical Containment
The following actions must be taken immediately to contain this incident:
-
Disable all user accounts created by informant: Immediately disable the accounts "informant," "admin11," "ITechTeam," and "temporary" on the affected PC and any domain-wide systems where these accounts may have propagated.
-
Isolate the affected PC system: Disconnect the PC from the network immediately to prevent any potential further data transmission or remote access.
-
Secure removable media: The USB drives rm1 ("Authorized USB"), rm2 ("IAMAN $_@"), and optical disc rm3_type3 ("IAMAN CD") must be secured as evidence. Do not connect these to other systems.
-
Block cloud exfiltration channel: Immediately revoke access to the Google Drive account configured with the sync folder at Users\informant\Google Drive. Initiate legal process to preserve and obtain Google Drive logs and stored data for the account.
-
Preserve email communications: Preserve all email communications for iaman.informant@nist.gov and iaman.informant.personal@gmail.com. Review communications for external collaboration indicators.
-
SanDisk Cruzer Fit USB investigation: Investigate the SanDisk Cruzer Fit USB device connected at 18:31:10 UTC on March 23. This device was connected 7 minutes before source file access began and may contain additional evidence.
-
Review file access logs for source documents: Examine fileserver logs for the "Secret Project Data" directory to identify all files accessed and determine if additional files beyond the identified 17 were exfiltrated.
-
Cloud storage account audit: Audit the user's Gmail account (iaman.informant.personal@gmail.com) and any other personal cloud storage accounts for uploaded government data.
Strategic Remediation
Root Cause 1: Insider Threat Detection Gap
The user was able to access sensitive government documents labeled "Secret Project Data," exfiltrate them over three days, and perform anti-forensic cleanup without triggering alerts. The absence of alerts for large-scale file staging, USB device usage, and cloud storage installation indicates insufficient insider threat monitoring.
Remediation: Deploy User and Entity Behavior Analytics (UEBA) to detect anomalous file access patterns, USB device usage, and cloud service installations. Specifically, configure alerts for: USB device connections by users with access to sensitive documents, installation of cloud storage clients on government systems, bulk file operations exceeding threshold volumes within short time windows, and execution of anti-forensic tools (CCleaner, Eraser) on any government system.
Root Cause 2: Data Loss Prevention Circumvention
Files were successfully renamed with media extensions (.jpg, .png, .avi, .amr) to bypass DLP controls. This indicates DLP rules were based on file extensions rather than content inspection or file signature analysis.
Remediation: Implement content-aware DLP that analyzes file payloads rather than extensions. Configure DLP to inspect for Office document signatures (DOCX, XLSX, PPTX, OLE compound documents) regardless of file extension. Block transfer of files with signature/extension mismatches to removable media or cloud services.
Root Cause 3: Privilege Management Weakness
A single user account was able to create three additional administrator accounts within 30 minutes without triggering approval workflows or generating alerts. This violates principle of least privilege.
Remediation: Implement Privileged Access Management (PAM) requiring approval workflows for administrator account creation. Configure alerts for any account creation by non-IT personnel. Restrict local administrator group membership to approved service accounts and documented IT staff.
Root Cause 4: Removable Media Controls Absent
USB drives were connected and used for staging government data without restriction. The volume labels "IAMAN $_@" and "Authorized USB" suggest the user was aware of and potentially circumventing media policies.
Remediation: Deploy USB device control using Device Control or similar solutions. Restrict USB access to approved encrypted devices only. Block write access to unapproved removable media on systems with access to sensitive documents.
Root Cause 5: Cloud Service Controls Insufficient
Google Drive was installed and synchronized government data without detection. The deleted sync databases indicate the user understood how to cover tracks.
Remediation: Block consumer cloud storage services (Google Drive, Dropbox, iCloud, OneDrive personal) at the network perimeter. Implement SSL inspection to detect unauthorized cloud service usage. Configureendpoint DLP to block sync client installations for unapproved cloud services.
Root Cause 6: Offboarding Security Gap
No evidence indicates the user's access was proactively revoked or monitored during the resignation period. The correlation between resignation timing and data exfiltration suggests the departure was anticipated without security escalation.
Remediation: Implement offboarding security protocols including: immediate access revocation upon resignation notification, enhanced monitoring for 30 days prior to departure for sensitive positions, mandatory exit interview with IT security review of system activity, and forensic imaging of departure-day activities for positions with sensitive access.
Conclusion
Q1. What systems were compromised?
One Windows 7 PC system was used as the primary exfiltration workstation. Three additional user accounts with administrator privileges (admin11, ITechTeam, temporary) were created on this system. The investigation found no evidence of compromise on other systems, no malware deployment, and no remote access tools installed. The compromise was limited to the insider threat actor's deliberate use of assigned workstation resources.
Q2. How did the attacker gain initial access?
This was an insider threat incident, not an external attack. The actor was a legitimate NIST employee (iaman.informant@nist.gov) with authorized access to the PC system. The user account was created on March 22, 2015, through standard provisioning. Initial access was legitimate employment-based access. No exploitation or credential theft was required.
Q3. What lateral movement occurred?
No traditional lateral movement to other systems was identified. However, the actor created three additional administrator accounts (admin11, ITechTeam, temporary) within the first 30 minutes of account creation. Only admin11 showed evidence of use (Notepad execution at 15:57:30 UTC on March 22). The creation of multiple admin accounts suggests preparation for potential lateral movement or establishing alternative access pathways.
Q4. What persistence mechanisms were installed?
No malware, remote access tools, or technical backdoors were installed. The primary persistence mechanism was the creation of multiple administrator accounts that could provide continued access if the primary account was disabled. The short activity window (four days) with resignation letter creation on the final day indicates the actor had no intention of persistent access—this was a departure time-limited data theft operation, not a long-term access strategy.
Q5. Was data exfiltrated, and if so, what and how much?
Yes. Seventeen files totaling approximately 85-90 MB were confirmed staged on removable media (USB rm2 and optical rm3_type3). Files included design documents, pricing materials, proposals, progress reports, and technical reviews disguised with media file extensions. Document metadata contained Executive Office of the President (OMB/EOP) and Library of Congress email addresses, indicating potential government intellectual property. Cloud exfiltration via Google Drive is highly probable based on sync activity timing, but the specific files uploaded cannot be determined due to sync database deletion. The total exfiltration scope may be larger if additional files were uploaded to cloud storage before database deletion.
Q6. What is the full timeline of the incident?
The complete timeline spans March 22-25, 2015:
-
March 22, 2015: User account created at 14:34:41 UTC. Three additional administrator accounts created between 15:51-15:53 UTC. User researches data leakage and forensic evasion topics via web browser.
-
March 23, 2015: SanDisk USB connected at 18:31:10 UTC. Source files accessed from "Authorized USB" (rm1) beginning at 18:38:21 UTC. Google Drive installed 20:02-20:05 UTC. Additional project file accessed at 20:27:33 UTC.
-
March 24, 2015: Data staging on USB rm2 at 09:59:27-10:00:18 UTC (51 seconds for 17 files). Optical media created at approximately 20:55 UTC. All 17 files disguised with media extensions.
-
March 25, 2015: Timestamp manipulation at 11:08:36 UTC. Anti-forensic tools installed 14:46-14:50 UTC. CCleaner and Eraser executed 14:57-15:15 UTC. Google Drive sync executed 15:21 UTC. Resignation letter created 15:28 UTC.
Total operational duration: 3 days from account creation to resignation.
Q7. What is the total scope and business impact?
One PC system with four administrator accounts. Seventeen known files staged on removable media, with cloud exfiltration probability high but undetermined. Document metadata indicates potential Executive Office of the President and Library of Congress involvement, suggesting possible national security implications. The insider threat actor's deliberate evidence destruction indicates consciousness of wrongdoing. Legal exposure includes potential federal crimes (theft of government property, unauthorized removal of records, evidence tampering). The correlation with resignation indicates premeditated data theft as part of an exit strategy, representing a breakdown in offboarding security controls for positions with sensitive access.
Q8. What are the recommended remediation actions?
Immediate containment actions are detailed in the Tactical Containment section above. Strategic remediation for each identified root cause includes: deploying User and Entity Behavior Analytics for insider threat detection, implementing content-aware DLP with file signature inspection rather than extension-based rules, establishing Privileged Access Management with approval workflows for administrator account creation, deploying USB device control to restrict removable media access, blocking consumer cloud storage services at the network perimeter, and implementing offboarding security protocols including proactive access revocation and enhanced monitoring. Each remediation directly addresses specific failures observed in this incident—failure to detect insider threat behavior, failure to prevent DLP circumvention through file masquerading, failure to control administrator privilege proliferation, failure to restrict removable media, failure to block unauthorized cloud storage, and failure to secure the departure process.
Attack Timeline
Findings
Government email address Eric_P._Lauer@omb.eop.gov (Office of Management and Budget, Executive Office of the President) was found on rm2 USB drive. This email appears in document metadata embedded within the exfiltrated files. Additional email addresses found include wayne.longman@att.net (personal) and mmun@loc.gov (Library of Congress).
The presence of OMB/EOP email addresses on a removable USB drive suggests potential exfiltration of US Government documents. Email addresses were extracted from file metadata by bulk_extractor and are embedded in the exfiltrated documents. The Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) and email subjects referencing historical photograph catalogs indicate Library of Congress content was also exfiltrated.
Evidence Chain
Web browsing evidence reveals the suspect was actively researching data leakage methods and forensic detection before and during the exfiltration:
Data Leakage Research:
- SANS whitepaper: "data-leakage-threats-mitigation-19312"
- Google search: "information leakage cases"
- News article: "Google to settle data leakage case for $85 million"
- Article: "Top 5 sources leaking personal data" (Emirates 24/7)
Confidential Information Leakage Research:
- Google searches for "leaking confidential information" with progressive query refinement:
- "leaking confidenti"
- "leaking confidential i"
- "leaking confidential informat"
- "leaking confidential information"
Forensic Countermeasure Research:
- "Tools:Data_Recovery" page on ForensicsWiki
- Microsoft Research paper: "leak_secret.pdf"
- Search for "system cleaner"
Cloud Storage Access:
- "https://www.google.com/drive/"
- "https://www.google.com/drive/download/"
This evidence proves the suspect had intent to leak confidential information and researched methods to avoid detection. The progression of search queries shows deliberate planning, not accidental data handling. The research into forensic tools suggests awareness of potential investigation.
Evidence Chain
Timeline of user activity demonstrates a deliberate data exfiltration sequence:
2015-03-23:
- 20:02:43 - 20:05:32 UTC: Google Drive desktop client installed and configured
- 20:05:32 UTC: Google Drive sync folder created at Users\informant\Google Drive
- 20:26:52 UTC: Excel application accessed
- 20:27:33 UTC: LNK file created for [secret_project]_final_meeting.pptx (evidence of secret project file access)
- 20:32:44 UTC: Apple iCloud software logs created (another potential cloud exfiltration channel)
2015-03-24:
- 09:59:27 - 10:00:18 UTC: 17 files disguised with media extensions created on removable media (rm2, volume "IAMAN $_@") in $OrphanFiles directory. All files marked as deleted.
- 13:21:17 - 21:07:21 UTC: Active web browsing via Chrome (multiple cache files updated throughout the day)
- Multiple Chrome cache entries for drive.google.com, docs.google.com, and mail.google.com
- Evidence of Google Drive sharing activity
2015-03-25:
- 15:21:34 - 15:21:36 UTC: Google Drive lockfile last modified (final sync activity)
The sequence shows: (1) install cloud storage tools, (2) access secret project files, (3) disguise documents as media files and copy to USB, (4) continue accessing cloud services. This methodical approach indicates deliberate preparation for data exfiltration.
Evidence Chain
The user "informant" has been conclusively identified as Iaman Informant, an employee of the National Institute of Standards and Technology (NIST), based on multiple corroborating evidence sources:
Email Address Evidence:
- Primary email: iaman.informant@nist.gov (found in PC email data via bulk_extractor)
- Exchange Labs identifier: 1b788828-c8a2-4681-bf6f-b1df9935415b@nist.gov
- Outlook profile: iaman.informant@nist.gov.ost
Document Evidence:
- Resignation letter: "Resignation_Letter_(Iaman_Informant).docx" (created 2015-03-25)
- Resignation letter XPS version: "Resignation_Letter_(Iaman_Informant).xps"
- Documents accessed on 2015-03-25 (last day of activity)
Government Data Theft Context:
The user's NIST employment status makes the theft of US Government documents (OMB/EOP, Library of Congress) particularly significant. As a federal employee, the user had trust and access privileges. The exfiltration of documents containing email addresses from the Office of Management and Budget (Executive Office of the President) and Library of Congress from a NIST employee's system suggests potential insider threat compromise or unauthorized transfer of government intellectual property.
Timeline Correlation:
- User created on 2015-03-22
- Active for only 4 days (March 22-25)
- Resignation letter suggests planned departure
- Data exfiltration occurred during final days of employment/tenure
Evidence Chain
The UDF write-once optical media (volume label 'IAMAN CD') contains 9 VAT (Virtual Allocation Table) sessions (generations) indicating multiple burn sessions. The disc shows evidence of directory renaming and file deletion across sessions to hide the original directory structure:
Original Directory Names (Session 7 and earlier):
- /design
- /pricing decision
- /progress
- /proposal
- /technical review
Abbreviated Directory Names (Session -1):
- /de (design)
- /pd (pricing decision)
- /prog (progress)
- /prop (proposal)
- /tr (technical review)
Currently Present Files (Session 0):
- /Koala.jpg (780,831 bytes) - Created: 2015-03-24
- /Penguins.jpg (777,835 bytes) - Created: 2015-03-24
- /Tulips.jpg (620,888 bytes) - Created: 2015-03-24
Deleted Files (Recoverable from Earlier Sessions):
Session -1 (Most recent deletions):
- /de/winter_storm.amr (14.5 MB)
- /de/winter_whether_advisory.zip (16.3 MB)
- /pd/my_favorite_cars.db (1.3 MB)
- /pd/my_favorite_movies.7z (100 KB)
- /pd/new_years_day.jpg (10.2 MB)
- /pd/super_bowl.avi (10.3 MB)
- /prog/my_friends.svg (58 KB)
- /prog/my_smartphone.png (4.4 MB)
- /prog/new_year_calendar.one (27 KB)
- /prop/a_gift_from_you.gif (35.2 MB) - LARGEST FILE
- /prop/landscape.png (6.5 MB)
- /tr/diary_#1d.txt (121 KB)
- /tr/diary_#1p.txt (458 KB)
- /tr/diary_#2d.txt (659 KB)
- /tr/diary_#2p.txt (1.2 MB)
- /tr/diary_#3d.txt (2.4 MB)
- /tr/diary_#3p.txt (325 KB)
The directory renaming and file deletion pattern across multiple sessions indicates an attempt to obscure the original document structure. The current session (0) only contains 3 image files, while earlier sessions contained 17+ files that were progressively deleted.
File modification timestamps range from December 2014 to January 2015, suggesting the original files were created over a 2-month period before being collected and burned to disc on March 24, 2015.
Merged findings:
- Mass File Masquerading on Optical Media - Systematic Data Obfuscation (f_1e67a48f, high, confirmed): 17 files on the UDF optical media (volume label 'IAMAN CD') have been systematically renamed with misleading file extensions to hide their true content type. This indicates deliberate data obfuscation consistent with data exfiltration preparation.
Key Findings:
All masqueraded files are in deleted directories from earlier VAT sessions but remain fully recoverable:
Word Documents (.docx) disguised as:
- my_smartphone.png (4.4 MB)
- new_year_calendar.one (27 KB)
- a_gift_from_you.gif (35.2 MB) - VERY LARGE
- landscape.png (6.5 MB)
- diary_#1d.txt (121 KB)
- diary_#2d.txt (659 KB)
Excel Spreadsheets (.xlsx) disguised as:
- my_favorite_movies.7z (100 KB)
- new_years_day.jpg (10.2 MB)
PowerPoint Files (.pptx) disguised as:
- winter_whether_advisory.zip (16.3 MB)
- diary_#1p.txt (458 KB)
OLE Compound Documents disguised as:
- winter_storm.amr (14.5 MB) - disguised as audio
- my_favorite_cars.db (1.3 MB) - disguised as database
- super_bowl.avi (10.3 MB) - disguised as video
- my_friends.svg (58 KB) - disguised as SVG image
- diary_#2p.txt (1.2 MB)
- diary_#3d.txt (2.4 MB)
- diary_#3p.txt (325 KB)
The naming pattern suggests business/project documents (design, pricing decision, progress, proposal, technical review) disguised to appear as personal media files. File dates range from December 2014 to January 2015, with disc creation on March 24, 2015.
This systematic obfuscation technique is commonly used to bypass DLP (Data Loss Prevention) systems and evade detection during data exfiltration.
- Cross-Media Correlation - Optical Disc Links to USB Drives and User Identity (f_90fd8093, info, confirmed): The rm3_type3 optical media volume label "IAMAN CD" correlates with the rm2 USB volume label "IAMAN $_@" and the user account name "iaman.informant@nist.gov". This naming consistency across multiple pieces of evidence (removable USB drives rm2 and rm3_type3, plus the user's NIST email identity) indicates a single actor is responsible for the data exfiltration activities.
Correlation Evidence:
- rm2 USB Drive: Volume label "IAMAN $_@"
- Contains 17 masqueraded files in $OrphanFiles
-
Files created 2015-03-24 09:59:27-10:00:18 UTC
-
rm3_type3 Optical Media: Volume label "IAMAN CD"
- Contains same 17 masqueraded files (deleted from earlier sessions)
- Shows evidence of multi-session data tampering
-
Files dating from December 2014 to January 2015
-
User Identity: iaman.informant@nist.gov
- NIST employee email address
- User account "informant" on PC
Significance:
The consistent "IAMAN" naming convention suggests the optical media (rm3_type3) was created by the same actor who prepared the USB drives. The optical media represents a redundant or fallback copy of the exfiltrated data, created using write-once UDF format which makes deletion attempts recoverable via VAT session analysis.
The correlation establishes that the same insider threat actor created multiple copies of the stolen data across different media types (USB flash drives and optical disc), indicating sophisticated data exfiltration planning and execution.
- Multi-Stage Data Exfiltration - USB and Optical Media Created 11 Hours Apart (f_d26a6832, critical, confirmed): Cross-system correlation of file creation timestamps reveals deliberate multi-stage exfiltration with redundant backup channels:
Stage 1 - USB Drive (rm2):
- 17 obfuscated files created on 2015-03-24 09:59:27-10:00:18 UTC
- Duration: 51 seconds for all files (rapid batch copy operation)
- Volume label: "IAMAN $_@"
- Files disguised with media extensions (.jpg, .png, .gif, .avi, .amr, .zip, .7z, .db, .txt)
Stage 2 - Optical Media (rm3_type3):
- Same 17 obfuscated files created on 2015-03-24 20:55:43 UTC
- ~11 hours AFTER USB creation (evening vs. morning)
- Volume label: "IAMAN CD"
- UDF write-once format with 9 VAT sessions
- Files progressively deleted across sessions (multi-session tampering)
Timeline Significance:
- Multi-stage approach indicates sophisticated planning
- Optical media created as redundant backup or alternative exfiltration channel
- ~11-hour gap suggests separate operational phases
- Same actor created both media (consistent "IAMAN" naming and identical file sets)
Data Flow:
rm1 ("Authorized USB", source files) → PC (processing/obfuscation) → rm2 (USB, morning) AND rm3_type3 (optical, evening)
The separate staging events demonstrate the actor's intent to create multiple copies of stolen data across different media types, ensuring data survivability and providing fallback exfiltration options.
Affected Systems: optical.listing, tsk.masquerade
Evidence Chain
US Government email addresses embedded in the metadata of exfiltrated documents indicate the stolen files contain or originated from sensitive US Government sources:
Government Email Addresses Found:
1. Eric_P._Lauer@omb.eop.gov
- Organization: Office of Management and Budget (OMB)
- Parent: Executive Office of the President (EOP)
- Context: Office of the President of the United States
- Source: Document metadata embedded within exfiltrated files
2. mmun@loc.gov
- Organization: Library of Congress (LOC)
- Context: Legislative branch digital content
- Related URLs: hdl.loc.gov/loc.pnp/acd.2a10339 (Library of Congress digital handle)
- Source: Email metadata and document properties
3. Wayne.Longman@att.net
- Personal email (AT&T domain)
- Source: Document metadata
Relationship to Secret Project Files:
- The government email addresses were embedded in the document properties/metadata of the exfiltrated files
- This indicates the documents were either:
a) Created by government employees and shared with the suspect
b) Received from government sources via email
c) Part of official government project documentation
Document Content Evidence:
- Library of Congress URLs (http://hdl.loc.gov/loc.pnp/acd.2a10339) in document content
- Email subjects referencing Library of Congress historical photograph catalogs
- Presence of OMB/EOP metadata in documents labeled as "Secret Project Data"
Significance:
1. Insider Threat Context: A NIST employee (iaman.informant@nist.gov) exfiltrating documents containing OMB/EOP and Library of Congress email metadata suggests unauthorized transfer of government intellectual property across federal agencies
-
Classification Level: Documents with Executive Office of the President metadata marked as "Secret Project Data" indicates potential classified or sensitive unclassified information
-
Attribution: The email addresses prove the documents originated from or passed through US Government systems before being stolen
-
Legal Implications: Unauthorized removal of documents containing Executive Office of the President and Library of Congress metadata constitutes potential federal crimes (theft of government property, unauthorized removal of records)
The exfiltration of documents with US Government email addresses from a NIST employee's system to personal removable media and cloud storage represents a significant insider threat incident with potential national security implications.
Evidence Chain
Seventeen files with deceptive file extensions were created on removable media (rm2, volume label "IAMAN $_@") on 2015-03-24 between 09:59:27 UTC and 10:00:18 UTC. All files are marked as deleted ($OrphanFiles). The files have media file extensions (.amr, .zip, .db, .7z, .jpg, .avi, .svg, .png, .one, .gif, .txt) but their actual file signatures indicate they are Microsoft Office documents (DOCX, XLSX, PPTX) or OLE compound files.
Files include:
- winter_storm.amr → OLE (14.5 MB)
- winter_whether_advisory.zip → PPTX (16.4 MB)
- my_favorite_cars.db → OLE (1.2 MB)
- my_favorite_movies.7z → XLSX (100 KB)
- new_years_day.jpg → XLSX (10.2 MB)
- super_bowl.avi → OLE (10.3 MB)
- a_gift_from_you.gif → DOCX (35.2 MB)
- diary_#1d.txt, diary_#2d.txt, diary_#3d.txt → DOCX/OLE
- diary_#1p.txt → PPTX
- diary_#2p.txt, diary_#3p.txt → OLE
- my_smartphone.png, new_year_calendar.one, landscape.png → DOCX
The files are organized in folders named: design, PRICIN~1 (Pricing?), progress, proposal, and TECHNI~1 (Technical?). This naming suggests corporate/business documents. The use of media file extensions to disguise documents is a clear indicator of data concealment for exfiltration.
Merged findings:
- Documents Renamed to Hide Contents on USB Drive (f_209cd841, high, confirmed): 17 files on rm2 USB drive exhibit extension/content mismatches, indicating deliberate obfuscation of Office documents. Files were renamed with media and archive file extensions to disguise their true content:
- winter_storm.amr → OLE format (14.5 MB)
- winter_whether_advisory.zip → PowerPoint (16.4 MB)
- my_favorite_cars.db → OLE format (1.3 MB)
- my_favorite_movies.7z → Excel (100 KB)
- new_years_day.jpg → Excel (10.2 MB)
- super_bowl.avi → OLE format (10.3 MB)
- my_friends.svg → OLE format (58 KB)
- my_smartphone.png → Word (4.4 MB)
- new_year_calendar.one → Word (27 KB)
- a_gift_from_you.gif → Word (35.2 MB)
- landscape.png → Word (6.5 MB)
- diary_#1d.txt → Word (121 KB)
- diary_#1p.txt → PowerPoint (458 KB)
- diary_#2d.txt → Word (659 KB)
- diary_#2p.txt → OLE format (1.2 MB)
- diary_#3d.txt → OLE format (2.4 MB)
- diary_#3p.txt → OLE format (325 KB)
All files are deleted and located in $OrphanFiles directories, indicating they were removed after being copied to the drive. This is consistent with data staging for exfiltration and anti-forensic cleanup.
Affected Systems: tsk.masquerade
Evidence Chain
USB drive rm1 with volume label "Authorized USB" contains the original source files that were subsequently obfuscated and exfiltrated to rm2. The drive contains a "Secret Project Data" directory with organized project materials:
Design folder:
- [secret_project]_design_concept.ppt
- [secret_project]_detailed_design.pptx
- [secret_project]_revised_points.ppt
Proposal folder:
- [secret_project]_detailed_proposal.docx
- [secret_project]_proposal.docx
- ~$ecret_project]_proposal.docx (Word temporary file, deleted)
The presence of a Word temporary file (~$ecret_project]_proposal.docx) indicates the proposal document was opened/edited on this drive. A duplicate directory structure exists under "RM#1/Secret Project Data/".
These are the source documents that were renamed with media file extensions and placed on rm2 for exfiltration. The naming convention "[secret_project]" indicates sensitive project materials were targeted for theft.
Evidence Chain
Google Drive client software was installed on the PC and configured for user "informant" on 2015-03-23 between 20:02:43-20:05:32 UTC. Evidence includes:
- Google Drive program files in Program Files (x86)\Google\Drive\ with language modules (installed 2015-02-19 and 2015-03-23)
- User data directory: Users\informant\AppData\Local\Google\Drive\user_default\ containing:
- sync_config.db, snapshot.db (deleted, track synced files)
- lockfile (last modified 2015-03-25 15:21:34, indicating active sync)
- com.google.drive.nativeproxy.json
- Sync folder: Users\informant\Google Drive\desktop.ini (created 2015-03-23 20:05:32, modified 2015-03-25 15:21:36)
- Downloaded installer: Users\informant\Downloads\googledrivesync.exe
The timing (installed one day before files were disguised on removable media on 2015-03-24) and the presence of sync databases suggest Google Drive was set up as a potential exfiltration channel. The lockfile modification on 2015-03-25 indicates Google Drive was actively syncing data until the investigation period.
Evidence Chain
Windows Recent Documents LNK files on the PC prove that the user "informant" accessed secret project files directly from removable media:
March 23, 2015 18:38:21 UTC - [secret_project]_design_concept.lnk
- Path: Users\informant\AppData\Roaming\Microsoft\Windows\Recent\
- This LNK file was created when the PowerPoint presentation was opened from the "Authorized USB" drive (rm1)
March 23, 2015 20:27:33 UTC - [secret_project]_final_meeting.pptx.lnk
- Path: Users\informant\AppData\Roaming\Microsoft\Windows\Recent\
- A second project file was opened approximately 2 hours later
The presence of these LNK files confirms that secret project files were accessed on the PC. The [secret_project]_design_concept.lnk corresponds to the file [secret_project]_design_concept.ppt found on rm1. Notably, [secret_project]_final_meeting.pptx is not present on rm1, suggesting additional project files may have existed or were deleted.
This establishes March 23 as the date of file access, with exfiltration occurring the following day (March 24) when obfuscated copies were created on rm2.
Merged findings:
- Access to Secret Project Files (f_8a9f7eba, high, confirmed): A Windows LNK (shortcut) file was created in the user's Recent documents folder on 2015-03-23 at 20:27:33 UTC pointing to a file named "[secret_project]_final_meeting.pptx". This LNK file at "Users\informant\AppData\Roaming\Microsoft\Windows\Recent[secret_project]_final_meeting.pptx.lnk" confirms the user accessed and opened a PowerPoint presentation related to the secret project.
This access occurred on the same day Google Drive was installed (2015-03-23) and one day before files were disguised and copied to removable media (2015-03-24), establishing a clear timeline of data access followed by exfiltration preparation.
Affected Systems: ez.mft
Evidence Chain
Cloud storage and synchronization tools were downloaded and installed, potentially for data exfiltration:
Google Drive:
- Client installed: Program Files (x86)\Google\Drive\
- Sync configuration: Users\informant\AppData\Local\Google\Drive\user_default\sync_config.db-shm (deleted)
- Snapshot database: Users\informant\AppData\Local\Google\Drive\user_default\snapshot.db (deleted)
- Certificate store: Users\informant\AppData\Local\Google\Drive\user_default\cacerts (deleted)
iCloud:
- Installer downloaded: Users\informant\Downloads\icloudsetup.exe
- Zone.Identifier present (downloaded from internet)
Google Drive Sync:
- Installer downloaded: Users\informant\Downloads\googledrivesync.exe
- Zone.Identifier present (downloaded from internet)
The presence of sync databases and their deletion suggests the suspect may have synchronized files to cloud storage and then attempted to remove evidence of the synchronization. The deleted status of Google Drive database files indicates anti-forensic cleanup.
Evidence Chain
Anti-forensic tools CCleaner and Eraser were downloaded, installed, and executed on 2015-03-25 after the data exfiltration events, indicating consciousness of guilt and attempted evidence destruction:
Installation Timeline (2015-03-25):
- 14:46:05 UTC - ccsetup504.exe (CCleaner installer) downloaded from Users\informant\Desktop\Download\
- 14:50:14 UTC - Eraser 6.2.0.2962.exe downloaded from Users\informant\Desktop\Download\
- 14:57:56 UTC - CCleaner installer executed (UserAssist entry)
- 15:12:28 UTC - Eraser executed (UserAssist entry)
- 15:15:50 UTC - CCleaner executed (UserAssist entry)
Significance:
- Tools were installed AFTER the data exfiltration on 2015-03-24
- Eraser is designed for secure file deletion beyond forensic recovery
- CCleaner cleans browser history, registry, temporary files, and system traces
- Execution on the same day as the resignation letter suggests intentional cleanup
- This constitutes evidence tampering and obstruction of justice
The installation and execution of these tools immediately following data exfiltration demonstrates the user's intent to destroy evidence of their activities.
Evidence Chain
User "informant" created three additional user accounts and granted them local administrator privileges on 2015-03-22, shortly after the "informant" account was created:
Account Creation Timeline:
1. 2015-03-22 14:33:54 - "informant" account added to Administrators group (by SYSTEM)
2. 2015-03-22 15:51:54 - "admin11" added to Administrators group by "informant"
3. 2015-03-22 15:52:10 - Password reset for "admin11" by "informant"
4. 2015-03-22 15:52:30 - "ITechTeam" added to Administrators group by "informant"
5. 2015-03-22 15:52:45 - Password reset for "ITechTeam" by "informant"
6. 2015-03-22 15:53:11 - Password reset for "temporary" by "informant"
Evidence from Security Event Logs (Hayabusa):
- Event ID 4732 (Member Added to Local Group) - Multiple instances
- Event ID 4724 (Password Reset By Admin) - Multiple instances
- All actions performed from SubjectLogonId: 0x224e3 (informant session)
User Accounts Involved:
- admin11 (SID: S-1-5-21-...-1001) - Administrator account with Chrome data
- ITechTeam (SID: S-1-5-21-...-1002) - Administrator account
- temporary (SID: S-1-5-21-...-1003) - Administrator account
Significance:
The creation of multiple admin accounts could indicate:
1. Preparation for lateral movement - Alternative credentials for evasion
2. Plausible deniability - Activity attribution to different accounts
3. Backdoor access - Maintaining access if primary account is disabled
4. Testing environment setup - Creating isolated contexts for exfiltration activities
All accounts have NTUSER.DAT registry hives extracted, confirming they were actively used profiles on this system.
Evidence Chain
Evidence from bulk_extractor domain analysis reveals access to multiple cloud storage platforms, with Google Drive actively configured for synchronization:
Cloud Storage Platforms Detected:
1. Google Drive (Primary exfiltration channel)
- drive.google.com
- docs.google.com
- Client installed: googledrivesync.exe (installed 2015-03-23)
- Sync databases: sync_config.db, snapshot.db (deleted)
- Active sync lockfile modified: 2015-03-25 15:21:34 UTC
- Microsoft OneDrive
- onedrive.live.com
- www.onedrive.com
- Accessed but no sync client installation detected
Google Drive Configuration Evidence:
- User data directory: Users\informant\AppData\Local\Google\Drive\user_default\
- Sync folder: Users\informant\Google Drive\
- desktop.ini created: 2015-03-23 20:05:32
- desktop.ini modified: 2015-03-25 15:21:36 (active during exfiltration window)
- Language modules and update components present
Data Transfer Indicators:
- The presence of snapshot.db indicates files were synced to cloud
- Lockfile indicates active Google Drive process
- Deleted sync databases (sync_config.db, snapshot.db) suggest cleanup attempts
- Timing coincides with USB data staging activities
Exfiltration Method:
The user likely used Google Drive to upload sensitive documents to a personal or external Google account, providing an alternative or additional exfiltration channel to the USB devices. The deleted sync databases are consistent with attempting to hide evidence of what files were uploaded to the cloud.
Evidence Chain
Google Drive was used as a third exfiltration channel beyond USB and optical media, with evidence of active synchronization followed by database deletion to hide traces:
Google Drive Installation and Configuration:
- Installed: 2015-03-23 20:02:43-20:05:32 UTC (one day before data staging)
- Sync folder created: Users\informant\Google Drive\desktop.ini (2015-03-23 20:05:32)
- Sync databases: sync_config.db, snapshot.db (BOTH DELETED)
Evidence of Active Sync:
1. UserAssist Execution: googledrivesync.exe executed on 2015-03-25 15:21:30Z
2. Lockfile Activity: Google Drive lockfile last modified 2015-03-25 15:21:34 UTC
3. Desktop.ini Modification: Google Drive folder modified 2015-03-25 15:21:36 UTC
Anti-Forensic Cleanup:
- sync_config.db (track synced files) - DELETED
- snapshot.db (record of synced files) - DELETED
- cacerts - DELETED
- Database deletion indicates intentional removal of sync history
Timeline Context:
- 14:57:56Z - CCleaner executed (1st run)
- 15:12:28Z - Eraser executed
- 15:15:50Z - CCleaner executed (2nd run)
- 15:21:30Z - Google Drive sync executed ← AFTER cleanup tools
- 15:28:33Z - Resignation letter created
Web Interface Evidence:
- drive.google.com and docs.google.com URLs in browser cache
- File sharing interface URLs: drive.google.com/sharing/share
- OAuth authentication scopes: www.googleapis.com/auth/drive.apps
Significance:
The installation timing (day before staging), active sync indicators, and subsequent database deletion strongly suggest Google Drive was used to upload exfiltrated files to a personal or external Google account. The deleted databases prevent forensic determination of which specific files were synced, but the timing and behavior are consistent with cloud-based exfiltration as an alternative to physical media transfer.
Exfiltration Channels Identified:
1. USB Drive (rm2) - Physical media
2. Optical Media (rm3_type3) - Physical media
3. Google Drive - Cloud exfiltration (EVIDENCE OF USE, CONTENT UNKNOWN)
Evidence Chain
A coordinated anti-forensic cleanup operation was executed on 2015-03-25, the same day as the resignation letter creation, indicating this was part of a planned exit strategy:
Cleanup Timeline (2015-03-25):
Phase 1 - Timestamp Manipulation (11:08:36 UTC)
- Root directory $STANDARD_INFORMATION timestamp backdated to 2009-07-14 (Windows installation date)
- Timestomping technique used to hide recent filesystem activity
- 2080 days discrepancy between SI and FN timestamps
Phase 2 - Tool Installation (14:46:05-14:50:14 UTC)
- 14:46:05Z - ccsetup504.exe executed (CCleaner installer)
- 14:50:14Z - Eraser 6.2.0.2962.exe executed (Eraser installer)
Phase 3 - Anti-Forensic Tool Execution (14:57:56-15:15:50 UTC)
- 14:57:56Z - CCleaner64.exe executed (1st run)
- 15:12:28Z - Eraser.exe executed (secure file deletion)
- 15:15:50Z - CCleaner64.exe executed (2nd run)
Phase 4 - Cloud Sync (15:21:30-15:21:36 UTC)
- 15:21:30Z - googledrivesync.exe executed
- 15:21:34Z - Google Drive lockfile modified
- 15:21:36Z - Google Drive folder updated
Phase 5 - Resignation Letter (15:28:33-15:29:08 UTC)
- 15:28:33Z - Resignation_Letter_(Iaman_Informant).xps created
- 15:29:08Z - Resignation_Letter_(Iaman_Informant).docx last accessed
Cleanup Targets:
- CCleaner: Browser history, temporary files, registry entries, system traces
- Eraser: Secure file deletion beyond forensic recovery
- Timestomping: Hide filesystem modification times
- Google Drive database deletion: Remove sync history evidence
Trigger Analysis:
The cleanup timing coincides with the resignation letter creation, indicating the anti-forensic measures were triggered by the planned departure/resignation event. The sequence (cleanup tools → cloud sync → resignation letter) suggests:
1. Clean local evidence
2. Sync final data to cloud
3. Submit resignation document
This coordinated timeline demonstrates consciousness of guilt and premeditated evidence destruction aligned with employment termination.
Evidence Chain
Timestomping detected on the PC system. One file exhibits evidence of timestamp manipulation where the $STANDARD_INFORMATION Created timestamp (2009-07-14 02:38:56) is significantly earlier than the $FILE_NAME Created timestamp (2015-03-25 11:08:36) by 2080 days (~5.7 years).
This technique is commonly used to make files appear older than they actually are, potentially to hide recent creation time and blend in with legitimate system files, or to establish a false timeline. The file path showing timestomping is the root directory ".", indicating potential manipulation of filesystem metadata at the root level.
Evidence Chain
Forensic timeline of data exfiltration activity reconstructed from file system evidence:
Phase 1 - Initial Setup (March 22, 2015):
- User profile "informant" created on PC at 14:34:41 UTC
- Email client (Windows Mail) and browser (Chrome) configured
Phase 2 - Source File Access (March 23, 2015):
- 18:38:21 - Opened [secret_project]_design_concept.ppt from rm1 USB drive
- 20:27:33 - Opened [secret_project]_final_meeting.pptx
- User accessed multiple secret project files from "Authorized USB" drive
Phase 3 - Data Staging and Obfuscation (March 24, 2015):
- 09:59:27 - First obfuscated file created on rm2 USB drive
- 09:59:27-10:00:18 - All 17 masqueraded files created on rm2 in ~51 seconds
- Files renamed: Office documents → media/archive extensions (.jpg, .png, .gif, .avi, .amr, .zip, .7z, .db, .txt)
- All files placed in $OrphanFiles as deleted entries
Phase 4 - Cleanup (March 25, 2015):
- 11:08:36 - Timestamp manipulation detected on PC root directory
- Government email metadata present in exfiltrated files
Total Duration: 3 days from profile creation to exfiltration completion.
Data Flow: rm1 ("Authorized USB") → PC → rm2 ("IAMAN $_@")
Exfiltrated Content: Secret Project Data including design concepts, detailed designs, and proposals containing US Government email addresses (OMB/EOP).
Evidence Chain
A SanDisk Cruzer Fit USB device was connected to the PC on 2015-03-23 at 18:31:10 UTC, as recorded in the Windows registry USBSTOR key. This timing correlates with:
- Same day as source file access: User opened [secret_project]_design_concept.ppt at 18:38:21 (7 minutes after USB connection)
- Same day as Google Drive installation: Google Drive installed on 2015-03-23
- One day before data obfuscation: Files disguised on rm2 USB on 2015-03-24
Registry Evidence:
- Key: ControlSet001\Enum\USBSTOR\Disk&Ven_SanDisk&Prod_Cruzer_Fit&Rev_2.01
- Last Written: 2015-03-23T18:31:10.573006
This USB device connection is the physical link between the source data (rm1 "Authorized USB") and the staging/obfuscation activities observed on the rm2 device. The timing establishes the user's physical access to removable storage during the critical period of data theft preparation.
Evidence Chain
The user "informant" created three additional administrator accounts on 2015-03-22. While security event logs show no 4624 (successful logon) events for these accounts, forensic analysis reveals the admin11 account was used at least once:
Account Creation Timeline (2015-03-22):
- 14:33:54 - "informant" added to Administrators group (by SYSTEM)
- 15:51:54 - "admin11" added to Administrators group by "informant"
- 15:52:10 - Password reset for "admin11" by "informant"
- 15:52:30 - "ITechTeam" added to Administrators group by "informant"
- 15:52:45 - Password reset for "ITechTeam" by "informant"
- 15:53:11 - Password reset for "temporary" by "informant"
Evidence of admin11 Account Use:
- 2015-03-22 15:57:30Z: NOTEPAD.EXE executed from admin11 UserAssist registry
- This proves the admin11 account was logged into and used interactively, despite absence of 4624 events in security logs
- The missing 4624 events may indicate audit policy gaps or log clearing
Login Evidence for Other Accounts:
- ITechTeam: No UserAssist or execution evidence found
- temporary: No UserAssist or execution evidence found
Revised Assessment:
The admin11 account was used at least once (Notepad execution), which undermines the theory that all three accounts were created solely as unused backdoors. However, the ITechTeam and temporary accounts show no evidence of use. The purpose of admin11's limited use (running Notepad ~4 minutes after the last password reset) is unclear - it could be:
1. A test to verify the account worked
2. Legitimate use
3. An attempt to obscure the account's true purpose (backdoor)
The creation of multiple admin accounts with at least minimal use of one account still suggests preparation for potential alternative access pathways.
Evidence Chain
A USB device (rm1) with volume label "Authorized USB" contains a directory structure named "Secret Project Data" with subdirectories including "Secret Project Data/design/" containing project files. The files were accessed starting 2015-03-23 18:38:21 UTC when the user opened [secret_project]_design_concept.ppt from this drive.
Directory Structure Found:
- Secret Project Data/design/ - Design documents (PPT, PPTX files)
- Secret Project Data/proposal/ - Proposal documents (DOCX files)
- Secret Project Data/pricing/ - Pricing documents (XLSX files)
- RM#1/Secret Project Data/ - Duplicate directory structure
Files Identified:
- [secret_project]_design_concept.ppt (accessed 2015-03-23 18:38:21)
- [secret_project]_detailed_design.pptx
- [secret_project]_revised_points.ppt
- [secret_project]_detailed_proposal.docx
- [secret_project]_proposal.docx (with temporary file ~$ecret_project]_proposal.docx, indicating it was opened/edited)
- (secret_project)_pricing_decision.xlsx
Significance:
The volume label "Authorized USB" may be an attempt to legitimize the device or could indicate it was provided as part of authorized work. However, the combination with disguised files on rm2 and Google Drive installation suggests the data was being exfiltrated. The presence of a Word temporary file indicates the proposal document was edited on this drive.
These source documents were subsequently renamed with media file extensions and placed on rm2 for exfiltration. The naming convention "[secret_project]" indicates sensitive project materials were targeted for theft.
Evidence Chain
The user accessed Google Drive via web browser in addition to the desktop client. Bulk_extractor found URLs including:
- https://drive.google.com/ (main Drive interface)
- https://docs.google.com/ (Google Docs interface)
- https://drive.google.com/sharing/share?subapp=10&shareProtocolVersion=2&theme=2&command=settings&shareUiType=default&authuser=0&client=desktop (file sharing interface)
- https://www.googleapis.com/auth/drive.apps and https://www.googleapis.com/auth/drive.apps.readonly (Google Drive API authentication scopes)
The sharing URL is particularly significant - it shows the user was actively configuring or using Google Drive's file sharing functionality. Combined with the Google Drive desktop client installation, this demonstrates the user had multiple pathways for data exfiltration via cloud storage.
The presence of mail.google.com URLs also indicates Gmail usage, which could have been another exfiltration channel.
Evidence Chain
MITRE ATT&CK Coverage
Indicators of Compromise
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
eric_p._lauer@omb.eop.gov |
US Government Email Address Found on Removable Media | |||
wayne.longman@att.net |
US Government Email Address Found on Removable Media | |||
mmun@loc.gov |
US Government Email Address Found on Removable Media | |||
iaman.informant@nist.gov |
NIST Employee Identity Confirmed - Iaman Informant | |||
1b788828-c8a2-4681-bf6f-b1df9935415b@nist.gov |
NIST Employee Identity Confirmed - Iaman Informant |
Evidence Browser
Evidence Sources
| Source Name | Extractor | Lines | Hash | Referenced By |
|---|---|---|---|---|
| tsk.partitions | sleuthkit | 9 | blake2b:83c0b87c... |
— |
| tsk.filelist | sleuthkit | 51 | blake2b:55fc9962... |
6 findings |
| tsk.masquerade | sleuthkit | 17 | blake2b:97440a18... |
4 findings |
| tsk.partitions | sleuthkit | 8 | blake2b:3eed10c8... |
— |
| tsk.partitions | sleuthkit | 10 | blake2b:67b9085f... |
— |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:3d44b8c0... |
— |
| bulk.domain | bulk_extractor | 264 | blake2b:c8b97b94... |
1 finding |
| bulk.duplicates | bulk_extractor | 9 | blake2b:9ba9de0c... |
— |
| bulk.email | bulk_extractor | 43 | blake2b:eb085c00... |
3 findings |
| bulk.rfc822 | bulk_extractor | 41 | blake2b:283d0ef9... |
2 findings |
| bulk.url | bulk_extractor | 288 | blake2b:d727c498... |
6 findings |
| bulk.url_services | bulk_extractor | 19 | blake2b:01e609ea... |
6 findings |
| ez.mft | eztools | 98918 | blake2b:e31e3377... |
5 findings |
| tsk.filelist | sleuthkit | 104709 | blake2b:171e0914... |
6 findings |
| tsk.filelist.p1 | sleuthkit | 93 | blake2b:5bdfadd3... |
6 findings |
| tsk.filelist | sleuthkit | 27 | blake2b:ae86d6dd... |
6 findings |
| tsk.masquerade | sleuthkit | 0 | blake2b:empty... |
4 findings |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:436e8d26... |
— |
| bulk.domain | bulk_extractor | 189 | blake2b:ae916b75... |
1 finding |
| bulk.duplicates | bulk_extractor | 9 | blake2b:bb406faf... |
— |
| bulk.exif | bulk_extractor | 20 | blake2b:d7c9e32a... |
— |
| bulk.url | bulk_extractor | 207 | blake2b:039de0b6... |
6 findings |
| bulk.url_services | bulk_extractor | 14 | blake2b:2eac1377... |
6 findings |
| bulk.wordlist | bulk_extractor | 131102 | blake2b:9d096226... |
— |
| bulk.wordlist_dedup_1 | bulk_extractor | 112437 | blake2b:afb1c64a... |
— |
| tsk.masquerade | sleuthkit | 3 | blake2b:42bb5e7d... |
4 findings |
| forensic.timestomping | timestomp_detector | 1 | blake2b:a8aad413... |
3 findings |
| composite.file_staging | composite | 578 | blake2b:2f05fb41... |
— |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:904f0355... |
— |
| bulk.domain | bulk_extractor | 403827 | blake2b:d56fb4e6... |
1 finding |
| bulk.duplicates | bulk_extractor | 6623 | blake2b:e799fb84... |
— |
| bulk.email | bulk_extractor | 6881 | blake2b:bac35c8e... |
3 findings |
| bulk.ether | bulk_extractor | 6 | blake2b:0825117f... |
— |
| bulk.exif | bulk_extractor | 794 | blake2b:c1c2b13e... |
— |
| bulk.jpeg | bulk_extractor | 9 | blake2b:efabc32f... |
— |
| bulk.rfc822 | bulk_extractor | 7326 | blake2b:8c3efa03... |
2 findings |
| bulk.url | bulk_extractor | 458564 | blake2b:e8cd927d... |
6 findings |
| bulk.url_facebook-address | bulk_extractor | 19 | blake2b:7fe55073... |
6 findings |
| bulk.url_searches | bulk_extractor | 155 | blake2b:b928562c... |
6 findings |
| bulk.url_services | bulk_extractor | 3681 | blake2b:f1dead12... |
6 findings |
| bulk.zip_carved | bulk_extractor | 22411 | blake2b:1a5d3360... |
— |
| registry.query.system | python-registry | 1 | blake2b:8639046c... |
1 finding |
| evtx.manifest | evtx-extract | 54 | blake2b:62bd3681... |
— |
| ez.shimcache | eztools | 307 | blake2b:1879f313... |
— |
| registry.system | regripper | 186 | blake2b:bbff9820... |
— |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.security | regripper | 69 | blake2b:6b7bf22c... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.system | regripper | 33492 | blake2b:e038c5c6... |
— |
| registry.system | regripper | 283 | blake2b:83a79d8c... |
— |
| registry.system | regripper | 283 | blake2b:5e405e71... |
— |
| registry.system | regripper | 5209 | blake2b:3a77cf33... |
— |
| registry.system | regripper | 199 | blake2b:4b1baf4d... |
— |
| registry.system | regripper | 199 | blake2b:70edbf72... |
— |
| hayabusa.alerts | hayabusa | 35 | blake2b:17620cb9... |
3 findings |
| registry.system | regripper | 381 | blake2b:070a4d56... |
— |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
— |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
— |
| registry.usrclass.admin11 | regripper | 11 | blake2b:26a43778... |
— |
| registry.ntuser.admin11 | regripper | 133 | blake2b:bf617a09... |
— |
| registry.ntuser.default | regripper | 74 | blake2b:8518dc3f... |
— |
| registry.usrclass.informant | regripper | 102 | blake2b:9f1344c3... |
— |
| registry.ntuser.informant | regripper | 306 | blake2b:597d71cd... |
5 findings |
| registry.usrclass.temporary | regripper | 15 | blake2b:3ef5eb22... |
— |
| registry.ntuser.temporary | regripper | 118 | blake2b:800424ee... |
— |
| registry.query.system | python-registry | 1 | blake2b:8639046c... |
1 finding |
| optical.listing | mulder-optical | 58 | blake2b:65ca19c0... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:9a158e59... |
— |
| bulk.domain | bulk_extractor | 7303 | blake2b:90c36187... |
1 finding |
| bulk.duplicates | bulk_extractor | 1738 | blake2b:481f17a5... |
— |
| bulk.email | bulk_extractor | 30 | blake2b:3fd4e07d... |
3 findings |
| bulk.exif | bulk_extractor | 21 | blake2b:c2dd544d... |
— |
| bulk.rfc822 | bulk_extractor | 41 | blake2b:e3da4d10... |
2 findings |
| bulk.url | bulk_extractor | 7204 | blake2b:bd98a868... |
6 findings |
| bulk.url_services | bulk_extractor | 60 | blake2b:787aa6dd... |
6 findings |
| bulk.zip_carved | bulk_extractor | 5221 | blake2b:769a57fa... |
— |
| composite.correlation | composite | 1 | blake2b:243b2a89... |
— |
| composite.timeline | composite | 172 | blake2b:6e15720e... |
— |
| composite.execution | composite | 122 | blake2b:fd78ddde... |
— |
| composite.defense_evasion | composite | 174 | blake2b:347306b8... |
— |
| composite.lateral_movement | composite | 441 | blake2b:3fa22e37... |
— |
| composite.persistence | composite | 2430 | blake2b:96f1e18f... |
1 finding |
| forensic.timestomping | timestomp_detector | 1 | blake2b:a8aad413... |
3 findings |
| composite.file_staging | composite | 578 | blake2b:1ac6dccb... |
— |
| composite.exfil | composite | 2496 | blake2b:866f0b45... |
— |
| composite.file_staging | composite | 578 | blake2b:1ac6dccb... |
— |
| forensic.timestomping | timestomp_detector | 1 | blake2b:a8aad413... |
3 findings |
| composite.defense_evasion | composite | 131 | blake2b:22ab360e... |
— |
| composite.execution | composite | 122 | blake2b:fd78ddde... |
— |
| composite.timeline | composite | 172 | blake2b:6e15720e... |
— |
| composite.persistence | composite | 2450 | blake2b:fb297bb8... |
1 finding |
| composite.lateral_movement | composite | 463 | blake2b:6426a7e6... |
— |
| composite.exfil | composite | 2514 | blake2b:12a05d1c... |
— |
| composite.correlation | composite | 1 | blake2b:243b2a89... |
— |
| composite.correlation | composite | 1 | blake2b:e6ffd218... |
— |
Investigation Performance
| Input Tokens | 8,856,848 |
| Output Tokens | 127,940 |
| Total Tokens | 8,984,788 |
| Per-Model Breakdown | |
| bedrock/zai.glm-5 | 8,984,788 |
Audit Trail
| ID | Tool | Duration | Timestamp | Actions |
|---|---|---|---|---|
| tc_699a435d | scan_evidence | 1996ms | 2026-09-20T05:41:41 | |
| tc_b52d6ba4 | list_sources | 2ms | 2026-09-20T05:41:56 | |
| tc_a67c6d50 | get_source_stats | 2ms | 2026-09-20T05:41:56 | |
| tc_6fb2cf4c | open_case | 29ms | 2026-09-20T05:42:17 | |
| tc_d64a58b7 | list_sources | 2ms | 2026-09-20T05:42:21 | |
| tc_9f1601dd | open_case | 26ms | 2026-09-20T05:42:27 | |
| tc_2f762a13 | open_case | 27ms | 2026-09-20T05:42:32 | |
| tc_5f8156f4 | open_case | 27ms | 2026-09-20T05:42:59 | |
| tc_43a83848 | start_extraction_batch | 7ms | 2026-09-20T05:43:08 | |
| tc_dc3c3051 | run_mmls | 46ms | 2026-09-20T05:43:08 | |
| tc_9c8b37e7 | run_fls | 998ms | 2026-09-20T05:43:09 | |
| tc_173dd6a2 | detect_masquerading | 1663ms | 2026-09-20T05:43:10 | |
| tc_f06d9e5a | open_case | 27ms | 2026-09-20T05:43:10 | |
| tc_a2f47fc6 | open_case | 28ms | 2026-09-20T05:43:24 | |
| tc_e5b3752e | run_mmls | 37ms | 2026-09-20T05:43:42 | |
| tc_60ed52e5 | run_mmls | 55ms | 2026-09-20T05:43:44 | |
| tc_4a60b7d0 | start_extraction_batch | 9ms | 2026-09-20T05:43:46 | |
| tc_417bf76c | run_bulk_extractor | 41540ms | 2026-09-20T05:43:50 | |
| tc_96b9a1db | run_mft_parser | 5506ms | 2026-09-20T05:43:51 | |
| tc_8e622e52 | get_completed_results | 0ms | 2026-09-20T05:43:54 | |
| tc_664001ab | run_fls | 10379ms | 2026-09-20T05:43:56 | |
| tc_c4238af7 | start_extraction_batch | 22ms | 2026-09-20T05:44:03 | |
| tc_72eeed73 | run_fls | 5086ms | 2026-09-20T05:44:08 | |
| tc_2082ca21 | detect_masquerading | 5900ms | 2026-09-20T05:44:09 | |
| tc_7f62424a | start_extraction_batch | 59ms | 2026-09-20T05:44:32 | |
| tc_ffbf5ccd | run_mft_parser | 163ms | 2026-09-20T05:44:32 | |
| tc_046d5318 | run_amcache_parser | 11769ms | 2026-09-20T05:44:44 | |
| tc_10a0c9e9 | query_registry_value | 0ms | 2026-09-20T05:44:44 | |
| tc_3935e010 | run_hayabusa | 18729ms | 2026-09-20T05:44:51 | |
| tc_7fdfa52e | query_registry_value | 0ms | 2026-09-20T05:44:51 | |
| tc_2d118a89 | run_shimcache_parser | 19043ms | 2026-09-20T05:44:51 | |
| tc_ff7bb274 | run_registry_parser | 20395ms | 2026-09-20T05:44:52 | |
| tc_b3c7b754 | run_prefetch_parser | 21422ms | 2026-09-20T05:44:53 | |
| tc_23f78628 | run_bulk_extractor | 81315ms | 2026-09-20T05:45:24 | |
| tc_dffdffb5 | get_completed_results | 0ms | 2026-09-20T05:45:26 | |
| tc_790545d9 | start_extraction_batch | 20ms | 2026-09-20T05:46:23 | |
| tc_33db27cd | run_registry_parser | 5838ms | 2026-09-20T05:46:29 | |
| tc_988f2308 | detect_masquerading | 300055ms | 2026-09-20T05:48:46 | |
| tc_d08e7a5c | run_mft_parser | 27ms | 2026-09-20T05:48:53 | |
| tc_612c8a44 | query_registry_value | 0ms | 2026-09-20T05:48:55 | |
| tc_50de725b | query_registry_value | 0ms | 2026-09-20T05:48:55 | |
| tc_ac99fa41 | start_extraction_batch | 4ms | 2026-09-20T05:48:55 | |
| tc_227e989c | run_shimcache_parser | 4138ms | 2026-09-20T05:48:57 | |
| tc_637dc5e4 | query_registry_value | 0ms | 2026-09-20T05:49:01 | |
| tc_5c7371d2 | run_prefetch_parser | 8691ms | 2026-09-20T05:49:02 | |
| tc_3bd45329 | run_evtx_parser | 0ms | 2026-09-20T05:49:03 | |
| tc_8d1248c4 | yara_scan_files | 8916ms | 2026-09-20T05:49:09 | |
| tc_521ca355 | get_completed_results | 0ms | 2026-09-20T05:49:10 | |
| tc_2ca147d8 | get_completed_results | 0ms | 2026-09-20T05:49:16 | |
| tc_cb446abb | start_extraction_batch | 3ms | 2026-09-20T05:49:18 | |
| tc_aa5088e5 | run_evtx_parser | 0ms | 2026-09-20T05:49:25 | |
| tc_a0b1c0b5 | open_case | 28ms | 2026-09-20T05:49:35 | |
| tc_e19ccce4 | wait_all | 0ms | 2026-09-20T05:49:35 | |
| tc_a31c5660 | wait_all | 0ms | 2026-09-20T05:49:41 | |
| tc_b70bc33b | get_completed_results | 0ms | 2026-09-20T05:49:51 | |
| tc_524fa834 | get_completed_results | 0ms | 2026-09-20T05:49:51 | |
| tc_5b04badb | open_case | 30ms | 2026-09-20T05:49:53 | |
| tc_f4b73478 | list_sources | 2ms | 2026-09-20T05:50:06 | |
| tc_62a7b95b | get_raw_output | 91ms | 2026-09-20T05:50:19 | |
| tc_656aeebd | get_raw_output | 14ms | 2026-09-20T05:50:19 | |
| tc_db63d356 | get_raw_output | 16ms | 2026-09-20T05:50:19 | |
| tc_4bd97e0f | search | 4ms | 2026-09-20T05:50:24 | |
| tc_a649188e | get_raw_output | 16ms | 2026-09-20T05:50:24 | |
| tc_2935f30c | search | 10ms | 2026-09-20T05:50:38 | |
| tc_efccf048 | search | 3ms | 2026-09-20T05:50:39 | |
| tc_5519a805 | search | 2ms | 2026-09-20T05:50:39 | |
| tc_04242fc6 | run_hayabusa | 1904ms | 2026-09-20T05:50:41 | |
| tc_826d49b7 | yara_scan_files | 5879ms | 2026-09-20T05:50:55 | |
| tc_ba60b083 | get_raw_output | 16ms | 2026-09-20T05:50:57 | |
| tc_f5ca191f | get_raw_output | 22ms | 2026-09-20T05:50:57 | |
| tc_1e991981 | get_raw_output | 21ms | 2026-09-20T05:50:57 | |
| tc_4f2e889c | open_case | 28ms | 2026-09-20T05:51:07 | |
| tc_3e8eddf5 | wait_all | 0ms | 2026-09-20T05:51:08 | |
| tc_e04fb8b5 | search | 4ms | 2026-09-20T05:51:18 | |
| tc_b8b2d545 | search | 3ms | 2026-09-20T05:51:19 | |
| tc_a19cf57d | open_case | 28ms | 2026-09-20T05:51:26 | |
| tc_8accecd7 | get_investigation_summary | 4ms | 2026-09-20T05:51:38 | |
| tc_bf1445a4 | list_sources | 1ms | 2026-09-20T05:51:38 | |
| tc_824f8bdb | get_raw_output | 19ms | 2026-09-20T05:51:44 | |
| tc_76e43792 | get_raw_output | 17ms | 2026-09-20T05:51:45 | |
| tc_221952ae | search | 5ms | 2026-09-20T05:51:45 | |
| tc_5fa1df33 | search | 3ms | 2026-09-20T05:51:47 | |
| tc_eabe8bb7 | search | 3ms | 2026-09-20T05:51:48 | |
| tc_9fa0973a | get_raw_output | 15ms | 2026-09-20T05:52:02 | |
| tc_a1e884b7 | search | 4ms | 2026-09-20T05:52:03 | |
| tc_8875f766 | search | 3ms | 2026-09-20T05:52:03 | |
| tc_4f3dc5b5 | get_raw_output | 17ms | 2026-09-20T05:52:10 | |
| tc_cb576a2f | get_raw_output | 17ms | 2026-09-20T05:52:10 | |
| tc_41b83054 | get_raw_output | 17ms | 2026-09-20T05:52:10 | |
| tc_04d037ef | search | 10ms | 2026-09-20T05:52:23 | |
| tc_addfb293 | get_raw_output | 16ms | 2026-09-20T05:52:24 | |
| tc_35815c39 | search | 4ms | 2026-09-20T05:52:28 | |
| tc_d9e9c2aa | search | 3ms | 2026-09-20T05:52:29 | |
| tc_0dc76182 | search | 3ms | 2026-09-20T05:52:29 | |
| tc_e2f6632f | search | 3ms | 2026-09-20T05:52:30 | |
| tc_150ac9db | detect_timestomping | 367ms | 2026-09-20T05:52:51 | |
| tc_d61ad05d | find_file_staging._search(tsk.filelist) | 3ms | 2026-09-20T05:52:51 | |
| tc_31109a7f | find_file_staging._search(ez.mft) | 3ms | 2026-09-20T05:52:51 | |
| tc_8bab2e3f | find_file_staging._query(tsk.filelist) | 32ms | 2026-09-20T05:52:51 | |
| tc_9eca078c | find_file_staging._query(ez.mft) | 139ms | 2026-09-20T05:52:51 | |
| tc_3affffd0 | find_file_staging._search(ez.mft) | 14ms | 2026-09-20T05:52:51 | |
| tc_69d4b4c2 | find_file_staging._search(ez.mft) | 2ms | 2026-09-20T05:52:51 | |
| tc_ef1d2df2 | find_file_staging | 554ms | 2026-09-20T05:52:51 | |
| tc_131ba178 | search | 5ms | 2026-09-20T05:53:08 | |
| tc_46820bc7 | get_raw_output | 14ms | 2026-09-20T05:53:09 | |
| tc_33a31851 | search | 3ms | 2026-09-20T05:53:28 | |
| tc_126c3910 | search | 3ms | 2026-09-20T05:53:29 | |
| tc_9344ac12 | get_timeline | 19ms | 2026-09-20T05:53:29 | |
| tc_1e77a73c | get_raw_output | 16ms | 2026-09-20T05:53:36 | |
| tc_262aaf44 | search | 2ms | 2026-09-20T05:53:36 | |
| tc_e4156052 | search | 7ms | 2026-09-20T05:53:45 | |
| tc_aa252ff3 | submit_finding | 18ms | 2026-09-20T05:53:59 | |
| tc_69dd57d1 | submit_finding | 16ms | 2026-09-20T05:54:02 | |
| tc_3aad1440 | search | 4ms | 2026-09-20T05:54:04 | |
| tc_26fda51a | search | 3ms | 2026-09-20T05:54:04 | |
| tc_c076492f | get_raw_output | 17ms | 2026-09-20T05:54:04 | |
| tc_468addc6 | submit_finding | 16ms | 2026-09-20T05:54:07 | |
| tc_a4fee2e3 | update_finding | 13ms | 2026-09-20T05:54:24 | |
| tc_28623724 | search | 3ms | 2026-09-20T05:54:43 | |
| tc_18aee01e | search | 3ms | 2026-09-20T05:54:43 | |
| tc_22299e09 | search | 10ms | 2026-09-20T05:54:48 | |
| tc_fc900623 | parse_mft | 19ms | 2026-09-20T05:54:49 | |
| tc_8287461a | get_raw_output | 17ms | 2026-09-20T05:55:04 | |
| tc_07fa12ee | get_raw_output | 3ms | 2026-09-20T05:55:04 | |
| tc_438fc665 | run_bulk_extractor | 695845ms | 2026-09-20T05:55:22 | |
| tc_30c3af7d | get_completed_results | 0ms | 2026-09-20T05:55:25 | |
| tc_55f4e3b2 | submit_finding | 12ms | 2026-09-20T05:55:37 | |
| tc_8efbe60b | start_extraction_batch | 12ms | 2026-09-20T05:55:47 | |
| tc_61f79ad9 | run_amcache_parser | 0ms | 2026-09-20T05:55:51 | |
| tc_5e4d4883 | submit_finding | 9ms | 2026-09-20T05:55:56 | |
| tc_d3a42665 | search | 3ms | 2026-09-20T05:55:57 | |
| tc_206a1296 | query_registry_value | 10035ms | 2026-09-20T05:55:57 | |
| tc_3b03ed18 | run_evtx_parser | 10352ms | 2026-09-20T05:55:57 | |
| tc_7cc840d2 | submit_finding | 9ms | 2026-09-20T05:55:58 | |
| tc_4126984f | run_shimcache_parser | 12382ms | 2026-09-20T05:55:59 | |
| tc_e4a13848 | run_prefetch_parser | 16043ms | 2026-09-20T05:56:03 | |
| tc_406d128d | submit_finding | 10ms | 2026-09-20T05:56:04 | |
| tc_43c7f39e | submit_finding | 9ms | 2026-09-20T05:56:07 | |
| tc_06ef94c9 | run_hayabusa | 21697ms | 2026-09-20T05:56:09 | |
| tc_d10164b3 | run_registry_parser | 34594ms | 2026-09-20T05:56:22 | |
| tc_8c2fcbb9 | search | 10ms | 2026-09-20T05:56:32 | |
| tc_989b08e7 | get_raw_output | 54ms | 2026-09-20T05:56:32 | |
| tc_e219fc0c | get_completed_results | 0ms | 2026-09-20T05:56:33 | |
| tc_81cf34d6 | update_finding | 7ms | 2026-09-20T05:56:47 | |
| tc_165692ec | open_case | 28ms | 2026-09-20T05:57:05 | |
| tc_0d4bc927 | wait_all | 0ms | 2026-09-20T05:57:05 | |
| tc_e032b475 | submit_finding | 7ms | 2026-09-20T05:57:14 | |
| tc_55751863 | open_case | 28ms | 2026-09-20T05:57:22 | |
| tc_8c8e48d7 | search | 4ms | 2026-09-20T05:57:23 | |
| tc_34ce987b | search | 4ms | 2026-09-20T05:57:24 | |
| tc_056038b2 | search | 4ms | 2026-09-20T05:57:24 | |
| tc_d34fbef5 | list_sources | 2ms | 2026-09-20T05:57:27 | |
| tc_841d04fe | get_investigation_summary | 3ms | 2026-09-20T05:57:27 | |
| tc_564da23e | get_findings | 1ms | 2026-09-20T05:57:45 | |
| tc_0980e9d7 | submit_finding | 9ms | 2026-09-20T05:57:50 | |
| tc_a0e68801 | search | 6ms | 2026-09-20T05:57:51 | |
| tc_0df850f6 | search | 17ms | 2026-09-20T05:57:51 | |
| tc_519d3d69 | get_raw_output | 53ms | 2026-09-20T05:58:00 | |
| tc_140b34d6 | search | 9ms | 2026-09-20T05:58:01 | |
| tc_c2269996 | search | 8ms | 2026-09-20T05:58:01 | |
| tc_537efe99 | search | 3ms | 2026-09-20T05:58:14 | |
| tc_56b744b2 | search | 4ms | 2026-09-20T05:58:14 | |
| tc_3d92516b | get_raw_output | 52ms | 2026-09-20T05:58:15 | |
| tc_a11949d5 | update_finding | 11ms | 2026-09-20T05:58:27 | |
| tc_3e83a341 | bookmark_window | 8ms | 2026-09-20T05:58:30 | |
| tc_896caf76 | bookmark_window | 5ms | 2026-09-20T05:58:31 | |
| tc_f9a1618b | query_registry_value | 4410ms | 2026-09-20T05:58:33 | |
| tc_9c5d9a2c | search | 56ms | 2026-09-20T05:58:33 | |
| tc_b4a22c0a | get_source_stats | 54ms | 2026-09-20T05:58:33 | |
| tc_16e21817 | submit_finding | 8ms | 2026-09-20T05:58:33 | |
| tc_75b0c75e | submit_finding | 10ms | 2026-09-20T05:58:47 | |
| tc_a6dc6cf9 | submit_finding | 10ms | 2026-09-20T05:58:52 | |
| tc_3794ac72 | submit_finding | 10ms | 2026-09-20T05:58:56 | |
| tc_626b7fa9 | get_timeline | 20ms | 2026-09-20T05:59:04 | |
| tc_a8ac9125 | get_raw_output | 53ms | 2026-09-20T05:59:04 | |
| tc_fd9a82be | search | 5ms | 2026-09-20T05:59:05 | |
| tc_e1caf2bd | update_finding | 13ms | 2026-09-20T05:59:25 | |
| tc_45ff9aa0 | update_finding | 13ms | 2026-09-20T05:59:27 | |
| tc_2b025482 | get_findings | 1ms | 2026-09-20T05:59:35 | |
| tc_c99f5847 | get_investigation_summary | 3ms | 2026-09-20T05:59:35 | |
| tc_dfd00177 | get_investigation_summary | 3ms | 2026-09-20T06:00:05 | |
| tc_15bc896f | get_findings | 1ms | 2026-09-20T06:00:05 | |
| tc_9e889b7a | submit_finding | 16ms | 2026-09-20T06:00:12 | |
| tc_38f635ae | track_progress | 13ms | 2026-09-20T06:00:13 | |
| tc_2cff599c | submit_finding | 17ms | 2026-09-20T06:00:28 | |
| tc_4290f7d5 | track_progress | 13ms | 2026-09-20T06:00:41 | |
| tc_7e120736 | submit_finding | 16ms | 2026-09-20T06:00:41 | |
| tc_a230bf15 | get_investigation_summary | 4ms | 2026-09-20T06:00:51 | |
| tc_23b4cf66 | submit_finding | 16ms | 2026-09-20T06:01:00 | |
| tc_8d77f00c | submit_finding | 18ms | 2026-09-20T06:01:07 | |
| tc_7e92d9e7 | open_case | 28ms | 2026-09-20T06:01:09 | |
| tc_47fc8bee | update_finding | 17ms | 2026-09-20T06:01:37 | |
| tc_14180b54 | get_findings | 1ms | 2026-09-20T06:01:37 | |
| tc_ed7bcf80 | get_investigation_summary | 4ms | 2026-09-20T06:01:40 | |
| tc_6830b959 | open_case | 28ms | 2026-09-20T06:01:50 | |
| tc_2d61aa5d | start_extraction_batch | 5ms | 2026-09-20T06:01:54 | |
| tc_4ceefe51 | run_optical_listing | 76ms | 2026-09-20T06:01:54 | |
| tc_d90f0d16 | get_investigation_summary | 3ms | 2026-09-20T06:02:04 | |
| tc_c55db226 | track_progress | 15ms | 2026-09-20T06:02:36 | |
| tc_2e10e0cc | run_bulk_extractor | 72642ms | 2026-09-20T06:03:07 | |
| tc_baa52dcd | get_completed_results | 0ms | 2026-09-20T06:03:13 | |
| tc_54a42515 | start_extraction_batch | 2ms | 2026-09-20T06:03:32 | |
| tc_2a026e22 | detect_masquerading | 0ms | 2026-09-20T06:03:32 | |
| tc_1fd7b89b | yara_scan_files | 5806ms | 2026-09-20T06:03:37 | |
| tc_82b40fdb | get_investigation_summary | 4ms | 2026-09-20T06:03:40 | |
| tc_a76ad205 | get_completed_results | 0ms | 2026-09-20T06:03:46 | |
| tc_a24d44a4 | open_case | 29ms | 2026-09-20T06:04:07 | |
| tc_58f54ace | list_sources | 3ms | 2026-09-20T06:04:16 | |
| tc_73fc34c7 | get_raw_output | 56ms | 2026-09-20T06:04:24 | |
| tc_3faa743a | search | 4ms | 2026-09-20T06:04:24 | |
| tc_88ed2319 | search | 3ms | 2026-09-20T06:04:45 | |
| tc_20382c42 | search | 3ms | 2026-09-20T06:04:45 | |
| tc_66d1eef9 | get_raw_output | 27ms | 2026-09-20T06:04:46 | |
| tc_2af02d27 | get_raw_output | 27ms | 2026-09-20T06:05:00 | |
| tc_0de9cb31 | get_raw_output | 21ms | 2026-09-20T06:05:00 | |
| tc_cd746815 | search | 9ms | 2026-09-20T06:05:06 | |
| tc_2498e1e8 | search | 3ms | 2026-09-20T06:05:07 | |
| tc_461e09f4 | get_raw_output | 26ms | 2026-09-20T06:05:07 | |
| tc_b8548498 | search | 6ms | 2026-09-20T06:05:18 | |
| tc_c7396f24 | get_raw_output | 26ms | 2026-09-20T06:05:18 | |
| tc_422c9198 | search | 26ms | 2026-09-20T06:05:19 | |
| tc_2dea3f74 | get_source_stats | 55ms | 2026-09-20T06:05:47 | |
| tc_3dee6118 | search | 3ms | 2026-09-20T06:05:48 | |
| tc_f01420c9 | search | 3ms | 2026-09-20T06:05:48 | |
| tc_e20b2092 | get_raw_output | 26ms | 2026-09-20T06:06:12 | |
| tc_43ae595b | search | 6ms | 2026-09-20T06:06:12 | |
| tc_416097be | detect_steganography | 1ms | 2026-09-20T06:06:12 | |
| tc_713626d9 | search | 4ms | 2026-09-20T06:06:23 | |
| tc_0676902a | search | 5ms | 2026-09-20T06:06:23 | |
| tc_e3ca2a2c | search | 8ms | 2026-09-20T06:06:24 | |
| tc_338fea05 | search | 5ms | 2026-09-20T06:06:48 | |
| tc_d49bc123 | search | 3ms | 2026-09-20T06:06:48 | |
| tc_d373923e | search | 21ms | 2026-09-20T06:06:49 | |
| tc_6b481885 | get_raw_output | 53ms | 2026-09-20T06:07:02 | |
| tc_75d91c9c | search | 25ms | 2026-09-20T06:07:02 | |
| tc_43459bde | bookmark_window | 11ms | 2026-09-20T06:07:51 | |
| tc_62de1393 | bookmark_window | 10ms | 2026-09-20T06:07:52 | |
| tc_7d993095 | submit_finding | 17ms | 2026-09-20T06:08:10 | |
| tc_99c814d0 | search | 5ms | 2026-09-20T06:08:38 | |
| tc_a1ae6c77 | submit_finding | 16ms | 2026-09-20T06:08:49 | |
| tc_2a28dbd4 | search | 5ms | 2026-09-20T06:08:49 | |
| tc_b64e2df5 | list_files | 200ms | 2026-09-20T06:09:07 | |
| tc_99ea5d50 | get_raw_output | 26ms | 2026-09-20T06:09:08 | |
| tc_64409a9d | search | 5ms | 2026-09-20T06:09:10 | |
| tc_60113f8f | get_investigation_summary | 3ms | 2026-09-20T06:09:35 | |
| tc_0dcec633 | search | 2ms | 2026-09-20T06:09:36 | |
| tc_298f76ef | search | 3ms | 2026-09-20T06:09:36 | |
| tc_0153cf7b | get_findings | 1ms | 2026-09-20T06:09:57 | |
| tc_a9fbb216 | search | 89ms | 2026-09-20T06:10:48 | |
| tc_d85f46d1 | track_progress | 13ms | 2026-09-20T06:10:59 | |
| tc_6ece7dd7 | submit_finding | 16ms | 2026-09-20T06:11:40 | |
| tc_5f7f5f8b | get_investigation_summary | 4ms | 2026-09-20T06:12:29 | |
| tc_9412b181 | open_case | 29ms | 2026-09-20T06:12:39 | |
| tc_df927df9 | get_findings | 2ms | 2026-09-20T06:12:46 | |
| tc_96f59a61 | get_investigation_summary | 4ms | 2026-09-20T06:12:46 | |
| tc_809192be | list_sources | 2ms | 2026-09-20T06:12:46 | |
| tc_69e47079 | get_source_stats | 54ms | 2026-09-20T06:12:46 | |
| tc_b60c4742 | get_bookmarks | 3ms | 2026-09-20T06:12:46 | |
| tc_bd95ea8e | get_findings | 2ms | 2026-09-20T06:12:52 | |
| tc_abb80b29 | get_timeline | 21ms | 2026-09-20T06:12:53 | |
| tc_323cf610 | open_case | 29ms | 2026-09-20T06:14:30 | |
| tc_135ca40a | reconstruct_execution_chains._query(volatility.pstree) | 51ms | 2026-09-20T06:14:49 | |
| tc_a91c2f38 | find_persistence_mechanisms._query(registry.system) | 56ms | 2026-09-20T06:14:49 | |
| tc_51c7b3cb | find_suspicious_processes._query(volatility.malfind) | 49ms | 2026-09-20T06:14:49 | |
| tc_22b3b78f | reconstruct_execution_chains._query(volatility.cmdline) | 17ms | 2026-09-20T06:14:49 | |
| tc_2cf80340 | find_lateral_movement_indicators._search(all) | 51ms | 2026-09-20T06:14:49 | |
| tc_04f25c68 | find_defense_evasion._search(all) | 72ms | 2026-09-20T06:14:49 | |
| tc_a6ecc5b7 | find_persistence_mechanisms._query(registry.software) | 10ms | 2026-09-20T06:14:49 | |
| tc_e1fe399b | find_suspicious_processes._query(volatility.cmdline) | 15ms | 2026-09-20T06:14:49 | |
| tc_9f5418e8 | find_file_staging._search(tsk.filelist) | 72ms | 2026-09-20T06:14:49 | |
| tc_cccc7069 | reconstruct_execution_chains._query(volatility.netscan) | 8ms | 2026-09-20T06:14:49 | |
| tc_8ceda4d6 | find_lateral_movement_indicators._search(all) | 3ms | 2026-09-20T06:14:49 | |
| tc_efe9a821 | find_defense_evasion._search(ez.mft) | 7ms | 2026-09-20T06:14:49 | |
| tc_de88806e | find_persistence_mechanisms._query(volatility.svcscan) | 7ms | 2026-09-20T06:14:49 | |
| tc_05e9b70f | find_suspicious_processes._query(volatility.netscan) | 6ms | 2026-09-20T06:14:49 | |
| tc_8e34714d | correlate_across_sources | 123ms | 2026-09-20T06:14:49 | |
| tc_e199b765 | reconstruct_execution_chains._query(volatility.malfind) | 7ms | 2026-09-20T06:14:49 | |
| tc_cba9bcaa | reconstruct_execution_chains | 150ms | 2026-09-20T06:14:49 | |
| tc_2358ccd8 | find_defense_evasion._search(all) | 6ms | 2026-09-20T06:14:49 | |
| tc_94f732e5 | find_persistence_mechanisms._search(all) | 6ms | 2026-09-20T06:14:49 | |
| tc_4e35d558 | find_file_staging._search(ez.mft) | 27ms | 2026-09-20T06:14:49 | |
| tc_82e668be | find_suspicious_processes._query(volatility.pstree) | 7ms | 2026-09-20T06:14:49 | |
| tc_ff3ec586 | find_lateral_movement_indicators._search(all) | 7ms | 2026-09-20T06:14:49 | |
| tc_c6d1c517 | analyze_execution_timeline._query(ez.shimcache) | 6ms | 2026-09-20T06:14:49 | |
| tc_620c5a0f | find_execution_evidence._query(ez.shimcache) | 6ms | 2026-09-20T06:14:49 | |
| tc_4b3a4396 | find_persistence_mechanisms._search(all) | 4ms | 2026-09-20T06:14:49 | |
| tc_95d4f1e7 | find_defense_evasion._search(all) | 12ms | 2026-09-20T06:14:49 | |
| tc_9f6f00f8 | find_suspicious_processes | 165ms | 2026-09-20T06:14:49 | |
| tc_8a371511 | analyze_execution_timeline | 39ms | 2026-09-20T06:14:49 | |
| tc_48c2fc9f | find_lateral_movement_indicators._query(volatility.netscan) | 7ms | 2026-09-20T06:14:49 | |
| tc_4470c0bb | find_execution_evidence | 34ms | 2026-09-20T06:14:49 | |
| tc_83a78398 | find_persistence_mechanisms._query(ez.shimcache) | 8ms | 2026-09-20T06:14:49 | |
| tc_9757a1b8 | find_defense_evasion._search(all) | 8ms | 2026-09-20T06:14:49 | |
| tc_3bc0f2d8 | find_lateral_movement_indicators._search(all) | 8ms | 2026-09-20T06:14:49 | |
| tc_0656a764 | find_defense_evasion | 223ms | 2026-09-20T06:14:49 | |
| tc_4f90b383 | find_persistence_mechanisms._search(all) | 8ms | 2026-09-20T06:14:49 | |
| tc_7ca4f122 | find_lateral_movement_indicators._search(all) | 4ms | 2026-09-20T06:14:49 | |
| tc_261b9f05 | get_eventlog_anomalies | 2ms | 2026-09-20T06:14:49 | |
| tc_c81edcc7 | get_userassist | 2ms | 2026-09-20T06:14:49 | |
| tc_1fbb7382 | parse_autoruns | 13ms | 2026-09-20T06:14:49 | |
| tc_046bd039 | find_lateral_movement_indicators._search(all) | 18ms | 2026-09-20T06:14:49 | |
| tc_67d08173 | find_lateral_movement_indicators | 273ms | 2026-09-20T06:14:49 | |
| tc_fdd4cd0e | find_file_staging._query(tsk.filelist) | 163ms | 2026-09-20T06:14:49 | |
| tc_4c544a32 | find_persistence_mechanisms._query(tsk.filelist) | 317ms | 2026-09-20T06:14:49 | |
| tc_71701c59 | find_persistence_mechanisms | 593ms | 2026-09-20T06:14:49 | |
| tc_4b060b74 | detect_timestomping | 793ms | 2026-09-20T06:14:50 | |
| tc_cac4863d | find_file_staging._query(ez.mft) | 739ms | 2026-09-20T06:14:50 | |
| tc_e6f94a9d | find_file_staging._search(ez.mft) | 14ms | 2026-09-20T06:14:50 | |
| tc_1eb83053 | find_file_staging._search(ez.mft) | 23ms | 2026-09-20T06:14:50 | |
| tc_d3a468d3 | find_file_staging | 1481ms | 2026-09-20T06:14:50 | |
| tc_7096d56c | find_data_exfiltration_indicators._query(bulk.url) | 1608ms | 2026-09-20T06:14:50 | |
| tc_0366323b | find_data_exfiltration_indicators._query(bulk.email) | 9ms | 2026-09-20T06:14:51 | |
| tc_30faf1d5 | find_data_exfiltration_indicators._query(bulk.domain) | 101ms | 2026-09-20T06:14:51 | |
| tc_101d1c3c | find_data_exfiltration_indicators._search(all) | 25ms | 2026-09-20T06:14:52 | |
| tc_a5c8884e | find_data_exfiltration_indicators | 2796ms | 2026-09-20T06:14:52 | |
| tc_12750b5c | get_completed_results | 0ms | 2026-09-20T06:14:54 | |
| tc_44238e23 | check_extraction_status | 0ms | 2026-09-20T06:14:55 | |
| tc_1adebbdb | get_userassist | 1ms | 2026-09-20T06:15:12 | |
| tc_0a8849df | reconstruct_execution_chains._query(volatility.pstree) | 8ms | 2026-09-20T06:15:14 | |
| tc_d690bf9e | reconstruct_execution_chains._query(volatility.cmdline) | 6ms | 2026-09-20T06:15:14 | |
| tc_d9b46792 | reconstruct_execution_chains._query(volatility.netscan) | 6ms | 2026-09-20T06:15:14 | |
| tc_27e83835 | reconstruct_execution_chains._query(volatility.malfind) | 6ms | 2026-09-20T06:15:14 | |
| tc_fc67cec2 | reconstruct_execution_chains | 43ms | 2026-09-20T06:15:14 | |
| tc_ed7499c4 | find_file_staging._search(tsk.filelist) | 23ms | 2026-09-20T06:15:14 | |
| tc_5a0c8f22 | find_file_staging._search(ez.mft) | 22ms | 2026-09-20T06:15:14 | |
| tc_dd511107 | find_file_staging._query(tsk.filelist) | 40ms | 2026-09-20T06:15:14 | |
| tc_20186c20 | find_file_staging._query(ez.mft) | 193ms | 2026-09-20T06:15:15 | |
| tc_96ec6053 | find_file_staging._search(ez.mft) | 14ms | 2026-09-20T06:15:15 | |
| tc_fbaab08f | find_file_staging._search(ez.mft) | 21ms | 2026-09-20T06:15:15 | |
| tc_0c79f412 | find_file_staging | 666ms | 2026-09-20T06:15:15 | |
| tc_ac68592e | detect_timestomping | 272ms | 2026-09-20T06:15:15 | |
| tc_f83996a3 | find_defense_evasion._search(all) | 5ms | 2026-09-20T06:15:15 | |
| tc_d8acde9c | find_defense_evasion._search(ez.mft) | 7ms | 2026-09-20T06:15:15 | |
| tc_5a4ecc56 | find_defense_evasion._search(all) | 4ms | 2026-09-20T06:15:15 | |
| tc_45108020 | find_defense_evasion._search(all) | 9ms | 2026-09-20T06:15:15 | |
| tc_ae277b06 | find_defense_evasion._search(all) | 3ms | 2026-09-20T06:15:15 | |
| tc_807f168b | find_defense_evasion | 49ms | 2026-09-20T06:15:15 | |
| tc_90f2d55b | find_execution_evidence._query(ez.shimcache) | 6ms | 2026-09-20T06:15:15 | |
| tc_877502d9 | find_execution_evidence | 12ms | 2026-09-20T06:15:15 | |
| tc_310775b9 | analyze_execution_timeline._query(ez.shimcache) | 6ms | 2026-09-20T06:15:15 | |
| tc_c3fbcf2e | analyze_execution_timeline | 11ms | 2026-09-20T06:15:15 | |
| tc_3d2dd68d | find_persistence_mechanisms._query(registry.system) | 14ms | 2026-09-20T06:15:23 | |
| tc_29ede4dd | find_persistence_mechanisms._query(registry.software) | 6ms | 2026-09-20T06:15:23 | |
| tc_c8a5d64c | find_persistence_mechanisms._query(volatility.svcscan) | 6ms | 2026-09-20T06:15:23 | |
| tc_0fdc4321 | find_persistence_mechanisms._search(all) | 6ms | 2026-09-20T06:15:23 | |
| tc_84c64389 | find_persistence_mechanisms._search(all) | 3ms | 2026-09-20T06:15:23 | |
| tc_aa96c737 | find_persistence_mechanisms._query(ez.shimcache) | 6ms | 2026-09-20T06:15:23 | |
| tc_9af92771 | find_persistence_mechanisms._search(all) | 5ms | 2026-09-20T06:15:23 | |
| tc_586d71d7 | find_persistence_mechanisms._query(tsk.filelist) | 35ms | 2026-09-20T06:15:23 | |
| tc_742c2006 | find_persistence_mechanisms | 143ms | 2026-09-20T06:15:23 | |
| tc_461416b9 | find_lateral_movement_indicators._search(all) | 16ms | 2026-09-20T06:15:24 | |
| tc_c3557a0f | find_lateral_movement_indicators._search(all) | 4ms | 2026-09-20T06:15:24 | |
| tc_0cbbe026 | find_lateral_movement_indicators._search(all) | 5ms | 2026-09-20T06:15:24 | |
| tc_8ce9d1bf | find_lateral_movement_indicators._query(volatility.netscan) | 6ms | 2026-09-20T06:15:24 | |
| tc_8c44fa38 | find_lateral_movement_indicators._search(all) | 4ms | 2026-09-20T06:15:24 | |
| tc_6c531e18 | find_lateral_movement_indicators._search(all) | 3ms | 2026-09-20T06:15:24 | |
| tc_736d7c12 | find_lateral_movement_indicators._search(all) | 5ms | 2026-09-20T06:15:24 | |
| tc_891889b2 | find_lateral_movement_indicators | 73ms | 2026-09-20T06:15:24 | |
| tc_e6850daf | find_data_exfiltration_indicators._query(bulk.url) | 446ms | 2026-09-20T06:15:25 | |
| tc_38e11941 | find_data_exfiltration_indicators._query(bulk.email) | 9ms | 2026-09-20T06:15:26 | |
| tc_c8464c4d | find_data_exfiltration_indicators._query(bulk.domain) | 103ms | 2026-09-20T06:15:26 | |
| tc_ac0e87ee | find_data_exfiltration_indicators._search(all) | 26ms | 2026-09-20T06:15:26 | |
| tc_0ab5e217 | find_data_exfiltration_indicators | 1584ms | 2026-09-20T06:15:26 | |
| tc_dad9acdb | find_suspicious_processes._query(volatility.malfind) | 8ms | 2026-09-20T06:15:26 | |
| tc_752edff9 | find_suspicious_processes._query(volatility.cmdline) | 6ms | 2026-09-20T06:15:26 | |
| tc_294197b2 | find_suspicious_processes._query(volatility.netscan) | 6ms | 2026-09-20T06:15:26 | |
| tc_db3ec810 | find_suspicious_processes._query(volatility.pstree) | 6ms | 2026-09-20T06:15:26 | |
| tc_09383eff | find_suspicious_processes | 41ms | 2026-09-20T06:15:26 | |
| tc_d5c93e1a | correlate_across_sources | 38ms | 2026-09-20T06:15:26 | |
| tc_543a3412 | parse_autoruns | 3ms | 2026-09-20T06:15:37 | |
| tc_cc99e9c8 | get_eventlog_anomalies | 1ms | 2026-09-20T06:15:38 | |
| tc_fa03bea1 | open_case | 30ms | 2026-09-20T06:16:05 | |
| tc_a08d5c21 | get_investigation_summary | 5ms | 2026-09-20T06:16:06 | |
| tc_e0a8c477 | get_findings | 2ms | 2026-09-20T06:16:12 | |
| tc_5f04d82b | get_raw_output | 56ms | 2026-09-20T06:16:23 | |
| tc_fafe386b | get_raw_output | 55ms | 2026-09-20T06:16:29 | |
| tc_591eaf00 | search | 7ms | 2026-09-20T06:16:36 | |
| tc_02f420f6 | search | 7ms | 2026-09-20T06:16:41 | |
| tc_de01af43 | search | 3ms | 2026-09-20T06:16:49 | |
| tc_38075eaa | search | 3ms | 2026-09-20T06:16:56 | |
| tc_5313802f | get_raw_output | 54ms | 2026-09-20T06:16:59 | |
| tc_6adcecfb | search | 8ms | 2026-09-20T06:17:15 | |
| tc_953117d0 | get_raw_output | 8ms | 2026-09-20T06:17:26 | |
| tc_7be86aeb | search | 3ms | 2026-09-20T06:17:48 | |
| tc_23aef311 | get_raw_output | 54ms | 2026-09-20T06:18:01 | |
| tc_0602a3ae | search | 4ms | 2026-09-20T06:18:25 | |
| tc_01f8154d | get_ioc_summary | 604ms | 2026-09-20T06:19:02 | |
| tc_d51311a8 | submit_finding | 10ms | 2026-09-20T06:20:06 | |
| tc_7ad32139 | submit_finding | 9ms | 2026-09-20T06:20:27 | |
| tc_ff81fadf | submit_finding | 8ms | 2026-09-20T06:21:16 | |
| tc_793a7d12 | submit_finding | 18ms | 2026-09-20T06:21:48 | |
| tc_992e6771 | submit_finding | 15ms | 2026-09-20T06:22:55 | |
| tc_37b8af5a | get_findings | 1ms | 2026-09-20T06:23:14 | |
| tc_fd8ff1ea | track_progress | 14ms | 2026-09-20T06:24:22 | |
| tc_b988c3f2 | get_investigation_summary | 4ms | 2026-09-20T06:24:49 | |
| tc_fb72b577 | open_case | 30ms | 2026-09-20T06:24:54 | |
| tc_13a3a948 | get_findings | 2ms | 2026-09-20T06:24:56 | |
| tc_efa8250b | get_investigation_summary | 4ms | 2026-09-20T06:24:56 | |
| tc_c6194b5c | list_sources | 2ms | 2026-09-20T06:24:56 | |
| tc_507d1a49 | get_timeline | 23ms | 2026-09-20T06:25:38 | |
| tc_9c0630b7 | get_timeline | 1ms | 2026-09-20T06:26:32 | |
| tc_1c6b1014 | open_case | 29ms | 2026-09-20T06:27:57 | |
| tc_00422f9a | search | 12ms | 2026-09-20T06:28:10 | |
| tc_f7bd5b63 | search | 13ms | 2026-09-20T06:28:10 | |
| tc_27eea260 | search | 20ms | 2026-09-20T06:28:10 | |
| tc_3ac34bef | search | 16ms | 2026-09-20T06:28:10 | |
| tc_ffec9423 | search | 16ms | 2026-09-20T06:28:10 | |
| tc_0f281fb0 | search | 15ms | 2026-09-20T06:28:10 | |
| tc_9bc4e4b6 | search | 9ms | 2026-09-20T06:28:10 | |
| tc_423987e3 | search | 14ms | 2026-09-20T06:28:10 | |
| tc_98469803 | search | 15ms | 2026-09-20T06:28:10 | |
| tc_66868151 | search | 7ms | 2026-09-20T06:28:10 | |
| tc_48d43254 | search | 6ms | 2026-09-20T06:28:10 | |
| tc_066c62f8 | search | 22ms | 2026-09-20T06:28:10 | |
| tc_680e00c5 | correlate_across_sources | 47ms | 2026-09-20T06:28:12 | |
| tc_9b1e160d | get_timeline | 11ms | 2026-09-20T06:28:15 | |
| tc_c60cea70 | get_timeline | 3ms | 2026-09-20T06:28:18 | |
| tc_7204490a | open_case | 29ms | 2026-09-20T06:29:31 | |
| tc_d5c3008a | get_findings | 2ms | 2026-09-20T06:29:31 | |
| tc_29e419d8 | get_investigation_summary | 4ms | 2026-09-20T06:29:49 | |
| tc_f4ac36c2 | search | 10ms | 2026-09-20T06:29:59 | |
| tc_10e00ec0 | search | 7ms | 2026-09-20T06:29:59 | |
| tc_e87fb019 | search | 5ms | 2026-09-20T06:29:59 | |
| tc_49ed2e87 | search | 4ms | 2026-09-20T06:30:00 | |
| tc_ddcace22 | search | 13ms | 2026-09-20T06:30:17 | |
| tc_67322fac | search | 8ms | 2026-09-20T06:30:18 | |
| tc_00cbc22e | search | 3ms | 2026-09-20T06:30:18 | |
| tc_eda86aa8 | get_raw_output | 56ms | 2026-09-20T06:30:43 | |
| tc_053a7646 | deduplicate_findings | 29ms | 2026-09-20T06:31:34 | |
| tc_d26fb1ca | audit_evidence_coverage | 222ms | 2026-09-20T06:32:23 | |
| tc_f857e516 | audit_tool_coverage | 2ms | 2026-09-20T06:32:23 | |
| tc_b2b8eb6d | get_raw_output | 54ms | 2026-09-20T06:33:06 | |
| tc_72ca7fe2 | get_raw_output | 54ms | 2026-09-20T06:33:06 | |
| tc_872b41ef | get_raw_output | 54ms | 2026-09-20T06:33:06 | |
| tc_c2bfec73 | search | 5ms | 2026-09-20T06:33:52 | |
| tc_30ac62fc | search | 8ms | 2026-09-20T06:33:52 | |
| tc_34bb9b7b | update_finding | 14ms | 2026-09-20T06:34:50 | |
| tc_d8f71c11 | update_finding | 13ms | 2026-09-20T06:35:42 | |
| tc_791a3369 | update_finding | 13ms | 2026-09-20T06:36:04 | |
| tc_829fce25 | update_finding | 14ms | 2026-09-20T06:36:27 | |
| tc_1c0cbfc2 | deduplicate_findings | 113ms | 2026-09-20T06:36:54 | |
| tc_cb51d4e2 | get_findings | 1ms | 2026-09-20T06:37:09 | |
| tc_c16eb104 | check_finalize_readiness | 3ms | 2026-09-20T06:37:09 | |
| tc_71452148 | track_progress | 12ms | 2026-09-20T06:37:45 | |
| tc_4f4c8bb3 | get_investigation_summary | 4ms | 2026-09-20T06:38:28 | |
| tc_72c487f0 | check_finalize_readiness | 4ms | 2026-09-20T06:38:28 | |
| tc_2905860f | open_case | 8ms | 2026-09-20T06:38:40 | |
| tc_ce3c5562 | get_findings | 2ms | 2026-09-20T06:38:44 | |
| tc_72db9c6d | get_investigation_summary | 4ms | 2026-09-20T06:38:44 | |
| tc_6e548c41 | get_ioc_summary | 595ms | 2026-09-20T06:38:45 | |
| tc_c8e572a8 | get_bookmarks | 2ms | 2026-09-20T06:38:45 | |
| tc_a8ca5c4b | get_source_stats | 53ms | 2026-09-20T06:38:45 | |
| tc_a5b9c723 | submit_narrative | 13ms | 2026-09-20T06:41:31 | |
| tc_6145f77c | check_finalize_readiness | 3ms | 2026-09-20T06:41:47 |
Each finding traces back to the specific tool calls that produced the supporting evidence.