Executive Summary

📂23 sources (53 disk, 223 other)
🔍827 tool calls
⏱️50 minutes elapsed
🚨12 findings (1 critical, 5 high)
10 confirmed
🤔2 inference
3 hypotheses ruled out
🔒 SHA-256 hashes

The attack timeline spans 2014-12-02 to 2015-03-25. The earliest activity was Document metadata on RM#3 attributes the leaked files to author "company" via Microsoft Office; content is NIST / US federal government IT-investment data (2014-12-02). The most recent activity was Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed after the data leak (2015-03-25).

Key Threats
  • Third exfiltration vector: Secret Project Data burned to optical CD/DVD "IAMAN CD" with masqueraded filenames and decoy photos

0
Total Findings
0
Critical
0
High
0
Medium
0
Confirmed
0
Inference
0
Sources
0
Tool Calls
Severity Breakdown
Critical (1) High (5) Medium (6)
☑ Forensic Soundness and Evidence Integrity
Analysis was executed via a read-only Model Context Protocol (MCP) server mapped to the SANS SIFT toolchain. The MCP architecture enforces structural evidence protection: original evidence files were mounted as read-only volumes, all tool interactions are typed functions (no shell access), and every finding is validated against the append-only audit log before acceptance. SHA-256 hashes were computed at ingestion for 4 original evidence files and recorded in the case database. 827 tool calls executed across 23 indexed sources with full provenance tracking.
⚠ Critical Findings
  • Third exfiltration vector: Secret Project Data burned to optical CD/DVD "IAMAN CD" with masqueraded filenames and decoy photos
    2015-03-24T20:54:16 — 2015-03-24T20:57:03
⚔ MITRE ATT&CK Coverage
Reconnaissance
Resource Development
Initial Access (1)
Execution
Persistence (3)
Privilege Escalation (2)
Defense Evasion (4)
Credential Access
Discovery
Lateral Movement
Collection (2)
Command and Control
Exfiltration (4)
Impact
Inhibit Response Function
Evasion
Impair Process Control
Initial Access (1)Persistence (3)Privilege Escalation (2)Defense Evasion (4)Collection (2)Exfiltration (4)
12 techniques across 12 findings
★ IOC Summary
External IPs0
Internal IPs1
File Paths4
Hashes0
Emails5
Investigation Metadata
Case IDndlc
Evidence Root/evidence
Report Generated2026-09-19T20:45:16
Investigation Start2026-09-19T19:54:59
Investigation End2026-09-19T20:45:07
Total Processing1489.7s
Audit Log/home/mulder/.mulder/cases/ndlc.audit.jsonl
4 FILES Hashes computed during evidence ingestion. Compare against your local copies to confirm integrity.
FileSHA-256Size
cfreds_2015_data_leakage_pc.E01 e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 2.0 GB
cfreds_2015_data_leakage_rm1.E01 a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 74.6 MB
cfreds_2015_data_leakage_rm2.E01 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 243.2 MB
cfreds_2015_data_leakage_rm3_type3.E01 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b 90.2 MB

Investigation Report: Insider Data Exfiltration — CFReDS 2015 Data Leakage Scenario

Background

This investigation concerns a suspected insider data-leak incident on a Windows 7 workstation assigned to the user account "informant" (iaman.informant@nist.gov). The evidence set comprises a forensic disk image of the informant's PC, two removable USB flash-drive images (RM#1, an exFAT device labeled "Authorized USB" mounted as E:, and RM#2, a FAT32 device labeled "IAMAN" mounted as D:), and an optical CD/DVD image (RM#3, a UDF write-once disc labeled "IAMAN CD"). A total of 23 evidence sources were indexed across 827 tool executions, spanning SleuthKit filesystem analysis, registry parsing (SYSTEM, NTUSER, USRCLASS), Windows Event Log analysis (EVTX, Hayabusa, Chainsaw), ShimCache/UserAssist execution artifacts, MFT parsing, bulk_extractor string carving, ExifTool metadata analysis, optical-media UDF reconstruction, YARA malware scanning, steganography detection, and Volume Shadow Copy analysis.

The environment is a small internal network (10.11.11.0/24, domain "localdomain"). The informant PC held DHCP address 10.11.11.129; the sensitive data resided on a network share at \10.11.11.128\secured_drive in a folder tree named "Secret Project Data" with subfolders design, pricing decision, final, technical review, proposal, and progress. The system timezone is US Eastern (UTC-4 during the relevant period). The evidence is drawn from the NIST CFReDS 2015 Data Leakage scenario, in which the document set is derived from the publicly available NIST GovDocs corpus and represents sensitive/classified material within the scenario; the behavioral findings regarding the user's conduct are the subject of this report and are unaffected by the public origin of the underlying test documents.

Incident Timeline

The incident unfolded in four distinct operational phases over four days, from 2015-03-22 through 2015-03-25.

Phase 1 — Preparation and persistence (2015-03-22). On the afternoon of 2015-03-22, shortly after initial system setup, the informant created three unauthorized local Administrator accounts in a roughly two-minute span: "admin11" (created 15:51:54), "ITechTeam" (15:52:30), and "temporary" (15:53:01). Each was added to the local Administrators group and had its password reset, and each was then interactively logged on (LogonType 2) — admin11 at 15:53:44 and again at 15:57:02 via explicit credentials, and temporary at 15:55:57. The name "ITechTeam" mimics a legitimate IT-support account, indicating an attempt to create plausible-looking backdoor accounts. Notably, admin11 opened setupapi.dev.log (the device/USB installation log), consistent with reviewing what USB activity had been recorded. At 14:52:22 the same day, the informant first browsed the \10.11.11.128\secured_drive "Secret Project Data" share. This account-creation activity preceded any data staging by two days, establishing premeditation.

Phase 2 — Reconnaissance and cloud-channel setup (2015-03-22 to 2015-03-23). Beginning with the first Chrome use on 2015-03-22 14:33:13 and continuing through the incident, the informant conducted extensive web research into data leakage and anti-forensics. Carved browser search artifacts reveal queries including "how to leak a secret," "leaking confidential information," "information leakage cases," "intellectual property theft," "data leakage methods," "anti-forensic tools," "how to delete data," "eraser," "ccleaner," "DLP DRM," "windows event logs," "what is windows system artifacts," "Forensic Email Investigation," "external device and forensics," "cd burning method," "security checkpoint cd-r," "google drive," and "cloud storage." The user visited a DEFCON-20 AntiForensics PDF, forensicswiki.org/wiki/Anti-forensic, NIJ digital-evidence pages, and a PCAdvisor article comparing cloud-storage services. On 2015-03-23 at 19:56:33 the informant executed the Google Drive installer (googledrivesync.exe); the client installed at 20:02 and the "Google Drive" folder was created at 20:05:32. The informant again browsed the secured_drive share on 2015-03-23 at 20:23–20:28.

Phase 3 — Multi-media exfiltration (2015-03-24). This was the execution day. In the morning (~09:59–10:00), 17 files were written to the RM#2 "IAMAN" FAT32 device with false extensions to disguise Office documents as innocuous media/text files. In the early afternoon (13:38–14:01), the informant accessed a local "S data\Secret Project Data" copy and staged the data onto the RM#1 "Authorized USB" exFAT device (E:\Secret Project Data and E:\RM#1\Secret Project Data), retaining real filenames. That evening (19:47–20:44), the informant created the disguised folder structure on RM#2 (D:\de, D:\tr, D:\pd, D:\prop, D:\prog — abbreviations for design, technical review, pricing decision, proposal, progress) and browsed into the internal structure of a masqueraded PowerPoint file. Finally, from 20:54:16 to 20:57:03, the informant burned the same data to the RM#3 "IAMAN CD" optical disc across 9 UDF write sessions, renaming folders from full names to the abbreviated disguised names across sessions, and added three stock Windows 7 sample photos (Koala.jpg, Penguins.jpg, Tulips.jpg) to the disc root at 20:57 as decoys to make the CD appear to be an innocuous photo disc.

Phase 4 — Anti-forensic cleanup (2015-03-25). The day after the staging, the informant downloaded and executed two data-destruction tools: Eraser 6.2.0.2962 (installer run 14:47:40, application run 15:15:50) and CCleaner (installer ccsetup504.exe run 14:48:28, application CCleaner64.exe run 15:21:30). The Google Drive sync client was also executed at 15:24:48. The 17 masqueraded files on RM#2 survive only as deleted $OrphanFiles entries, consistent with this wiping activity; the live browser history databases were likewise unrecoverable, consistent with the CCleaner run.

Key Findings

The investigation produced 12 findings (10 confirmed, 2 inference, 3 negative), of which 1 is critical, 5 are high, and 6 are medium severity. Eight findings carry MITRE ATT&CK mappings spanning 12 techniques.

Persistence — backdoor accounts. The informant created three local Administrator accounts (admin11, ITechTeam, temporary) on 2015-03-22 and logged into them interactively. None were deleted (no EID 4726), so all three persisted. This maps to MITRE T1136.001 (Create Account: Local Account), T1098 (Account Manipulation), and T1078 (Valid Accounts). The account "ITechTeam" was named to blend in with legitimate IT support.

Data collection and staging. The source data was harvested from \10.11.11.128\secured_drive (T1039, Data from Network Shared Drive; T1020, Automated Exfiltration context). The data was staged locally and then onto removable media (T1074.001, Data Staged: Local Data Staging).

Exfiltration — three physical vectors plus a cloud channel. The investigation identified an unusually broad set of exfiltration channels. RM#1 ("Authorized USB") held the data with real filenames. RM#2 ("IAMAN") held identical content with 17 files renamed to false extensions (T1036.005, Masquerading: Match Legitimate Name or Location; T1567.002, Exfiltration to Cloud/physical; T1052.001, Exfiltration over Physical Medium: USB). RM#3 ("IAMAN CD") held the same content burned to optical disc with decoy photos (T1052.001, T1036.005, T1030, Data Transfer Size Limits context). The identical 16,381,123-byte winter_whether_advisory.zip on both RM#2 and RM#3 confirms the same content was written to multiple devices. Additionally, the Google Drive sync client was installed and run, representing a potential cloud exfiltration channel, though actual upload of the leaked files could not be confirmed from the indexed artifacts (confidence: inference).

Masquerading and concealment. The 17 files on RM#2 and RM#3 were Office documents (DOCX/XLSX/PPTX/OLE) renamed with media/archive extensions (.amr, .zip, .db, .7z, .jpg, .avi, .svg, .png, .one, .gif, .txt). Shellbags independently corroborated this by showing the user browsing into the internal PPTX structure of a ".zip" file. The decoy JPEGs on RM#3 were genuine Windows sample photos placed to make the disc look innocuous.

Anti-forensics. Eraser and CCleaner were downloaded and executed on 2015-03-25 (T1070.004, Indicator Removal: File Deletion; T1070.002, Clear Linux or Mac System Logs / general cleanup). The deletion of the RM#2 files and the unrecoverability of the browser history are consistent with this cleanup.

Negative results. Several hypotheses were affirmatively ruled out. No archiver (7-Zip/WinRAR) or file-transfer (FileZilla/WinSCP/PuTTY) tools were present, ruling out FTP/SFTP/SSH transfer and local archive creation — the ".7z"/".zip" files were renamed Office documents, not archives. No steganography was detected in the disc images. No malware was found (YARA produced no matches; no macros/JS/OLE exploits in the documents) — the tooling was legitimate-but-misused software. No Volume Shadow Copies existed on the removable media (expected for FAT32/exFAT). No external/remote intrusion vector was found — all network logons were benign ANONYMOUS LOGON, with no failed logons or RDP.

IOC clarification. The address Eric_P._Lauer@omb.eop.gov appears on both RM#2 and RM#3 with an identical surrounding byte context, indicating it is embedded document metadata carried inside the GovDocs-derived files rather than an exfiltration destination typed by the actor. It is therefore treated as a low-value indicator. The most defensible indicators are the internal source share (\10.11.11.128\secured_drive) and the actor's own accounts (iaman.informant@nist.gov, iaman.informant.personal@gmail.com).

Threat Intelligence and Attribution

This incident is attributable to an insider — the "informant" user — rather than an external threat actor. The evidence for this is convergent and strong: the backdoor accounts were created by the informant's own SID; the data access originated from the informant's PC on the same LAN segment as the server; the staging, masquerading, and cleanup were all performed interactively under the informant's session; and the web research into "how to leak a secret" and anti-forensics was conducted from the informant's browser. No external intrusion, malware, or remote-access vector was identified.

Attribution to a named external threat group is not applicable here; this is an insider-threat scenario. The TTP pattern — premeditated research, creation of plausible-looking backdoor accounts, multi-vector physical exfiltration with filename masquerading and decoy content, followed by anti-forensic cleanup — is consistent with a deliberate, planned insider data-theft operation rather than opportunistic or automated activity. The specific research queries ("security checkpoint cd-r," "DLP DRM," "windows event logs") indicate the actor anticipated physical security screening and forensic investigation and actively sought to defeat both. Confidence in the insider attribution is high and confirmed by multiple independent artifact sources; confidence in any external actor is nil.

Impact Assessment

The scope of compromise is a single workstation (the informant PC, 10.11.11.129) and the data it could reach. The data at risk is the "Secret Project Data" collection, which within the scenario represents sensitive US federal government IT-investment and budget data spanning numerous departments and agencies (Air Force, Army, Navy, DoD Agencies, USDA, DOC, ED, Energy, HHS, DHS, HUD, Interior, DOJ, Labor, State, USAID, DOT, Treasury, VA, USACE, EPA, GSA, NASA, NARA, NRC, OMB, OPM) plus climate/satellite research presentations. The total staged volume is substantial — individual files ranged up to 35 MB, with the aggregate across the 17 masqueraded files exceeding 100 MB, replicated across three separate physical media.

Credential and access exposure is significant: three unauthorized local Administrator accounts were created and persisted, granting the actor continued privileged access independent of the primary account. Persistence depth is therefore moderate (local account backdoors on one host). The exfiltration breadth is high — the data left the environment on at least two USB devices and one optical disc, with a possible additional cloud channel via Google Drive. The anti-forensic activity (Eraser/CCleaner) partially succeeded in destroying browser history and the on-media copies, though the deleted files were recoverable from orphan space and the behavioral record survived in registry, event logs, and execution artifacts.

Immediate Tactical Containment

The following steps should be executed immediately to stop the active threat. Note that this is a historical/forensic scenario; the steps are framed as they would apply to a live equivalent incident.

  1. Isolate the informant workstation (last known IP 10.11.11.129) from the network — pull the network cable or quarantine via switch/NAC to prevent any further access to \10.11.11.128\secured_drive.
  2. Disable the primary user account "informant" (iaman.informant@nist.gov) in Active Directory / locally, and revoke any associated credentials and active sessions.
  3. Disable and investigate the three backdoor local Administrator accounts: "admin11," "ITechTeam," and "temporary." Do not delete them until their hives and activity are preserved; reset their passwords and remove them from the Administrators group.
  4. Preserve and restrict access to the file server at 10.11.11.128; audit access to the "secured_drive" share and enable detailed file-access auditing on the "Secret Project Data" tree.
  5. Seize and forensically image all removable media associated with the user — specifically the two SanDisk Cruzer Fit USB devices (serials 4C530012450531101593&0 and 4C530012550531106501&0) and the "IAMAN CD" optical disc — and issue a recall for any media that may have left the premises.
  6. Block and audit the Google Drive sync client (googledrivesync.exe) and the consumer cloud-storage channel at the proxy/egress filter; capture any pending sync activity to determine whether data was uploaded.
  7. Quarantine the anti-forensic tools pending review — preserve C:\Program Files\Eraser\Eraser.exe and C:\Program Files\CCleaner\CCleaner64.exe and their installers as evidence; do not run them.
  8. Block egress to drive.google.com and consumer cloud-storage domains at the perimeter until the scope of any cloud upload is determined.
  9. Preserve the Security event log, ShimCache, UserAssist, USRCLASS shellbags, and MFT from the workstation before any cleanup or reimaging.
  10. Interview/escort the user per insider-threat protocol and preserve their Outlook OST (iaman.informant@nist.gov.ost) and any personal webmail artifacts (iaman.informant.personal@gmail.com) via legal hold.

Strategic Remediation

Root cause 1 — Unrestricted local Administrator and account-creation rights. The informant was able to create three local Administrator accounts and add them to the Administrators group (finding f_d2b08f44, T1136.001/T1098). The control that failed was the absence of any restriction or alerting on privileged-account creation. The specific change that would have prevented this attack path is to remove standing local-admin rights from standard users, route account creation through a controlled process, and alert on Security EID 4720 (account created) and 4732 (member added to Administrators) in near-real-time — the three accounts created in a two-minute burst at 15:51–15:53 on 2015-03-22 would have triggered immediate investigation two days before the data was staged.

Root cause 2 — Unrestricted access to the sensitive network share. The informant browsed and harvested \10.11.11.128\secured_drive "Secret Project Data" without any apparent access control or DLP intervention (findings f_8a3b21e2, f_84fc9db9, T1039). The control that failed was overly permissive share ACLs combined with no data-loss-prevention monitoring. The specific change is to enforce least-privilege ACLs on the secured_drive share so only authorized project members can read the Secret Project Data tree, and to deploy DLP that alerts on bulk reads from that share — the actor explicitly researched "DLP DRM" (90 hits), indicating they expected and sought to evade such a control.

Root cause 3 — Uncontrolled removable-media and optical-burning capability. The actor staged data onto two USB devices and burned a CD, using filename masquerading and decoy photos to defeat casual inspection (findings f_84fc9db9, f_b0a2bacd, f_5dc19002, T1052.001/T1036.005). The control that failed was the absence of removable-media control and optical-burn restrictions. The specific change is to enforce a device-control policy that blocks or encrypts writes to unapproved USB storage and disables optical burning for users without a business need — the actor researched "security checkpoint cd-r" and "cd burning method," indicating they planned to physically carry media past a checkpoint, which a device-control policy rendering media unreadable off-system would have defeated.

Root cause 4 — Unrestricted installation of cloud-sync and anti-forensic software. The actor installed Google Drive, Eraser, and CCleaner without restriction (findings f_5b6d90e2, f_97049535, T1567.002/T1070.004). The control that failed was the absence of application allow-listing. The specific change is to deploy application control (e.g., AppLocker/WDAC) that blocks unapproved executables — this would have prevented both the cloud exfiltration channel (googledrivesync.exe) and the evidence-destruction tools (Eraser/CCleaner) from running.

Root cause 5 — No monitoring of anti-forensic research or execution. The actor conducted extensive reconnaissance into forensic artifacts and evidence destruction and then executed wiping tools, with no detection (findings f_437ab754, f_97049535). The control that failed was the absence of user-behavior and execution monitoring. The specific change is to alert on execution of known anti-forensic tools (Eraser, CCleaner secure-delete functions) and on ShimCache/UserAssist anomalies, so that the 2015-03-25 cleanup would have been detected and the media preserved before deletion.

Conclusion

This investigation confirms a deliberate, premeditated insider data-exfiltration incident carried out by the "informant" user between 2015-03-22 and 2015-03-25.

Q1. What systems were compromised? A single workstation — the informant PC at 10.11.11.129 — was compromised, in the sense that the legitimate user abused their own access. Three backdoor local Administrator accounts (admin11, ITechTeam, temporary) were created on it. The file server at 10.11.11.128 was accessed as the data source but was not itself compromised.

Q2. How did the attacker gain initial access? This is an insider threat; the actor already had legitimate access. No external intrusion occurred — the actor used their own authorized credentials and local access. The "initial access" for the data-theft phase was the actor's legitimate ability to read the \10.11.11.128\secured_drive share.

Q3. What lateral movement occurred? No lateral movement to other systems occurred. The actor's activity was confined to their own workstation and access to the single network share. All network logons were benign ANONYMOUS LOGON; there were no failed logons, no RDP, and no movement to other hosts.

Q4. What persistence mechanisms were installed? Three unauthorized local Administrator accounts (admin11, ITechTeam, temporary) were created on 2015-03-22, added to the Administrators group, and never deleted. These constitute the persistence mechanism, providing continued privileged access independent of the primary account.

Q5. Was data exfiltrated, and if so, what and how much? Yes. The "Secret Project Data" collection — representing US federal government IT-investment/budget data and climate-research documents — was staged onto at least three physical media: two USB flash drives (RM#1 "Authorized USB" with real filenames, RM#2 "IAMAN" with 17 masqueraded files) and one optical CD ("IAMAN CD" with the same masqueraded files plus decoy photos). Individual files ranged up to 35 MB, with the aggregate across the 17 files exceeding 100 MB replicated across the three media. A Google Drive cloud channel was set up but actual upload could not be confirmed.

Q6. What is the full timeline of the incident? 2015-03-22: backdoor accounts created (15:51–15:57), share first browsed (14:52), research begun. 2015-03-23: share re-browsed (20:23–20:28), Google Drive installed (19:56–20:05). 2015-03-24: RM#2 files written (~09:59–10:00), RM#1 staged (13:38–14:01), RM#2 disguised structure created and browsed (19:47–20:44), RM#3 CD burned (20:54–20:57). 2015-03-25: Eraser and CCleaner executed (14:47–15:21), Google Drive sync run (15:24).

Q7. What is the total scope and business impact? The scope is one workstation, one data source, three backdoor accounts, and exfiltration of a sensitive multi-agency government data collection across three physical media plus a potential cloud channel. The business impact is the loss of confidentiality of the Secret Project Data and the persistence of privileged backdoor access; within the scenario this represents a serious breach of restricted government data.

Q8. What are the recommended remediation actions? Contain the workstation and disable the informant and backdoor accounts immediately; preserve all media and forensic artifacts; then implement the five strategic remediations — restrict and alert on privileged-account creation, enforce least-privilege and DLP on the secured_drive share, deploy removable-media and optical-burn device control, enforce application allow-listing to block unapproved cloud-sync and anti-forensic tools, and add behavioral/execution monitoring for anti-forensic activity. These map directly to the specific failures observed in this case.

2014-12-02
2014-12-02T17:28:58Z — 2015-01-23T20:47:10Z
Document metadata on RM#3 attributes the leaked files to author "company" via Microsoft Office; content is NIST / US federal government IT-investment data
medium confirmed
exiftool.metadata, yara.files
2015-03-22
2015-03-22T14:33:13 — 2015-03-25T14:47:40
Web search history shows premeditated research into data leakage, anti-forensics, and evidence destruction
medium confirmed
bulk.url_searches, bulk.url
2015-03-22T14:52:22Z — 2015-03-23T20:28:17Z
Network Share Access to Secured Drive Containing Secret Project Data
high confirmed
registry.usrclass.informant, registry.system, bulk.domain
2015-03-22T15:51:54 — 2015-03-22T15:57:02
Informant created three unauthorized local Administrator accounts (admin11, ITechTeam, temporary) for persistence
high confirmed
evtx.windows_system32_winevt_logs_security, hayabusa.alerts, chainsaw.hunt, registry.ntuser.admin11, registry.ntuser.temporary
2015-03-23
2015-03-23T19:56:33 — 2015-03-25T15:24:48
Google Drive cloud sync client installed and run; user researched cloud-storage services for leaking data
medium inference
ez.shimcache, registry.ntuser.informant, ez.mft, bulk.url
2015-03-24
2015-03-24T09:59:27 — 2015-03-24T20:44:18
17 files renamed with false extensions (masquerading) on removable media RM#2 to disguise leaked Office documents
high confirmed
tsk.masquerade, registry.usrclass.informant, ez.mft
2015-03-24T09:59:27 — 2015-03-24T10:00:18
External emails, domains, and IPs on disk that represent potential exfiltration destinations
medium inference
bulk.email, bulk.domain
2015-03-24T09:59:27 — 2015-03-25T15:21:30
RM#2 target device contains only deleted files (all content removed); no shadow copies, steganography, or malware found
medium confirmed
tsk.filelist, vshadow.info, yara.files, binwalk.scan, steg.detection, tsk.masquerade
2015-03-24T13:38:31 — 2015-03-24T20:44:18
Sensitive "Secret Project Data" copied from network share \\10.11.11.128\secured_drive to two removable USB drives (RM#1 and RM#2)
high confirmed
registry.usrclass.informant, bulk.domain, tsk.masquerade, tsk.filelist
2015-03-24T13:58:32
Two SanDisk Cruzer Fit USB storage devices connected to the informant PC (RM#1 and RM#2)
medium confirmed
registry.system
2015-03-24T20:54:16 — 2015-03-24T20:57:03
Third exfiltration vector: Secret Project Data burned to optical CD/DVD "IAMAN CD" with masqueraded filenames and decoy photos
critical confirmed
optical.listing, bulk.url_searches, tsk.masquerade, exiftool.metadata
2015-03-25
2015-03-25T14:47:40 — 2015-03-25T15:21:30
Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed after the data leak
high confirmed
registry.ntuser.informant, ez.shimcache
critical confirmed Third exfiltration vector: Secret Project Data burned to optical CD/DVD "IAMAN CD" with masqueraded filenames and decoy photos

Optical-media analysis (mulder-optical UDF listing) reveals a CD/DVD with volume label "IAMAN CD" (UDF write-once, VAT, 52,513 sectors, 9 write sessions/VAT generations) containing the SAME "Secret Project Data" that was staged onto the USB drives — a THIRD physical exfiltration vector distinct from RM#1 ("Authorized USB") and RM#2 ("IAMAN" FAT32 flash drive).

Content and correlation:
- The disc holds the same sensitive folder set, seen in BOTH full-name form (design, pricing decision, progress, proposal, technical review) and the abbreviated form (de, pd, prog, prop, tr) used on RM#2 — the VAT session history shows the folders were renamed from full names to the abbreviated/disguised names across write sessions.
- It contains the SAME masqueraded files with byte-identical sizes to RM#2, e.g. winter_whether_advisory.zip = 16,381,123 bytes (matches the USB finding exactly), winter_storm.amr = 14,547,968, my_favorite_cars.db = 1,260,544, super_bowl.avi = 10,289,152, a_gift_from_you.gif = 35,226,880, plus the diary_#*.txt files. These are Office documents (PPTX/XLSX/DOCX/OLE) renamed with media/archive extensions.
- Three stock Windows 7 sample photos — Koala.jpg (780,831), Penguins.jpg (777,835), Tulips.jpg (620,888) — were written to the disc root at 2015-03-24 20:57, AFTER the data files (20:54–20:55). ExifTool confirms Penguins.jpg is a genuine JPEG (MIME image/jpeg, Adobe XMP, Corbis stock-photo web statement) — i.e., these are REAL images placed as decoys to make the CD look like an innocuous photo disc on casual inspection, NOT additional disguised documents.

ExifTool content analysis of the masqueraded files on the disc independently corroborates that they are real Office documents with substantive content (Author/LastModifiedBy "company", created 2003–2004, modified 2014–2015):
- "[secret_project]_market_shares" (Microsoft Excel).
- A federal "IT Investment Details" spreadsheet referencing the Nuclear_Regulatory_Commission, Office_of_Management_and_Budget, Office_of_Personnel_Management, and Department of Defense Agencies.
- Climate/satellite research presentations (Microsoft PowerPoint) referencing ISCCP Data, NCDC processing, GEWEX Projects, Albedo, and Satellite Coverage.
- A Microsoft Word 97-2003 document with hyperlinks to hdl.loc.gov and digitalcorpora.org/corpora/govdocs (the GovDocs corpus — the origin of the test data representing the "Secret Project Data").

Timeline: data files created on the disc 2015-03-24 20:54:16–20:55:46; decoy images 20:57:00–20:57:03 — the same evening as the RM#2 USB staging (19:47–20:44), indicating a coordinated multi-media exfiltration effort.

This corroborates the web-search research finding: the user searched for "cd burning method" (64 hits), "cd burning method in windows" (53), and "security checkpoint cd-r" — i.e., they researched how to burn data to CD and get it past security checkpoints. The shared "IAMAN" volume label links the CD to the RM#2 USB device. Confidence is confirmed via three independent sources: the optical UDF listing (file enumeration/sizes), the byte-identical sizes in the USB masquerading finding (tsk.masquerade), and ExifTool content/metadata analysis of the files themselves.

Evidence strength:
4 refs
optical.listingbulk.url_searchestsk.masqueradeexiftool.metadata

Evidence Chain

tc_0d5a6790 get_raw_output 62ms
tc_d87263a2 get_raw_output 64ms
tc_1e369e28 search 4ms
tc_429306c8 search 4ms
Time: 2015-03-24T20:54:16 — 2015-03-24T20:57:03
Sources: optical.listing, bulk.url_searches, tsk.masquerade, exiftool.metadata
Evidence Refs: tc_0d5a6790, tc_d87263a2, tc_1e369e28, tc_429306c8
high confirmed 17 files renamed with false extensions (masquerading) on removable media RM#2 to disguise leaked Office documents

Content/signature analysis (tsk.masquerade) of the RM#2 removable drive (FAT32, volume label "IAMAN", the target media) identified 17 deleted files in $OrphanFiles whose true content type (by file signature) contradicts their displayed extension — a classic concealment technique to disguise sensitive Office documents as innocuous media/text files before exfiltration. All were created on the media in a tight burst on 2015-03-24 (~09:59–10:00 per FAT timestamps) and all are now deleted (recovered only as orphans).

Mismatches (extension → real type):
- design/winter_storm.amr → OLE/Office (14.5 MB)
- design/winter_whether_advisory.zip → PPTX (16.4 MB)
- PRICIN~1 (pricing decision)/my_favorite_cars.db → OLE (1.3 MB)
- PRICIN~1/my_favorite_movies.7z → XLSX (100 KB)
- PRICIN~1/new_years_day.jpg → XLSX (10.2 MB)
- PRICIN~1/super_bowl.avi → OLE (10.3 MB)
- progress/my_friends.svg → OLE (58 KB)
- progress/my_smartphone.png → DOCX (4.4 MB)
- progress/new_year_calendar.one → DOCX (27 KB)
- proposal/a_gift_from_you.gif → DOCX (35.2 MB)
- proposal/landscape.png → DOCX (6.5 MB)
- TECHNI~1 (technical review)/diary_#1d.txt → DOCX; diary_#1p.txt → PPTX; diary_#2d.txt → DOCX; diary_#2p.txt, diary_#3d.txt, diary_#3p.txt → OLE

The $OrphanFiles directory names (design, PRICIN~1=pricing decision, progress, proposal, TECHNI~1=technical review) exactly match the "Secret Project Data" subfolders the user accessed on the source network share and PC. Corroborated independently by Shellbags (registry.usrclass.informant), which show the user browsing INTO D:\de\winter_whether_advisory.zip\ppt\slides\ppt and \ppt\slideMasters\ppt on 2015-03-24 19:54–20:44 — internal PPTX/ZIP structure, proving the ".zip" is really a PowerPoint file. The D: drive folders de/tr/pd/prop/prog map to design/technical review/pricing decision/proposal/progress.

Evidence strength:
3 refs
tsk.masqueraderegistry.usrclass.informantez.mft

Evidence Chain

tc_62a66069 get_raw_output 52ms
tc_64dfac60 get_raw_output 66ms
tc_1dd92c90 get_timeline 2ms
Time: 2015-03-24T09:59:27 — 2015-03-24T20:44:18
Sources: tsk.masquerade, registry.usrclass.informant, ez.mft
Evidence Refs: tc_62a66069, tc_64dfac60, tc_1dd92c90
high confirmed Sensitive "Secret Project Data" copied from network share \\10.11.11.128\secured_drive to two removable USB drives (RM#1 and RM#2)

Shellbag artifacts (registry.usrclass.informant) reconstruct the data-leak path on 2015-03-24. The source data lived on a network share \10.11.11.128\secured_drive (also mapped as drive V:) containing "Secret Project Data" with subfolders design, pricing decision, final, technical review, proposal, progress, plus Common Data and Past Projects. The user browsed this share on 2015-03-22 14:52 and 2015-03-23 20:23–20:28, and accessed a local "S data\Secret Project Data" copy on 2015-03-24 13:40–13:52.

On 2015-03-24 the data was staged onto two removable drives:
- E: = RM#1, exFAT, volume label "Authorized USB" — "E:\Secret Project Data" and "E:\RM#1\Secret Project Data" created ~13:59 and accessed 13:38–14:01, retaining REAL filenames (e.g. E:\Secret Project Data\design\winter_whether_advisory.zip, 16,381,123 bytes).
- D: = RM#2, FAT32, volume label "IAMAN" — folders D:\de, D:\tr, D:\pd, D:\prop, D:\prog created 19:47:48 and browsed 19:54–20:44, holding the SAME content but renamed with false extensions (see masquerading finding). The same winter_whether_advisory.zip (16,381,123 bytes) appears on both drives, confirming identical content was written to both.

The presence of identical sensitive content on two different USB devices — one labeled "Authorized USB" with real names, one labeled "IAMAN" with disguised names — indicates deliberate exfiltration with an attempt to conceal the nature of the data on the second device.

Evidence strength:
4 refs
registry.usrclass.informantbulk.domaintsk.masqueradetsk.filelist

Evidence Chain

tc_64dfac60 get_raw_output 66ms
tc_553cdb5f search 5ms
tc_62a66069 get_raw_output 52ms
tc_1dd92c90 get_timeline 2ms
Time: 2015-03-24T13:38:31 — 2015-03-24T20:44:18
Sources: registry.usrclass.informant, bulk.domain, tsk.masquerade, tsk.filelist
Evidence Refs: tc_64dfac60, tc_553cdb5f, tc_62a66069, tc_1dd92c90
high confirmed Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed after the data leak

Execution artifacts show the user installed and ran data-destruction/cleanup tools immediately after the 2015-03-24 leak, indicating an attempt to destroy evidence:
- Eraser 6.2.0.2962 (secure file-wiping tool): installer C:\Users\informant\Desktop\Download\Eraser 6.2.0.2962.exe executed 2015-03-25 14:47:40 (ShimCache) / 14:50:14 (UserAssist); C:\Program Files\Eraser\Eraser.exe executed 2015-03-25 15:15:50 (UserAssist) and present in ShimCache.
- CCleaner (temp/history cleaner): installer ccsetup504.exe executed 2015-03-25 14:48:28 (ShimCache) / 14:57:56 (UserAssist); C:\Program Files\CCleaner\CCleaner64.exe executed 2015-03-25 15:21:30 (UserAssist) and in ShimCache.

Both tools were downloaded to the Desktop\Download folder and run on 2015-03-25, one day after the sensitive files were staged onto removable media and subsequently deleted (the RM#2 files survive only as $OrphanFiles). This timing is consistent with post-exfiltration cleanup/anti-forensic activity. The deletion of the 17 masqueraded files on RM#2 is consistent with this wiping activity.

Evidence strength:
2 refs
registry.ntuser.informantez.shimcache

Evidence Chain

tc_f874bc29 get_raw_output 61ms
tc_4baf803d get_raw_output 62ms
Time: 2015-03-25T14:47:40 — 2015-03-25T15:21:30
Sources: registry.ntuser.informant, ez.shimcache
Evidence Refs: tc_f874bc29, tc_4baf803d
high confirmed Network Share Access to Secured Drive Containing Secret Project Data

The system accessed a network share at \10.11.11.128\secured_drive which contained Secret Project Data with subdirectories for Common Data, Past Projects, design, pricing decision, final, technical review, proposal, and progress. Shellbags evidence shows the user browsed this network share on 2015-03-22 at 14:52:22 and again on 2015-03-23 at 20:23:28. The system's DHCP IP address was 10.11.11.x, placing it on the same network segment as the secured drive server. This network share appears to be the source of the Secret Project Data that was subsequently copied to the local system and to the USB device.

Evidence strength:
4 refs
registry.usrclass.informantregistry.systembulk.domain

Evidence Chain

tc_1f4618b9 get_raw_output 62ms
tc_4677eefe search 4ms
tc_507831a1 search 3ms
tc_fb3af364 search 3ms
Time: 2015-03-22T14:52:22Z — 2015-03-23T20:28:17Z
Sources: registry.usrclass.informant, registry.system, bulk.domain
Evidence Refs: tc_1f4618b9, tc_4677eefe, tc_507831a1, tc_fb3af364
ATT&CK: T1039, T1020
high confirmed Informant created three unauthorized local Administrator accounts (admin11, ITechTeam, temporary) for persistence

Windows Security event log records show the informant account (S-1-5-21-2425377081-3129163575-2985601102-1000) created three new local user accounts in a ~2-minute span on 2015-03-22, added each to the local Administrators group, and reset their passwords:

  • 15:51:54 — "admin11" (SID ...-1001) created (EID 4720/4738), added to Administrators (EID 4732), password reset 15:52:10 (EID 4724)
  • 15:52:30 — "ITechTeam" (SID ...-1002) created (EID 4720), added to Administrators (EID 4732), password reset 15:52:45 (EID 4724)
  • 15:53:01 — "temporary" (SID ...-1003) created (EID 4720), added to Administrators (EID 4732), password reset 15:53:11 (EID 4724)

The accounts were then interactively logged on (LogonType 2): admin11 at 15:53:44 (with administrative privileges, EID 4672) and again at 15:57:02 via explicit credentials (EID 4648), and temporary at 15:55:57. The NTUSER.DAT hives for admin11 and temporary confirm the profiles were created and used on 2015-03-22; admin11 opened setupapi.dev.log (the device/USB installation log) and an "inf" folder, consistent with reviewing what USB/device activity had been recorded.

No EID 4726 (account deleted) events exist, so all three accounts persisted on the system. The account names are notable: "ITechTeam" mimics a legitimate IT-support account, and "temporary"/"admin11" are generic — consistent with an attempt to create plausible-looking backdoor/persistence accounts. This activity occurred on 2015-03-22, immediately after initial system setup and BEFORE the informant first browsed the \10.11.11.128\secured_drive "Secret Project Data" share (14:52) and two days before the 2015-03-24 USB staging, indicating premeditation. No failed-logon (4625) or external network/RDP logons involving these accounts were observed; all LogonType 3 events were ANONYMOUS LOGON (benign).

Corroborated by independent sources: the Security EVTX (direct parse and via Hayabusa/Chainsaw) and the per-user NTUSER.DAT registry hives.

Evidence strength:
5 refs
evtx.windows_system32_winevt_logs_securityhayabusa.alertschainsaw.huntregistry.ntuser.admin11registry.ntuser.temporary

Evidence Chain

tc_90f3f830 get_raw_output 65ms
tc_ba019ffb get_raw_output 63ms
tc_ab4a8f0c search 9ms
tc_f58bad5f get_raw_output 63ms
tc_ecd12658 get_raw_output 63ms
Time: 2015-03-22T15:51:54 — 2015-03-22T15:57:02
Sources: evtx.windows_system32_winevt_logs_security, hayabusa.alerts, chainsaw.hunt, registry.ntuser.admin11, registry.ntuser.temporary
Evidence Refs: tc_90f3f830, tc_ba019ffb, tc_ab4a8f0c, tc_f58bad5f, tc_ecd12658
medium confirmed Two SanDisk Cruzer Fit USB storage devices connected to the informant PC (RM#1 and RM#2)

The Windows registry (ControlSet001\Enum\USBSTOR) on the informant PC records two SanDisk Cruzer Fit USB flash drives (Disk&Ven_SanDisk&Prod_Cruzer_Fit&Rev_2.01), distinguished by serial number:
- Serial 4C530012450531101593&0
- Serial 4C530012550531106501&0
The USBSTOR key was last written 2015-03-23 18:31:10 and the device subkey 2015-03-24 13:58:32, consistent with the 2015-03-24 leak window. These two devices correspond to the two removable-media images in the case: RM#1 (exFAT, volume label "Authorized USB", mounted as E:) and RM#2 (FAT32, volume label "IAMAN", mounted as D:). System timezone is Eastern (EST/EDT; ActiveTimeBias=240 = UTC-4 during DST, which was in effect on 2015-03-24), relevant when correlating FAT local timestamps against UTC registry/MFT values.

Evidence strength:
3 refs
registry.system

Evidence Chain

tc_24c2ef91 query_registry_value 4372ms
tc_c76b6d9d query_registry_value 4322ms
tc_427964db query_registry_value 4301ms
Time: 2015-03-24T13:58:32
Sources: registry.system
Evidence Refs: tc_24c2ef91, tc_c76b6d9d, tc_427964db
medium inference Google Drive cloud sync client installed and run; user researched cloud-storage services for leaking data

Google Drive was installed on the informant PC and the sync client executed, indicating a cloud-storage exfiltration channel was set up:
- C:\Users\informant\Downloads\googledrivesync.exe (installer) executed 2015-03-23 19:56:33 (ShimCache).
- C:\Program Files (x86)\Google\Drive\ installed 2015-03-23 20:02 (MFT); shell-extension googledrivesync64.dll registered 2015-03-23 20:02:45.
- C:\Users\informant\Google Drive folder created 2015-03-23 20:05:32 (MFT); shellbags show "Users\Google Drive" accessed 2015-03-25 15:20:59.
- googledrivesync.exe executed 2015-03-25 15:24:48 (UserAssist).
- Browser/URL artifacts show drive.google.com access and a PCAdvisor article "best-cloud-storage-dropbox-google-drive-onedrive-icloud" plus a Wikipedia "Cloud_storage" page, i.e. the user was evaluating cloud services.

Whether data was actually uploaded to Google Drive cannot be confirmed from the indexed artifacts (no Google Drive sync-database content was recovered showing the leaked files), but the installation and execution of the client during the leak window, combined with the research queries, make cloud storage a plausible exfiltration vector in addition to the USB devices.

Evidence strength:
4 refs
ez.shimcacheregistry.ntuser.informantez.mftbulk.url

Evidence Chain

tc_4baf803d get_raw_output 62ms
tc_f874bc29 get_raw_output 61ms
tc_4749446a search 4ms
tc_f6a52bc3 search 5839ms
Time: 2015-03-23T19:56:33 — 2015-03-25T15:24:48
Sources: ez.shimcache, registry.ntuser.informant, ez.mft, bulk.url
Evidence Refs: tc_4baf803d, tc_f874bc29, tc_4749446a, tc_f6a52bc3
ATT&CK: T1567.002
medium inference External emails, domains, and IPs on disk that represent potential exfiltration destinations

bulk_extractor recovered the following external indicators relevant to exfiltration:
- On the target RM#2 device (bulk.email, source rm2): "Eric_P._Lauer@omb.eop.gov" appears with surrounding "upload" context. omb.eop.gov is the Office of Management and Budget / Executive Office of the President — a U.S. federal government address.
- Source network share: \10.11.11.128\secured_drive (internal IP 10.11.11.128), confirmed in both shellbags and bulk.domain — this is the origin of the leaked "Secret Project Data".
- Informant's own accounts: iaman.informant@nist.gov and iaman@nist.gov (NIST; the Outlook OST on the PC), plus Gmail addresses scarter@gmail.com and erovira@gmail.com and a large set of "informant@<ad/tracker domain>" cookie strings (the latter are browser tracking cookies, likely noise).

COUNTER-ANALYSIS CLARIFICATION (Eric_P._Lauer mechanism): The "Eric_P._Lauer@omb.eop.gov" string appears with an IDENTICAL surrounding byte context ("upload\000\036\000\000\000\034\000\000\000") on BOTH RM#2 (offset 57020544) and the RM#3 optical disc (offset 53407872). The identical context string recurring at the same relative structure across two independent media strongly indicates this is EMBEDDED DOCUMENT METADATA carried inside the leaked files (which derive from the NIST GovDocs public corpus — OMB is heavily represented in that corpus), NOT an exfiltration destination typed or used by the actor. bulk_extractor carves strings from raw disk, so presence proves the string exists on the media but not the mechanism by which it got there. Accordingly this address should be treated as a low-value indicator (likely document metadata), not a confirmed exfiltration recipient. No email-send artifacts (Outlook OST Sent Items, SMTP traffic) tying this address to an actual transmission were identified.

The most defensible external indicators are therefore the internal source share (\10.11.11.128\secured_drive) and the actor's own NIST/Gmail accounts; the omb.eop.gov address is likely corpus metadata.

Evidence strength:
3 refs
bulk.emailbulk.domain

Evidence Chain

tc_c3514976 search 150ms
tc_ca95f6e7 search 3ms
tc_553cdb5f search 5ms
Time: 2015-03-24T09:59:27 — 2015-03-24T10:00:18
Sources: bulk.email, bulk.domain
Evidence Refs: tc_c3514976, tc_ca95f6e7, tc_553cdb5f
medium confirmed RM#2 target device contains only deleted files (all content removed); no shadow copies, steganography, or malware found

Filesystem analysis of the target RM#2 device (FAT32, volume label "IAMAN") shows that every data file on it is deleted: the only allocated entry is the volume label; all 17 masqueraded files and their parent folders (design, PRICIN~1, progress, proposal, TECHNI~1) exist solely as deleted $OrphanFiles entries. This is consistent with the files being deleted after staging — matching the Eraser/CCleaner cleanup activity on the PC the following day (2015-03-25). The deleted files were recoverable because FAT/exFAT deletion only marks directory entries, leaving content in unallocated/orphan space.

Negative results (questions 7 & 8):
- Shadow copies: vshadowinfo returned only its version banner for the removable media — no Volume Shadow Copies exist (expected; VSS does not apply to FAT32/exFAT removable drives). Earlier file versions are nonetheless preserved via the recoverable $OrphanFiles entries.
- Steganography: stegdetect/binwalk scans returned no hits — the disguise used was extension renaming (masquerading), not steganographic embedding.
- Malware: the YARA file scan produced no matches; no malware was identified. The relevant tooling is legitimate-but-misused software (Eraser, CCleaner, Google Drive) rather than malware.

Evidence strength:
5 refs
tsk.filelistvshadow.infoyara.filesbinwalk.scansteg.detectiontsk.masquerade

Evidence Chain

tc_20ae918e search 206ms
tc_29a8b73b get_raw_output 63ms
tc_f6d195c4 get_raw_output 62ms
tc_2e261a93 get_raw_output 62ms
tc_62a66069 get_raw_output 52ms
Time: 2015-03-24T09:59:27 — 2015-03-25T15:21:30
Sources: tsk.filelist, vshadow.info, yara.files, binwalk.scan, steg.detection, tsk.masquerade
Evidence Refs: tc_20ae918e, tc_29a8b73b, tc_f6d195c4, tc_2e261a93, tc_62a66069
medium confirmed Web search history shows premeditated research into data leakage, anti-forensics, and evidence destruction

Browser search-engine query artifacts recovered by bulk_extractor (both the url_searches histogram and the full url recorder) from the informant PC reveal the user researched topics directly related to planning and concealing a data leak. Notable queries (with hit counts from url_searches):

Leak/exfiltration intent: "how to leak a secret", "leaking confidential information", "information leakage cases" (47), "intellectual property theft", "data leakage methods", "file sharing and tethering" (491), "security checkpoint cd-r".

Anti-forensics / evidence destruction: "anti-forensic tools" (85), "anti-forensics", "how to delete data", "system cleaner", "eraser" (51), "ccleaner" (65), "data recovery tools", "how to recover data".

Evasion of detection / understanding investigations: "DLP DRM" (90), "windows event logs" (61), "what is windows system artifacts" (79), "Forensic Email Investigation" (78), "e-mail investigation" (88), "external device and forensics" (65), "investigation on windows machine" (64), "digital forensics", "cd burning method" (64).

Cloud exfiltration channel: "google drive" (10), "cloud storage", "apple icloud".

The full url recorder corroborates these with the actual result pages visited, including a DEFCON-20 "AntiForensics" PDF (defcon.org), forensicswiki.org/wiki/Anti-forensic, NIJ digital-evidence-analysis pages, a MediaPost article on a Google data-leakage settlement, and the icloudsetup.exe download.

NOTE ON TIMESTAMPS: These are carved browser artifacts (the live browser history databases were not recoverable — consistent with the CCleaner run on 2015-03-25), so individual per-search timestamps were not recoverable. The activity is bounded below by the first Chrome use on the freshly built system (informant Chrome UserAssist/LNK at 2015-03-22 14:33:13) and above by the anti-forensic tool execution it produced (Eraser/CCleaner, 2015-03-25 14:47:40). The searches directly corroborate and precede the observed actions: the user subsequently installed/ran Eraser and CCleaner, installed Google Drive, and staged data onto USB media with disguised filenames. This establishes the leak was premeditated and that the user actively sought to understand forensic artifacts, defeat DLP, and destroy evidence — evidence of intent and planning distinct from the execution findings.

Evidence strength:
3 refs
bulk.url_searchesbulk.url

Evidence Chain

tc_d87263a2 get_raw_output 64ms
tc_4e8fb390 search 7ms
tc_0ab8643c get_timeline 14ms
Time: 2015-03-22T14:33:13 — 2015-03-25T14:47:40
Sources: bulk.url_searches, bulk.url
Evidence Refs: tc_d87263a2, tc_4e8fb390, tc_0ab8643c
medium confirmed Document metadata on RM#3 attributes the leaked files to author "company" via Microsoft Office; content is NIST / US federal government IT-investment data

ExifTool metadata extracted from the recovered documents on the RM#3 optical disc (and identical RM#2 copies) characterizes the leaked content and its origin:

AUTHORSHIP/ATTRIBUTION: The documents consistently carry Author = "company" and Last Modified By = "company", created/edited with Microsoft Office applications (Microsoft Excel, Microsoft PowerPoint, Microsoft Word 97-2003). The generic "company" author is the default Office template author and does not identify a specific individual; it indicates the files were produced with standard Office installs rather than attributing a named person.

CONTENT / LEAK SOURCE: The spreadsheet winter_whether_advisory.zip (really XLSX) is titled "[secret_project]_market_shares" and its sheet names (Title Of Parts) enumerate a NIST document plus US federal government departments/agencies: "NIST, Please read first, Summary, Department of the Air Force, Department of the Army, Department of the Navy, Department of Defense Agencies, USDA, DOC, ED, Energy, HHS, DHS, HUD, Interior, DOJ, Labor, State, USAID, DOT, Treasury, VA, USACE, EPA, GSA, NASA, NARA, Nuclear Regulatory Commission, Office of Management and Budget, Office of Personnel Management..." — i.e. government-wide IT-investment/budget data. Other files reference climate-research hyperlinks (ISCCP, NCDC, GEWEX, NASA-related) and public-domain sources (hdl.loc.gov, digitalcorpora.org/govdocs).

COUNTER-ANALYSIS CLARIFICATION (GovDocs/CFReDS context): The embedded hyperlinks to digitalcorpora.org/corpora/govdocs and hdl.loc.gov identify the document set as derived from the NIST GovDocs corpus — a PUBLICLY AVAILABLE collection of government documents assembled by NIST for forensic testing (this is the CFReDS 2015 Data Leakage scenario, per the evidence image filenames cfreds_2015_data_leakage_*). The documents are therefore PUBLIC test data that REPRESENTS sensitive/classified material within the scenario, not genuinely classified content. This nuance does NOT alter the behavioral findings: within the scenario the data resided on a restricted share (\10.11.11.128\secured_drive) labeled "Secret Project Data," and the user's conduct (backdoor account creation, multi-media staging, filename masquerading, decoy-CD burning, anti-forensic cleanup, and "how to leak a secret"/"security checkpoint cd-r" research) is the actual subject of analysis and is unaffected by the public origin of the underlying test documents. The Eric_P._Lauer@omb.eop.gov address found on RM#2/RM#3 is consistent with embedded GovDocs document metadata (OMB is heavily represented in the corpus) rather than a confirmed exfiltration recipient.

TIMESTAMPS: Original document Create Dates are old (e.g. Excel 2004-02-20, PowerPoint 2003-12-04), with Modify Dates in Dec 2014–Jan 2015 — the files predate the 2015-03-24 leak, consistent with a collection of pre-existing documents that were harvested and burned to disc.

QUESTION 7 — Malicious content: No macros, embedded JavaScript, or malicious OLE objects were detected. YARA scanning of the files produced no matches, and no VBA/vbaProject/AutoOpen indicators exist in the documents (the only VBA artifacts on the system are legitimate Microsoft Office VBA7.1 installation DLLs). One PowerPoint file reports "Embedded OLE Servers, 2", a standard Office feature for embedded objects (e.g. charts), not malicious content. The documents are data-theft payloads, not malware.

Evidence strength:
4 refs
exiftool.metadatayara.files

Evidence Chain

tc_0cced7cc search 10ms
tc_73f900c1 search 4ms
tc_2b0946d0 search 4ms
tc_1e01368f get_raw_output 62ms
Time: 2014-12-02T17:28:58Z — 2015-01-23T20:47:10Z
Sources: exiftool.metadata, yara.files
Evidence Refs: tc_0cced7cc, tc_73f900c1, tc_2b0946d0, tc_1e01368f
✓ Ruled Out (Negative Findings)

These hypotheses were explicitly tested and no supporting evidence was found.

  • No archiver (7-Zip/WinRAR) or file-transfer (FileZilla/WinSCP/PuTTY) tools present; exfiltration was via USB media and Google Drive
    Click to expand
  • Network environment: informant PC was on the internal 10.11.11.0/24 LAN, same subnet as the data server
    Click to expand
  • RM#3 optical disc: no steganography in images and no malicious content (macros/JS/OLE exploits) in documents
    Click to expand
0
Techniques
0
Tactics
0
Findings Mapped
Reconnaissance
Resource Development
Initial Access1
Execution
Persistence3
Privilege Escalation2
Defense Evasion4
Credential Access
Discovery
Lateral Movement
Collection2
Command and Control
Exfiltration4
Impact
Inhibit Response Function
Evasion
Impair Process Control
Initial Access
Valid Accounts
1F
Persistence
Valid Accounts
1F
Account Manipulation
1F
Local Account
1F
Privilege Escalation
Valid Accounts
1F
Account Manipulation
1F
Defense Evasion
Match Legitimate Resource Name or Location
2F
Clear Linux or Mac System Logs
1F
File Deletion
2F
Valid Accounts
1F
Collection
Data from Network Shared Drive
1F
Local Data Staging
1F
Exfiltration
Automated Exfiltration
2F
Data Transfer Size Limits
1F
Exfiltration over USB
2F
Exfiltration to Cloud Storage
4F
0
Total IOCs
0
External IPs
0
File IOCs
0
Emails
Network IOCs (1)
TypeValueEnrichmentContextActions
Internal IP 10.11.11.128 Sensitive "Secret Project Data" copied from network share \\10.11.11.128\secured VT
File IOCs (4)
TypeValueEnrichmentContextActions
Path C:\Users\informant\Desktop\Download\Eraser Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed a
Path C:\Program Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed a
Path C:\Users\informant\Downloads\googledrivesync.exe Google Drive cloud sync client installed and run; user researched cloud-storage
Path C:\Users\informant\Google Google Drive cloud sync client installed and run; user researched cloud-storage
Email IOCs (5)
TypeValueEnrichmentContextActions
Email eric_p._lauer@omb.eop.gov External emails, domains, and IPs on disk that represent potential exfiltration
Email iaman.informant@nist.gov External emails, domains, and IPs on disk that represent potential exfiltration
Email iaman@nist.gov External emails, domains, and IPs on disk that represent potential exfiltration
Email scarter@gmail.com External emails, domains, and IPs on disk that represent potential exfiltration
Email erovira@gmail.com External emails, domains, and IPs on disk that represent potential exfiltration
Select a source
Select a source from the tree to view raw evidence output.
Source Name Extractor Lines Hash Referenced By
tsk.partitions sleuthkit 8 blake2b:3eed10c8...
tsk.fsstat sleuthkit 37 blake2b:2d2079ee...
tsk.filelist sleuthkit 27 blake2b:ae86d6dd... 3 findings
tsk.timeline sleuthkit 67 blake2b:822b5179...
tsk.masquerade sleuthkit 0 blake2b:empty... 4 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:76c8c9e9...
bulk.domain bulk_extractor 189 blake2b:ae916b75... 3 findings
bulk.duplicates bulk_extractor 9 blake2b:bb406faf...
bulk.url bulk_extractor 207 blake2b:039de0b6... 2 findings
bulk.url_services bulk_extractor 14 blake2b:2eac1377... 2 findings
binwalk.scan binwalk 0 blake2b:empty... 2 findings
exiftool.metadata exiftool 9 blake2b:b39315d4... 2 findings
hashdeep.hashes hashdeep 6 blake2b:0e07b059...
strings.output strings 22065 blake2b:9705a003...
tsk.partitions sleuthkit 9 blake2b:83c0b87c...
tsk.filelist sleuthkit 51 blake2b:55fc9962... 3 findings
tsk.partitions sleuthkit 10 blake2b:67b9085f...
tsk.fsstat sleuthkit 39 blake2b:ac3885f3...
tsk.filelist sleuthkit 104709 blake2b:171e0914... 3 findings
tsk.filelist.p1 sleuthkit 93 blake2b:5bdfadd3... 3 findings
tsk.timeline sleuthkit 344089 blake2b:4cc4645b...
bulk.bulk_extractor bulk_extractor 1 blake2b:2d7a1e96...
bulk.domain bulk_extractor 264 blake2b:c8b97b94... 3 findings
bulk.duplicates bulk_extractor 9 blake2b:9ba9de0c...
bulk.email bulk_extractor 43 blake2b:eb085c00... 1 finding
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9...
bulk.url bulk_extractor 288 blake2b:d727c498... 2 findings
bulk.url_services bulk_extractor 19 blake2b:01e609ea... 2 findings
vshadow.info vshadowinfo 1 blake2b:64c0f8d0... 1 finding
tsk.masquerade sleuthkit 17 blake2b:97440a18... 4 findings
bulk.alerts bulk_extractor 7 blake2b:75914a77...
bulk.bulk_extractor bulk_extractor 1 blake2b:dc1eb377...
bulk.ccn bulk_extractor 263 blake2b:23fa15b5...
bulk.domain bulk_extractor 366963 blake2b:74e7e245... 3 findings
bulk.duplicates bulk_extractor 12 blake2b:f8b9f6c0...
bulk.email bulk_extractor 6851 blake2b:498a4ff6... 1 finding
bulk.ether bulk_extractor 6 blake2b:0825117f...
bulk.exif bulk_extractor 793 blake2b:2158d20a...
bulk.rfc822 bulk_extractor 7326 blake2b:38720e75...
bulk.sin bulk_extractor 54 blake2b:e85ef814...
bulk.telephone bulk_extractor 2326 blake2b:3e8a1090...
bulk.url bulk_extractor 421750 blake2b:cbee79de... 2 findings
bulk.url_facebook-address bulk_extractor 19 blake2b:7fe55073... 2 findings
bulk.url_searches bulk_extractor 155 blake2b:b928562c... 3 findings
bulk.url_services bulk_extractor 3637 blake2b:c01e89c3... 2 findings
exiftool.metadata exiftool 9 blake2b:a0e4740f... 2 findings
tsk.masquerade sleuthkit 3 blake2b:42bb5e7d... 4 findings
ez.mft eztools 98918 blake2b:79311f1d... 2 findings
pcap.disk.atiumd6a tshark 8 blake2b:a8b87544... 1 finding
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
evtx.manifest evtx-extract 54 blake2b:62bd3681...
registry.query.software python-registry 1 blake2b:07529315...
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
pcap.disk.atiumdva tshark 8 blake2b:6cfc822f...
registry.query.system python-registry 1 blake2b:3ab1cb9e...
pcap.disk.atiumd6a tshark 8 blake2b:a8b87544... 1 finding
ez.shimcache eztools 307 blake2b:ee0a740e... 3 findings
registry.query.system python-registry 1 blake2b:106b833a...
registry.query.system python-registry 1 blake2b:8639046c...
pcap.disk.atiumdva tshark 8 blake2b:6cfc822f...
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
appfiles.*google_drive*.desktop.ini icat 6 blake2b:a76b0467...
registry.default regripper 418 blake2b:c385c021...
pcap.disk.atiumd6a tshark 8 blake2b:a8b87544... 1 finding
registry.system regripper 186 blake2b:dbba0bf5... 3 findings
registry.system regripper 7 blake2b:e4c6f012... 3 findings
pcap.disk.atiumdva tshark 8 blake2b:6cfc822f...
registry.system regripper 7 blake2b:e4c6f012... 3 findings
registry.system regripper 69 blake2b:6b7bf22c... 3 findings
registry.system regripper 8 blake2b:3c5e87f4... 3 findings
registry.system regripper 33492 blake2b:5f8ab549... 3 findings
registry.system regripper 283 blake2b:7d8bde12... 3 findings
registry.system regripper 283 blake2b:7906603d... 3 findings
registry.system regripper 5209 blake2b:c177099c... 3 findings
registry.system regripper 199 blake2b:1f223ee3... 3 findings
registry.system regripper 199 blake2b:7b5f05e5... 3 findings
registry.system regripper 381 blake2b:070a4d56... 3 findings
registry.system regripper 255 blake2b:0d77cf74... 3 findings
registry.system regripper 255 blake2b:0d77cf74... 3 findings
registry.usrclass.admin11 regripper 11 blake2b:26a43778...
registry.ntuser.admin11 regripper 133 blake2b:bf617a09... 1 finding
registry.ntuser.default regripper 74 blake2b:8518dc3f...
registry.usrclass.informant regripper 102 blake2b:9f1344c3... 3 findings
registry.ntuser.informant regripper 306 blake2b:597d71cd... 3 findings
registry.usrclass.temporary regripper 15 blake2b:3ef5eb22...
registry.ntuser.temporary regripper 118 blake2b:800424ee... 1 finding
hayabusa.alerts hayabusa 35 blake2b:afc63957... 1 finding
appfiles.*outlook*.fc39fbc8c85bcb43816b40b7d4c72f22_-_autodiscover.xml icat 129 blake2b:5ea6b3bf...
appfiles.*outlook*.firstrun.log icat 13 blake2b:685452c9...
appfiles.*outlook*.outlook.xml icat 48 blake2b:5ebeaab3...
appfiles.*outlook*.outlookmui.xml icat 67 blake2b:4af3f61d...
appfiles.*outlook*.setup.xml icat 53 blake2b:47b8b844...
appfiles.*outlook*.yahoo.com.ar.xml icat 25 blake2b:9e6ebebe...
appfiles.*outlook*.ameritech.net.xml icat 25 blake2b:da89ea41...
appfiles.*outlook*.btinternet.net.xml icat 25 blake2b:4ace5e32...
appfiles.*outlook*.btopenworld.com.xml icat 25 blake2b:e93b45f3...
appfiles.*outlook*.flash.net.xml icat 25 blake2b:5d785c6c...
appfiles.*outlook*.gmail.com.xml icat 25 blake2b:320ab73e...
appfiles.*outlook*.nl.rogers.com.xml icat 25 blake2b:6e5aa261...
appfiles.*outlook*.nvbell.net.xml icat 25 blake2b:8c1e168b...
appfiles.*outlook*.pacbell.net.xml icat 25 blake2b:5b927c96...
appfiles.*outlook*.prodigy.net.xml icat 25 blake2b:5c0043bc...
appfiles.*outlook*.rogers.com.xml icat 25 blake2b:d6fcba9f...
appfiles.*outlook*.sbcglobal.net.xml icat 25 blake2b:1473b28b...
appfiles.*outlook*.snet.net.xml icat 25 blake2b:3b370adb...
appfiles.*outlook*.swbell.net.xml icat 25 blake2b:016a4f1b...
appfiles.*outlook*.talk21.com.xml icat 25 blake2b:642de72e...
appfiles.*outlook*.wans.net.xml icat 25 blake2b:55c18629...
appfiles.*outlook*.yahoo.com.au.xml icat 25 blake2b:115de104...
appfiles.*outlook*.yahoo.com.xml icat 25 blake2b:5c2443a5...
appfiles.*outlook*.yahoo.ca.xml icat 25 blake2b:1a48bfe8...
appfiles.*outlook*.yahoo.co.id.xml icat 25 blake2b:41b50605...
appfiles.*outlook*.yahoo.co.in.xml icat 25 blake2b:58ab44cc...
appfiles.*outlook*.yahoo.co.jp.xml icat 25 blake2b:4ea25151...
appfiles.*outlook*.yahoo.co.kr.xml icat 25 blake2b:a0a75647...
appfiles.*outlook*.yahoo.co.nz.xml icat 25 blake2b:4f41f193...
appfiles.*outlook*.yahoo.co.th.xml icat 25 blake2b:483738ff...
appfiles.*outlook*.yahoo.co.uk.xml icat 25 blake2b:056fe40b...
appfiles.*outlook*.yahoo.com.br.xml icat 25 blake2b:702ecfe7...
appfiles.*outlook*.yahoo.com.cn.xml icat 25 blake2b:5ce30f36...
appfiles.*outlook*.yahoo.com.hk.xml icat 25 blake2b:2b949740...
appfiles.*outlook*.yahoo.com.mx.xml icat 25 blake2b:faccb5e7...
appfiles.*outlook*.yahoo.com.my.xml icat 25 blake2b:ca23d507...
appfiles.*outlook*.yahoo.com.ph.xml icat 25 blake2b:83ff3879...
appfiles.*outlook*.yahoo.com.sg.xml icat 25 blake2b:e870c702...
appfiles.*outlook*.yahoo.com.tw.xml icat 25 blake2b:c8697328...
appfiles.*outlook*.yahoo.com.vn.xml icat 25 blake2b:f129e3d1...
appfiles.*outlook*.yahoo.de.xml icat 25 blake2b:77585e03...
appfiles.*outlook*.yahoo.es.xml icat 25 blake2b:f7e0d39e...
appfiles.*outlook*.yahoo.fr.xml icat 25 blake2b:79ff62a0...
appfiles.*outlook*.yahoo.hk.xml icat 25 blake2b:870a813e...
appfiles.*outlook*.yahoo.ie.xml icat 25 blake2b:44aef8ac...
appfiles.*outlook*.yahoo.it.xml icat 25 blake2b:a7b39844...
appfiles.*outlook*.yahoo.jp.xml icat 25 blake2b:de082dd0...
appfiles.*outlook*.yahoo.no.xml icat 25 blake2b:b8e902c6...
appfiles.*outlook*.yahoo.pl.xml icat 25 blake2b:3eb059cf...
appfiles.*outlook*.yahoo.se.xml icat 25 blake2b:e9c72ae1...
appfiles.*outlook*.fc39fbc8c85bcb43816b40b7d4c72f22_-_autodiscover.xml icat 129 blake2b:5ea6b3bf...
appfiles.*outlook*.firstrun.log icat 13 blake2b:685452c9...
appfiles.*outlook*.outlook.xml icat 48 blake2b:5ebeaab3...
appfiles.*outlook*.outlookmui.xml icat 67 blake2b:4af3f61d...
appfiles.*outlook*.setup.xml icat 53 blake2b:47b8b844...
appfiles.*outlook*.yahoo.com.ar.xml icat 25 blake2b:9e6ebebe...
appfiles.*outlook*.ameritech.net.xml icat 25 blake2b:da89ea41...
appfiles.*outlook*.btinternet.net.xml icat 25 blake2b:4ace5e32...
appfiles.*outlook*.btopenworld.com.xml icat 25 blake2b:e93b45f3...
appfiles.*outlook*.flash.net.xml icat 25 blake2b:5d785c6c...
appfiles.*outlook*.gmail.com.xml icat 25 blake2b:320ab73e...
appfiles.*outlook*.nl.rogers.com.xml icat 25 blake2b:6e5aa261...
appfiles.*outlook*.nvbell.net.xml icat 25 blake2b:8c1e168b...
appfiles.*outlook*.pacbell.net.xml icat 25 blake2b:5b927c96...
appfiles.*outlook*.prodigy.net.xml icat 25 blake2b:5c0043bc...
appfiles.*outlook*.rogers.com.xml icat 25 blake2b:d6fcba9f...
appfiles.*outlook*.sbcglobal.net.xml icat 25 blake2b:1473b28b...
appfiles.*outlook*.snet.net.xml icat 25 blake2b:3b370adb...
appfiles.*outlook*.swbell.net.xml icat 25 blake2b:016a4f1b...
appfiles.*outlook*.talk21.com.xml icat 25 blake2b:642de72e...
appfiles.*outlook*.wans.net.xml icat 25 blake2b:55c18629...
appfiles.*outlook*.yahoo.com.au.xml icat 25 blake2b:115de104...
appfiles.*outlook*.yahoo.com.xml icat 25 blake2b:5c2443a5...
appfiles.*outlook*.yahoo.ca.xml icat 25 blake2b:1a48bfe8...
appfiles.*outlook*.yahoo.co.id.xml icat 25 blake2b:41b50605...
appfiles.*outlook*.yahoo.co.in.xml icat 25 blake2b:58ab44cc...
appfiles.*outlook*.yahoo.co.jp.xml icat 25 blake2b:4ea25151...
appfiles.*outlook*.yahoo.co.kr.xml icat 25 blake2b:a0a75647...
appfiles.*outlook*.yahoo.co.nz.xml icat 25 blake2b:4f41f193...
appfiles.*outlook*.yahoo.co.th.xml icat 25 blake2b:483738ff...
appfiles.*outlook*.yahoo.co.uk.xml icat 25 blake2b:056fe40b...
appfiles.*outlook*.yahoo.com.br.xml icat 25 blake2b:702ecfe7...
appfiles.*outlook*.yahoo.com.cn.xml icat 25 blake2b:5ce30f36...
appfiles.*outlook*.yahoo.com.hk.xml icat 25 blake2b:2b949740...
appfiles.*outlook*.yahoo.com.mx.xml icat 25 blake2b:faccb5e7...
appfiles.*outlook*.yahoo.com.my.xml icat 25 blake2b:ca23d507...
appfiles.*outlook*.yahoo.com.ph.xml icat 25 blake2b:83ff3879...
appfiles.*outlook*.yahoo.com.sg.xml icat 25 blake2b:e870c702...
appfiles.*outlook*.yahoo.com.tw.xml icat 25 blake2b:c8697328...
appfiles.*outlook*.yahoo.com.vn.xml icat 25 blake2b:f129e3d1...
appfiles.*outlook*.yahoo.de.xml icat 25 blake2b:77585e03...
appfiles.*outlook*.yahoo.es.xml icat 25 blake2b:f7e0d39e...
appfiles.*outlook*.yahoo.fr.xml icat 25 blake2b:79ff62a0...
appfiles.*outlook*.yahoo.hk.xml icat 25 blake2b:870a813e...
appfiles.*outlook*.yahoo.ie.xml icat 25 blake2b:44aef8ac...
appfiles.*outlook*.yahoo.it.xml icat 25 blake2b:a7b39844...
appfiles.*outlook*.yahoo.jp.xml icat 25 blake2b:de082dd0...
appfiles.*outlook*.yahoo.no.xml icat 25 blake2b:b8e902c6...
appfiles.*outlook*.yahoo.pl.xml icat 25 blake2b:3eb059cf...
appfiles.*outlook*.yahoo.se.xml icat 25 blake2b:e9c72ae1...
appfiles.*outlook*.fc39fbc8c85bcb43816b40b7d4c72f22_-_autodiscover.xml icat 129 blake2b:5ea6b3bf...
appfiles.*outlook*.firstrun.log icat 13 blake2b:685452c9...
appfiles.*outlook*.outlook.xml icat 48 blake2b:5ebeaab3...
appfiles.*outlook*.outlookmui.xml icat 67 blake2b:4af3f61d...
appfiles.*outlook*.setup.xml icat 53 blake2b:47b8b844...
appfiles.*outlook*.yahoo.com.ar.xml icat 25 blake2b:9e6ebebe...
appfiles.*outlook*.ameritech.net.xml icat 25 blake2b:da89ea41...
appfiles.*outlook*.btinternet.net.xml icat 25 blake2b:4ace5e32...
appfiles.*outlook*.btopenworld.com.xml icat 25 blake2b:e93b45f3...
appfiles.*outlook*.flash.net.xml icat 25 blake2b:5d785c6c...
appfiles.*outlook*.gmail.com.xml icat 25 blake2b:320ab73e...
appfiles.*outlook*.nl.rogers.com.xml icat 25 blake2b:6e5aa261...
appfiles.*outlook*.nvbell.net.xml icat 25 blake2b:8c1e168b...
appfiles.*outlook*.pacbell.net.xml icat 25 blake2b:5b927c96...
appfiles.*outlook*.prodigy.net.xml icat 25 blake2b:5c0043bc...
appfiles.*outlook*.rogers.com.xml icat 25 blake2b:d6fcba9f...
appfiles.*outlook*.sbcglobal.net.xml icat 25 blake2b:1473b28b...
appfiles.*outlook*.snet.net.xml icat 25 blake2b:3b370adb...
appfiles.*outlook*.swbell.net.xml icat 25 blake2b:016a4f1b...
appfiles.*outlook*.talk21.com.xml icat 25 blake2b:642de72e...
appfiles.*outlook*.wans.net.xml icat 25 blake2b:55c18629...
appfiles.*outlook*.yahoo.com.au.xml icat 25 blake2b:115de104...
appfiles.*outlook*.yahoo.com.xml icat 25 blake2b:5c2443a5...
appfiles.*outlook*.yahoo.ca.xml icat 25 blake2b:1a48bfe8...
appfiles.*outlook*.yahoo.co.id.xml icat 25 blake2b:41b50605...
appfiles.*outlook*.yahoo.co.in.xml icat 25 blake2b:58ab44cc...
appfiles.*outlook*.yahoo.co.jp.xml icat 25 blake2b:4ea25151...
appfiles.*outlook*.yahoo.co.kr.xml icat 25 blake2b:a0a75647...
appfiles.*outlook*.yahoo.co.nz.xml icat 25 blake2b:4f41f193...
appfiles.*outlook*.yahoo.co.th.xml icat 25 blake2b:483738ff...
appfiles.*outlook*.yahoo.co.uk.xml icat 25 blake2b:056fe40b...
appfiles.*outlook*.yahoo.com.br.xml icat 25 blake2b:702ecfe7...
appfiles.*outlook*.yahoo.com.cn.xml icat 25 blake2b:5ce30f36...
appfiles.*outlook*.yahoo.com.hk.xml icat 25 blake2b:2b949740...
appfiles.*outlook*.yahoo.com.mx.xml icat 25 blake2b:faccb5e7...
appfiles.*outlook*.yahoo.com.my.xml icat 25 blake2b:ca23d507...
appfiles.*outlook*.yahoo.com.ph.xml icat 25 blake2b:83ff3879...
appfiles.*outlook*.yahoo.com.sg.xml icat 25 blake2b:e870c702...
appfiles.*outlook*.yahoo.com.tw.xml icat 25 blake2b:c8697328...
appfiles.*outlook*.yahoo.com.vn.xml icat 25 blake2b:f129e3d1...
appfiles.*outlook*.yahoo.de.xml icat 25 blake2b:77585e03...
appfiles.*outlook*.yahoo.es.xml icat 25 blake2b:f7e0d39e...
appfiles.*outlook*.yahoo.fr.xml icat 25 blake2b:79ff62a0...
appfiles.*outlook*.yahoo.hk.xml icat 25 blake2b:870a813e...
appfiles.*outlook*.yahoo.ie.xml icat 25 blake2b:44aef8ac...
appfiles.*outlook*.yahoo.it.xml icat 25 blake2b:a7b39844...
appfiles.*outlook*.yahoo.jp.xml icat 25 blake2b:de082dd0...
appfiles.*outlook*.yahoo.no.xml icat 25 blake2b:b8e902c6...
appfiles.*outlook*.yahoo.pl.xml icat 25 blake2b:3eb059cf...
appfiles.*outlook*.yahoo.se.xml icat 25 blake2b:e9c72ae1...
chainsaw.hunt chainsaw 99 blake2b:f0815fc8... 1 finding
evtx.windows_system32_winevt_logs_microsoft-windows-windows-firewall-with-advanced-security4connectionsecurity eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-application-experience4program-inventory eztools 70 blake2b:603298e9...
evtx.windows_system32_winevt_logs_security eztools 1195 blake2b:a3e119c5... 2 findings
evtx.windows_system32_winevt_logs_microsoft-windows-application-experience4program-inventory eztools 70 blake2b:603298e9...
regripper.cfreds_2015_data_leakage_pc regripper 0 blake2b:empty...
exiftool.metadata exiftool 2 blake2b:8853a280... 2 findings
registry.query.system python-registry 1 blake2b:8639046c...
registry.query.system python-registry 1 blake2b:651ecc03...
registry.query.system python-registry 1 blake2b:106b833a...
composite.file_staging composite 578 blake2b:d514068a...
registry.query.system python-registry 1 blake2b:3ab1cb9e...
registry.query.system python-registry 1 blake2b:50c185a8...
registry.query.system python-registry 1 blake2b:9f595401...
optical.listing mulder-optical 58 blake2b:65ca19c0... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:c4f0c389...
bulk.domain bulk_extractor 237 blake2b:29444e46... 3 findings
bulk.email bulk_extractor 12 blake2b:26c081a6... 1 finding
bulk.rfc822 bulk_extractor 41 blake2b:e3da4d10...
bulk.url bulk_extractor 300 blake2b:28d82359... 2 findings
bulk.url_services bulk_extractor 21 blake2b:6224c8f2... 2 findings
exiftool.metadata exiftool 934 blake2b:84a8c965... 2 findings
exiftool.metadata exiftool 934 blake2b:84a8c965... 2 findings
composite.timeline composite 172 blake2b:f4c4c609...
composite.defense_evasion composite 200 blake2b:8b436cef...
composite.lateral_movement composite 526 blake2b:c20e6e12...
composite.persistence composite 2438 blake2b:4b9f0a6f...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 578 blake2b:d514068a...
composite.exfil composite 2551 blake2b:8722cfcf...
composite.execution composite 122 blake2b:dd320f71...
composite.correlation composite 1 blake2b:c7895920...
composite.correlation composite 1 blake2b:c2ccfde7...
composite.correlation composite 1 blake2b:ecdd3446...
composite.correlation composite 1 blake2b:c1cabcad...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.correlation composite 1 blake2b:faa9c9a3...
0
Tool Calls
0
Unique Tools
1489.7s
Processing Time
196,896
Tokens
7,930
Tokens/min
Tool Distribution
Token Breakdown
Input Tokens3,780
Output Tokens193,116
Total Tokens196,896
Per-Model Breakdown
bedrock/us.moonshotai.kimi-k3196,896
Token Throughput Over Time
Estimated token consumption by model over time. Each bar represents a 5-minute window.
ID Tool Duration Timestamp Actions
tc_5ee75f83 scan_evidence 1949ms 2026-09-19T19:54:59
tc_2b0144d0 list_sources 2ms 2026-09-19T19:55:01
tc_37d53557 list_directory 2ms 2026-09-19T19:55:01
tc_312f86bf get_source_stats 2ms 2026-09-19T19:55:02
tc_ed9904dd open_case 28ms 2026-09-19T19:55:08
tc_40b7dfe8 open_case 28ms 2026-09-19T19:55:08
tc_a5effbc5 open_case 33ms 2026-09-19T19:55:08
tc_609d2367 list_directory 2ms 2026-09-19T19:55:09
tc_da1b2d97 open_case 27ms 2026-09-19T19:55:21
tc_fed79459 start_extraction_batch 9ms 2026-09-19T19:55:24
tc_46a4baf5 run_mmls 38ms 2026-09-19T19:55:24
tc_4ec4b663 run_fsstat 72ms 2026-09-19T19:55:24
tc_721abc75 run_fls 3231ms 2026-09-19T19:55:27
tc_18f164ad run_mactime 3312ms 2026-09-19T19:55:27
tc_042f0485 detect_masquerading 3325ms 2026-09-19T19:55:27
tc_76ce80be run_bulk_extractor 40118ms 2026-09-19T19:56:04
tc_b57c629d get_completed_results 0ms 2026-09-19T19:56:05
tc_a2e5e66d start_extraction_batch 11ms 2026-09-19T19:56:08
tc_d82a9634 detect_steganography 13ms 2026-09-19T19:56:08
tc_9c0156b6 run_photorec 5ms 2026-09-19T19:56:08
tc_410642bc run_binwalk 57ms 2026-09-19T19:56:08
tc_5e96992d run_exiftool 90ms 2026-09-19T19:56:08
tc_71dd0292 run_hashdeep 357ms 2026-09-19T19:56:08
tc_c2986c49 run_strings 600ms 2026-09-19T19:56:08
tc_c74426b5 open_case 27ms 2026-09-19T19:56:09
tc_a3ab294e open_case 26ms 2026-09-19T19:56:10
tc_51d5d233 run_mmls 45ms 2026-09-19T19:56:11
tc_8bd4c690 start_extraction_batch 4ms 2026-09-19T19:56:11
tc_5c30e8d0 run_fls 975ms 2026-09-19T19:56:12
tc_0734363a start_extraction_batch 9ms 2026-09-19T19:56:12
tc_f763c10a run_mmls 49ms 2026-09-19T19:56:13
tc_f2489c5f run_fsstat 101ms 2026-09-19T19:56:13
tc_230bd2b9 yara_scan_files 5560ms 2026-09-19T19:56:13
tc_0e6d8a6e get_completed_results 0ms 2026-09-19T19:56:14
tc_3f1d411c open_case 49ms 2026-09-19T19:56:22
tc_8b2a2bc6 get_investigation_summary 13ms 2026-09-19T19:56:23
tc_27676fbc list_sources 1ms 2026-09-19T19:56:23
tc_f607faba run_fls 10922ms 2026-09-19T19:56:23
tc_3f4a6c40 run_mactime 25317ms 2026-09-19T19:56:38
tc_48d7503d run_bulk_extractor 72429ms 2026-09-19T19:57:24
tc_f861d702 get_completed_results 0ms 2026-09-19T19:57:25
tc_05692a81 query_registry_value 0ms 2026-09-19T19:58:38
tc_a5a3c257 get_raw_output 28ms 2026-09-19T19:59:55
tc_bbedef4d get_raw_output 30ms 2026-09-19T19:59:55
tc_fb1d6906 query_registry_value 0ms 2026-09-19T20:00:00
tc_ff7f0b1b query_registry_value 0ms 2026-09-19T20:00:01
tc_bd066b4f get_raw_output 5ms 2026-09-19T20:00:02
tc_8e0ea6ce get_raw_output 8ms 2026-09-19T20:00:03
tc_6f4bc3c1 list_files 218ms 2026-09-19T20:00:04
tc_ed394fe9 get_deleted_files 261ms 2026-09-19T20:00:05
tc_f167fbdd parse_browser_history 7941ms 2026-09-19T20:00:09
tc_52caf67e start_extraction_batch 14ms 2026-09-19T20:00:09
tc_dec823a9 run_vshadow_info 35ms 2026-09-19T20:00:09
tc_92953092 run_mft_parser 52ms 2026-09-19T20:00:09
tc_8ed13eb7 search 5ms 2026-09-19T20:00:11
tc_fbb37699 search 3ms 2026-09-19T20:00:11
tc_78286446 run_amcache_parser 3487ms 2026-09-19T20:00:12
tc_e5e42ba1 get_raw_output 5ms 2026-09-19T20:00:13
tc_a8bbf628 index_app_files 3389ms 2026-09-19T20:00:16
tc_889c46f5 search 4ms 2026-09-19T20:00:16
tc_4beaacd8 run_shimcache_parser 7712ms 2026-09-19T20:00:17
tc_6cf1ece0 search 3ms 2026-09-19T20:00:18
tc_d19e26d1 run_evtx_parser 0ms 2026-09-19T20:00:18
tc_0e1cb699 search 3ms 2026-09-19T20:00:18
tc_fc0769df detect_masquerading 5022ms 2026-09-19T20:00:19
tc_f1b68d6c search 5ms 2026-09-19T20:00:20
tc_fd98f41b search 3ms 2026-09-19T20:00:22
tc_d55af79c search 3ms 2026-09-19T20:00:22
tc_7e65817b index_app_files 8364ms 2026-09-19T20:00:24
tc_1d4c29eb search 3ms 2026-09-19T20:00:24
tc_264a5872 search 3ms 2026-09-19T20:00:24
tc_07f68e04 search 3ms 2026-09-19T20:00:24
tc_26db0e97 run_prefetch_parser 16502ms 2026-09-19T20:00:25
tc_f3efeb88 index_app_files 11996ms 2026-09-19T20:00:26
tc_d0a88be5 get_raw_output 25ms 2026-09-19T20:00:27
tc_dce1b81b get_raw_output 18ms 2026-09-19T20:00:27
tc_b35a907c index_app_files 13383ms 2026-09-19T20:00:27
tc_f74ca445 run_registry_parser 14764ms 2026-09-19T20:00:29
tc_a1944275 get_raw_output 22ms 2026-09-19T20:00:30
tc_a3515235 get_raw_output 22ms 2026-09-19T20:00:30
tc_d7042ab7 index_app_files 13706ms 2026-09-19T20:00:30
tc_9fc9dcfb index_app_files 14347ms 2026-09-19T20:00:33
tc_acabc9b1 index_app_files 10327ms 2026-09-19T20:00:36
tc_975d7113 index_app_files 11684ms 2026-09-19T20:00:36
tc_0b472c09 index_app_files 20069ms 2026-09-19T20:00:38
tc_82ebfdb2 yara_scan_files 15373ms 2026-09-19T20:00:42
tc_d2b197a7 get_completed_results 0ms 2026-09-19T20:00:43
tc_f2524beb run_bulk_extractor 273035ms 2026-09-19T20:00:46
tc_7b277290 get_fs_timeline 14ms 2026-09-19T20:00:47
tc_a37c581c get_raw_output 26ms 2026-09-19T20:00:47
tc_ce30b39a query_registry_value 0ms 2026-09-19T20:00:49
tc_fe0bf617 query_registry_value 0ms 2026-09-19T20:00:51
tc_2b398b57 query_registry_value 0ms 2026-09-19T20:00:51
tc_d5d5db26 run_hindsight 0ms 2026-09-19T20:00:54
tc_16ca5071 detect_steganography 1ms 2026-09-19T20:00:54
tc_6b10c97c run_exiftool 74ms 2026-09-19T20:00:54
tc_5c59cd85 get_timeline 2ms 2026-09-19T20:00:54
tc_15d84e45 detect_steganography 0ms 2026-09-19T20:00:54
tc_b4bbbbb6 open_case 40ms 2026-09-19T20:01:04
tc_9797d285 list_sources 2ms 2026-09-19T20:01:05
tc_620b4cff search 3ms 2026-09-19T20:01:06
tc_537ed705 search 3ms 2026-09-19T20:01:06
tc_e2ff2920 search 4ms 2026-09-19T20:01:10
tc_aebd94dd search 3ms 2026-09-19T20:01:10
tc_ffb592e0 get_raw_output 51ms 2026-09-19T20:01:11
tc_6f56cfa2 get_raw_output 6ms 2026-09-19T20:01:11
tc_62a66069 get_raw_output 52ms 2026-09-19T20:01:13
tc_95cf879d get_raw_output 7ms 2026-09-19T20:01:14
tc_2677da61 detect_masquerading 300053ms 2026-09-19T20:01:18
tc_30c7e4f6 get_raw_output 6ms 2026-09-19T20:01:18
tc_408851e7 get_completed_results 0ms 2026-09-19T20:01:19
tc_3401dec5 get_raw_output 27ms 2026-09-19T20:01:23
tc_87d8775a get_raw_output 27ms 2026-09-19T20:01:23
tc_38bfba07 start_extraction_batch 22ms 2026-09-19T20:01:24
tc_20be2431 run_photorec 14ms 2026-09-19T20:01:24
tc_42c6da6e parse_autoruns 46ms 2026-09-19T20:01:24
tc_f7b74f7b get_raw_output 56ms 2026-09-19T20:01:27
tc_304fb623 get_raw_output 56ms 2026-09-19T20:01:27
tc_b6133f19 get_raw_output 56ms 2026-09-19T20:01:30
tc_003dd69f get_raw_output 57ms 2026-09-19T20:01:30
tc_1b6a2376 search 2ms 2026-09-19T20:01:33
tc_14227f37 search 3ms 2026-09-19T20:01:33
tc_b0cd2903 list_files 175ms 2026-09-19T20:01:37
tc_e37b9664 get_raw_output 58ms 2026-09-19T20:01:37
tc_b40a7206 index_app_files 13846ms 2026-09-19T20:01:37
tc_3ff4d925 run_amcache_parser 0ms 2026-09-19T20:01:38
tc_dedc50a4 index_app_files 15050ms 2026-09-19T20:01:39
tc_41e2dabd search 4ms 2026-09-19T20:01:40
tc_9de9d5dc search 3ms 2026-09-19T20:01:40
tc_bb41046c index_app_files 3818ms 2026-09-19T20:01:41
tc_a780502f get_raw_output 9ms 2026-09-19T20:01:44
tc_4858ed8c search 3ms 2026-09-19T20:01:46
tc_3ee07a3e search 3ms 2026-09-19T20:01:47
tc_129cec57 parse_browser_history 23644ms 2026-09-19T20:01:47
tc_339fc4f7 run_mft_parser 24773ms 2026-09-19T20:01:48
tc_0bc5f5d3 run_evtx_parser 24780ms 2026-09-19T20:01:48
tc_cc6648e1 query_registry_value 24752ms 2026-09-19T20:01:48
tc_381b5344 search 339ms 2026-09-19T20:01:51
tc_35362869 search 171ms 2026-09-19T20:01:51
tc_9c83abf5 query_registry_value 28335ms 2026-09-19T20:01:52
tc_23dddfd9 search 3ms 2026-09-19T20:01:52
tc_637fb31f search 2ms 2026-09-19T20:01:52
tc_b2212be9 run_shimcache_parser 29185ms 2026-09-19T20:01:53
tc_915f103a query_registry_value 29278ms 2026-09-19T20:01:53
tc_558caae2 query_registry_value 29650ms 2026-09-19T20:01:53
tc_1e865c96 index_app_files 30820ms 2026-09-19T20:01:54
tc_6cdb0a86 analyze_disk_pcaps 33422ms 2026-09-19T20:01:57
tc_187564a4 search 271ms 2026-09-19T20:01:57
tc_dac66329 search 3ms 2026-09-19T20:01:57
tc_82d556c8 run_prefetch_parser 34004ms 2026-09-19T20:01:58
tc_9d123f06 search 3ms 2026-09-19T20:02:02
tc_44939d10 search 3ms 2026-09-19T20:02:02
tc_6096b717 get_raw_output 7ms 2026-09-19T20:02:06
tc_aa6a6c40 search 4ms 2026-09-19T20:02:07
tc_e5751268 get_raw_output 7ms 2026-09-19T20:02:08
tc_8b5b70c4 get_raw_output 11ms 2026-09-19T20:02:13
tc_20fd8dd5 run_registry_parser 52873ms 2026-09-19T20:02:16
tc_119a1b62 search 4ms 2026-09-19T20:02:18
tc_3c4c1819 get_completed_results 0ms 2026-09-19T20:02:18
tc_b9a4c319 run_photorec 2ms 2026-09-19T20:02:20
tc_f7913bd7 get_raw_output 11ms 2026-09-19T20:02:21
tc_eaf6e5d7 search 202ms 2026-09-19T20:02:22
tc_1c99f032 search 269ms 2026-09-19T20:02:22
tc_e3c3c493 search 3ms 2026-09-19T20:02:27
tc_50dd69db run_hayabusa 10679ms 2026-09-19T20:02:35
tc_1dd92c90 get_timeline 2ms 2026-09-19T20:02:37
tc_aeae69f7 search 2ms 2026-09-19T20:02:37
tc_bfe4bedd index_app_files 2775ms 2026-09-19T20:02:38
tc_6d771eb4 get_raw_output 7ms 2026-09-19T20:02:38
tc_96e03ec5 index_app_files 7902ms 2026-09-19T20:02:43
tc_6240a95f index_app_files 8222ms 2026-09-19T20:02:43
tc_cd450de8 index_app_files 8451ms 2026-09-19T20:02:43
tc_5231d1aa index_app_files 9365ms 2026-09-19T20:02:44
tc_cc9c1c45 index_app_files 5351ms 2026-09-19T20:02:45
tc_8d871944 search 3ms 2026-09-19T20:02:47
tc_42d65bad search 3ms 2026-09-19T20:02:47
tc_f1d8f36c search 3ms 2026-09-19T20:02:52
tc_64dfac60 get_raw_output 66ms 2026-09-19T20:02:53
tc_76fbc27e search 197ms 2026-09-19T20:02:53
tc_77169bc1 index_app_files 22212ms 2026-09-19T20:02:57
tc_8363a50f run_chainsaw 1281ms 2026-09-19T20:03:01
tc_e80f23b7 index_evtx_file 1130ms 2026-09-19T20:03:02
tc_8b86a213 get_raw_output 7ms 2026-09-19T20:03:04
tc_97844c8d index_evtx_file 1637ms 2026-09-19T20:03:05
tc_e2f37536 run_regripper 41ms 2026-09-19T20:03:08
tc_ea16196e parse_pst 0ms 2026-09-19T20:03:08
tc_0e729179 run_hindsight 0ms 2026-09-19T20:03:08
tc_c1ca2619 run_exiftool 77ms 2026-09-19T20:03:10
tc_00488acf search 134ms 2026-09-19T20:03:15
tc_553cdb5f search 5ms 2026-09-19T20:03:15
tc_3bc8fa21 search 3ms 2026-09-19T20:03:15
tc_16d4118f yara_scan_files 5483ms 2026-09-19T20:03:16
tc_f50fea9c detect_steganography 0ms 2026-09-19T20:03:18
tc_ac1053e4 get_raw_output 7ms 2026-09-19T20:03:21
tc_9909a91f search 192ms 2026-09-19T20:03:23
tc_4749446a search 4ms 2026-09-19T20:03:23
tc_86b1c259 open_case 30ms 2026-09-19T20:03:30
tc_200e2c15 wait_all 0ms 2026-09-19T20:03:31
tc_513ffe09 search 3ms 2026-09-19T20:03:31
tc_43ff6ac0 open_case 28ms 2026-09-19T20:03:36
tc_80288e0e get_investigation_summary 5ms 2026-09-19T20:03:37
tc_39e8d411 list_sources 3ms 2026-09-19T20:03:37
tc_bc5aaf49 search 5ms 2026-09-19T20:03:40
tc_99b90ef1 search 2ms 2026-09-19T20:03:40
tc_e3344b78 search 2ms 2026-09-19T20:03:40
tc_24c2ef91 query_registry_value 4372ms 2026-09-19T20:03:42
tc_f874bc29 get_raw_output 61ms 2026-09-19T20:03:42
tc_be1ca777 get_raw_output 62ms 2026-09-19T20:03:43
tc_c10c47d2 get_raw_output 62ms 2026-09-19T20:03:43
tc_703e5fe9 get_raw_output 61ms 2026-09-19T20:03:43
tc_b5164d42 search 5ms 2026-09-19T20:03:45
tc_af1593e0 get_raw_output 61ms 2026-09-19T20:03:45
tc_d9080fe7 get_raw_output 61ms 2026-09-19T20:03:45
tc_17f8e125 search 3ms 2026-09-19T20:03:48
tc_5bfdf0b3 get_deleted_files 184ms 2026-09-19T20:03:49
tc_67d2b070 get_raw_output 64ms 2026-09-19T20:03:49
tc_507831a1 search 3ms 2026-09-19T20:03:52
tc_afc4e438 search 4ms 2026-09-19T20:03:52
tc_172a2a08 search 4ms 2026-09-19T20:03:53
tc_fd4b9d26 get_raw_output 7ms 2026-09-19T20:03:54
tc_1f4618b9 get_raw_output 62ms 2026-09-19T20:03:56
tc_4677eefe search 4ms 2026-09-19T20:03:56
tc_8e51e7be search 3ms 2026-09-19T20:03:58
tc_c76b6d9d query_registry_value 4322ms 2026-09-19T20:04:01
tc_ee4fbf63 search 3ms 2026-09-19T20:04:02
tc_9cfc19d9 search 4ms 2026-09-19T20:04:02
tc_596c367a search 3ms 2026-09-19T20:04:02
tc_6ebe482e get_raw_output 7ms 2026-09-19T20:04:02
tc_427964db query_registry_value 4301ms 2026-09-19T20:04:06
tc_617b6ed2 search 3ms 2026-09-19T20:04:07
tc_2b9aad81 list_partitions 1ms 2026-09-19T20:04:08
tc_c125644b search 2ms 2026-09-19T20:04:09
tc_252b3da9 search 6ms 2026-09-19T20:04:09
tc_dc701890 get_raw_output 7ms 2026-09-19T20:04:16
tc_fb3af364 search 3ms 2026-09-19T20:04:19
tc_7e682449 find_file_staging._search(tsk.filelist) 4ms 2026-09-19T20:04:19
tc_98d4b4e7 find_file_staging._search(ez.mft) 3ms 2026-09-19T20:04:19
tc_f7b0b7eb find_file_staging._query(tsk.filelist) 41ms 2026-09-19T20:04:20
tc_88ae1260 find_file_staging._query(ez.mft) 153ms 2026-09-19T20:04:20
tc_7576ccb5 find_file_staging._search(ez.mft) 16ms 2026-09-19T20:04:20
tc_f8d0a569 find_file_staging._search(ez.mft) 4ms 2026-09-19T20:04:20
tc_82f1da7c find_file_staging 558ms 2026-09-19T20:04:20
tc_b67c8492 search 4ms 2026-09-19T20:04:20
tc_d5ffe129 get_timeline 13ms 2026-09-19T20:04:26
tc_36b1f64a search 3ms 2026-09-19T20:04:26
tc_181f1c6b search 3ms 2026-09-19T20:04:29
tc_b99df9ac get_raw_output 7ms 2026-09-19T20:04:32
tc_c3514976 search 150ms 2026-09-19T20:04:33
tc_fee2be42 get_raw_output 61ms 2026-09-19T20:04:33
tc_0b4a431e get_raw_output 7ms 2026-09-19T20:04:35
tc_e6c6caee search 3ms 2026-09-19T20:04:38
tc_adf453b8 search 3ms 2026-09-19T20:04:38
tc_64b50931 search 3ms 2026-09-19T20:04:39
tc_4baf803d get_raw_output 62ms 2026-09-19T20:04:45
tc_c5260bf5 get_raw_output 62ms 2026-09-19T20:04:45
tc_dfbcc257 parse_lnk_files 1ms 2026-09-19T20:04:48
tc_59201b83 get_timeline 2ms 2026-09-19T20:04:48
tc_27a45284 get_raw_output 7ms 2026-09-19T20:04:49
tc_d43a000b search 3ms 2026-09-19T20:04:54
tc_85eb0e55 search 268ms 2026-09-19T20:04:57
tc_bd3e6850 get_investigation_summary 4ms 2026-09-19T20:04:57
tc_ab2083b7 search 3ms 2026-09-19T20:05:01
tc_3ac576a9 search 2ms 2026-09-19T20:05:01
tc_a49c96ff get_raw_output 7ms 2026-09-19T20:05:03
tc_c29d9952 search 3ms 2026-09-19T20:05:07
tc_fa961f9d get_raw_output 7ms 2026-09-19T20:05:13
tc_b7f31654 get_raw_output 61ms 2026-09-19T20:05:14
tc_b266c55a search 4ms 2026-09-19T20:05:17
tc_7d88330e search 3ms 2026-09-19T20:05:24
tc_95f627ee search 9ms 2026-09-19T20:05:24
tc_586ce686 get_raw_output 11ms 2026-09-19T20:05:24
tc_dd3b793f search 4ms 2026-09-19T20:05:29
tc_1bb945cc submit_finding 9ms 2026-09-19T20:05:37
tc_330254c5 search 3ms 2026-09-19T20:05:39
tc_3889be5f search 2ms 2026-09-19T20:05:39
tc_76799ff7 get_raw_output 7ms 2026-09-19T20:05:43
tc_6b90a6d0 submit_finding 9ms 2026-09-19T20:05:49
tc_7620f9af search 10ms 2026-09-19T20:05:51
tc_f331c0aa search 4ms 2026-09-19T20:05:51
tc_172ad991 search 3ms 2026-09-19T20:05:56
tc_e8ea2b3b get_raw_output 7ms 2026-09-19T20:06:02
tc_4fee3f95 submit_finding 9ms 2026-09-19T20:06:04
tc_9ad04f80 search 9ms 2026-09-19T20:06:05
tc_76263f6c search 3ms 2026-09-19T20:06:05
tc_76a1f022 submit_finding 8ms 2026-09-19T20:06:14
tc_64f643b8 search 3ms 2026-09-19T20:06:16
tc_937fbcfe search 9ms 2026-09-19T20:06:20
tc_adcc3549 search 3ms 2026-09-19T20:06:31
tc_c2a729ca get_raw_output 7ms 2026-09-19T20:06:31
tc_f6a52bc3 search 5839ms 2026-09-19T20:06:36
tc_ca95f6e7 search 3ms 2026-09-19T20:06:36
tc_b5639f17 search 3ms 2026-09-19T20:06:37
tc_69545e3d search 10ms 2026-09-19T20:06:42
tc_e43caa32 search 3ms 2026-09-19T20:06:50
tc_3b710187 submit_finding 8ms 2026-09-19T20:06:51
tc_ac2d10ce get_raw_output 7ms 2026-09-19T20:06:52
tc_29a530af search 10ms 2026-09-19T20:07:00
tc_81d1370f search 3ms 2026-09-19T20:07:03
tc_e3f9174d open_case 29ms 2026-09-19T20:07:13
tc_7218517b get_investigation_summary 6ms 2026-09-19T20:07:14
tc_c5b4d583 get_findings 1ms 2026-09-19T20:07:14
tc_124f8203 submit_finding 9ms 2026-09-19T20:07:14
tc_a2d89c9e search 7ms 2026-09-19T20:07:21
tc_82cf0f9d search 3ms 2026-09-19T20:07:21
tc_85991e3c get_source_stats 63ms 2026-09-19T20:07:25
tc_90f3f830 get_raw_output 65ms 2026-09-19T20:07:30
tc_ba019ffb get_raw_output 63ms 2026-09-19T20:07:30
tc_02ba23b9 get_raw_output 63ms 2026-09-19T20:07:30
tc_7e27631c update_finding 10ms 2026-09-19T20:07:33
tc_09e695a3 search 2ms 2026-09-19T20:07:35
tc_7c63396d search 3ms 2026-09-19T20:07:35
tc_89c96f05 search 2ms 2026-09-19T20:07:35
tc_f45f79e2 get_raw_output 64ms 2026-09-19T20:07:36
tc_c52e9991 get_raw_output 62ms 2026-09-19T20:07:39
tc_d60a090b search 4ms 2026-09-19T20:07:50
tc_17e31fe9 submit_finding 9ms 2026-09-19T20:07:54
tc_063d4f33 search 6ms 2026-09-19T20:07:57
tc_5bac55b9 search 4ms 2026-09-19T20:08:01
tc_389b9cea search 3ms 2026-09-19T20:08:01
tc_ab4a8f0c search 9ms 2026-09-19T20:08:14
tc_37e23447 update_finding 8ms 2026-09-19T20:08:15
tc_4a4dd848 search 4ms 2026-09-19T20:08:28
tc_f58bad5f get_raw_output 63ms 2026-09-19T20:08:28
tc_ecd12658 get_raw_output 63ms 2026-09-19T20:08:28
tc_b8f416ce search 136ms 2026-09-19T20:08:29
tc_f761dfbf search 64ms 2026-09-19T20:08:29
tc_3beccc2b get_timeline 1ms 2026-09-19T20:08:30
tc_c4a9eccd search 4ms 2026-09-19T20:08:30
tc_b9d52a36 search 4ms 2026-09-19T20:08:43
tc_e381319c search 3ms 2026-09-19T20:08:43
tc_2fdd2ab8 submit_finding 8ms 2026-09-19T20:08:46
tc_f6d195c4 get_raw_output 62ms 2026-09-19T20:08:57
tc_c0139328 search 143ms 2026-09-19T20:08:58
tc_e9997fa7 submit_finding 8ms 2026-09-19T20:09:01
tc_939e4bc9 search 4ms 2026-09-19T20:09:02
tc_a4103e7d get_raw_output 65ms 2026-09-19T20:09:02
tc_29a8b73b get_raw_output 63ms 2026-09-19T20:09:12
tc_84cdb499 search 4ms 2026-09-19T20:09:12
tc_b7e940f2 submit_finding 10ms 2026-09-19T20:09:16
tc_d87263a2 get_raw_output 64ms 2026-09-19T20:09:29
tc_d3e87477 search 7ms 2026-09-19T20:09:29
tc_c4210c36 search 76ms 2026-09-19T20:09:31
tc_20ae918e search 206ms 2026-09-19T20:09:31
tc_f712b89c submit_finding 9ms 2026-09-19T20:09:33
tc_a52ae05a submit_finding 8ms 2026-09-19T20:09:47
tc_0ab8643c get_timeline 14ms 2026-09-19T20:09:56
tc_87bf750c search 5ms 2026-09-19T20:09:56
tc_2e261a93 get_raw_output 62ms 2026-09-19T20:09:57
tc_a5af55fe get_raw_output 62ms 2026-09-19T20:09:57
tc_d0a6251a submit_finding 9ms 2026-09-19T20:10:18
tc_bf098e00 submit_finding 7ms 2026-09-19T20:10:18
tc_bd25c723 submit_finding 10ms 2026-09-19T20:10:20
tc_057d5baa submit_finding 9ms 2026-09-19T20:10:30
tc_7c63d038 get_findings 1ms 2026-09-19T20:10:31
tc_12346b88 parse_lnk_files 1ms 2026-09-19T20:10:31
tc_4e8fb390 search 7ms 2026-09-19T20:10:39
tc_acdf4957 submit_finding 0ms 2026-09-19T20:10:40
tc_b056244f search 107ms 2026-09-19T20:10:54
tc_c5e5b32e submit_finding 8ms 2026-09-19T20:11:02
tc_fce28293 parse_browser_history 4642ms 2026-09-19T20:11:04
tc_c61707ed search 64ms 2026-09-19T20:11:19
tc_4e7701d7 get_raw_output 27ms 2026-09-19T20:11:23
tc_9f888a41 track_progress 8ms 2026-09-19T20:11:35
tc_7288cc1d submit_finding 10ms 2026-09-19T20:11:39
tc_49972f49 update_finding 10ms 2026-09-19T20:11:44
tc_d907f46a get_findings 1ms 2026-09-19T20:11:47
tc_41014cf1 get_raw_output 62ms 2026-09-19T20:11:54
tc_16c95371 search 5ms 2026-09-19T20:11:54
tc_ae14e081 get_investigation_summary 5ms 2026-09-19T20:11:59
tc_070fa138 track_progress 10ms 2026-09-19T20:12:02
tc_bb77d135 search 15ms 2026-09-19T20:12:05
tc_111480cc search 3ms 2026-09-19T20:12:05
tc_734e6368 get_findings 1ms 2026-09-19T20:12:14
tc_6b6e473c search 10ms 2026-09-19T20:12:16
tc_ce2a33dd query_registry_value 4329ms 2026-09-19T20:12:29
tc_f65a2f01 get_investigation_summary 6ms 2026-09-19T20:12:38
tc_ea7fb63b get_findings 1ms 2026-09-19T20:12:42
tc_7cb3d28a query_registry_value 4369ms 2026-09-19T20:12:42
tc_bd899208 open_case 29ms 2026-09-19T20:12:43
tc_51923537 list_sources 4ms 2026-09-19T20:12:44
tc_23ebd698 query_registry_value 4317ms 2026-09-19T20:12:47
tc_9fe111fb get_findings 1ms 2026-09-19T20:12:55
tc_97ca5516 open_case 29ms 2026-09-19T20:12:59
tc_89c851db get_raw_output 63ms 2026-09-19T20:13:08
tc_dfe3f65e search 5ms 2026-09-19T20:13:08
tc_c64fffa7 update_finding 7ms 2026-09-19T20:13:08
tc_7156a90a run_optical_listing 61ms 2026-09-19T20:13:10
tc_11860c19 start_extraction_batch 4ms 2026-09-19T20:13:10
tc_7363cae2 run_bulk_extractor 5505ms 2026-09-19T20:13:15
tc_181c30bd update_finding 7ms 2026-09-19T20:13:21
tc_1f328fd6 search 6ms 2026-09-19T20:13:24
tc_c87e3b81 detect_masquerading 0ms 2026-09-19T20:13:31
tc_c82ca542 get_investigation_summary 4ms 2026-09-19T20:13:35
tc_03ab2ec2 yara_scan_files 5512ms 2026-09-19T20:13:40
tc_ee1e994e extract_optical_file 0ms 2026-09-19T20:13:41
tc_ae65c10e submit_finding 10ms 2026-09-19T20:13:50
tc_abff2113 track_progress 6ms 2026-09-19T20:13:53
tc_7e1fdc9a get_findings 1ms 2026-09-19T20:14:04
tc_54129e41 check_extraction_status 0ms 2026-09-19T20:14:07
tc_4fa7eda2 extract_optical_file 84ms 2026-09-19T20:14:07
tc_71af3a3b extract_optical_file 89ms 2026-09-19T20:14:07
tc_16e9cbb2 extract_optical_file 102ms 2026-09-19T20:14:07
tc_aa8a4bf3 extract_optical_file 105ms 2026-09-19T20:14:07
tc_852b1449 extract_optical_file 128ms 2026-09-19T20:14:07
tc_d8402e67 extract_optical_file 133ms 2026-09-19T20:14:07
tc_1c0e3473 extract_optical_file 61ms 2026-09-19T20:14:07
tc_873a4f7c extract_optical_file 146ms 2026-09-19T20:14:07
tc_d9d92b46 extract_optical_file 149ms 2026-09-19T20:14:07
tc_e912f9ee extract_optical_file 62ms 2026-09-19T20:14:07
tc_5472df96 extract_optical_file 92ms 2026-09-19T20:14:07
tc_3a98ab52 extract_optical_file 54ms 2026-09-19T20:14:07
tc_69217fe4 extract_optical_file 103ms 2026-09-19T20:14:07
tc_96f31566 extract_optical_file 72ms 2026-09-19T20:14:07
tc_3d7786f3 extract_optical_file 58ms 2026-09-19T20:14:07
tc_51d0045e extract_optical_file 63ms 2026-09-19T20:14:07
tc_8ff247a0 extract_optical_file 47ms 2026-09-19T20:14:07
tc_5d32deef extract_optical_file 54ms 2026-09-19T20:14:07
tc_ceee9433 extract_optical_file 94ms 2026-09-19T20:14:07
tc_70750b2e extract_optical_file 60ms 2026-09-19T20:14:07
tc_88948787 extract_optical_file 62ms 2026-09-19T20:14:07
tc_f1d895b5 extract_optical_file 58ms 2026-09-19T20:14:07
tc_29d258f6 extract_optical_file 55ms 2026-09-19T20:14:07
tc_a3e5f674 extract_optical_file 89ms 2026-09-19T20:14:07
tc_0dc14e6d extract_optical_file 79ms 2026-09-19T20:14:07
tc_1147a5a6 extract_optical_file 63ms 2026-09-19T20:14:07
tc_a8a27e53 extract_optical_file 54ms 2026-09-19T20:14:07
tc_c26e3644 extract_optical_file 145ms 2026-09-19T20:14:07
tc_04a4bf66 extract_optical_file 56ms 2026-09-19T20:14:07
tc_21b9bbd5 extract_optical_file 151ms 2026-09-19T20:14:08
tc_0fcab360 extract_optical_file 69ms 2026-09-19T20:14:08
tc_feacd74c extract_optical_file 69ms 2026-09-19T20:14:08
tc_698e5388 extract_optical_file 64ms 2026-09-19T20:14:08
tc_4e18280a extract_optical_file 72ms 2026-09-19T20:14:08
tc_2df0593d extract_optical_file 57ms 2026-09-19T20:14:08
tc_d6cc0013 extract_optical_file 49ms 2026-09-19T20:14:08
tc_74d26f13 extract_optical_file 54ms 2026-09-19T20:14:08
tc_e25ebf73 get_completed_results 0ms 2026-09-19T20:14:12
tc_7b8b808d run_exiftool 342ms 2026-09-19T20:14:12
tc_53ee781d detect_steganography 157ms 2026-09-19T20:14:13
tc_dc1b794b analyze_office_document 0ms 2026-09-19T20:14:13
tc_53d8d364 get_investigation_summary 5ms 2026-09-19T20:14:18
tc_b3356b74 yara_scan_files 662ms 2026-09-19T20:14:20
tc_e504cbcc open_case 29ms 2026-09-19T20:14:30
tc_1fa143f4 wait_all 0ms 2026-09-19T20:14:31
tc_2e4b914e open_case 29ms 2026-09-19T20:14:36
tc_d04b5af0 get_investigation_summary 6ms 2026-09-19T20:14:37
tc_97236954 list_sources 2ms 2026-09-19T20:14:37
tc_41ae2835 get_findings 1ms 2026-09-19T20:14:39
tc_52323451 search 8ms 2026-09-19T20:14:41
tc_52ca8a78 get_source_stats 61ms 2026-09-19T20:14:42
tc_5cf3bada get_raw_output 63ms 2026-09-19T20:14:45
tc_141ac420 get_raw_output 62ms 2026-09-19T20:14:50
tc_7bcc0dcc get_raw_output 61ms 2026-09-19T20:14:50
tc_af615d12 get_source_stats 63ms 2026-09-19T20:15:06
tc_5289c5f9 get_raw_output 61ms 2026-09-19T20:15:14
tc_0cced7cc search 10ms 2026-09-19T20:15:17
tc_0d5a6790 get_raw_output 62ms 2026-09-19T20:15:21
tc_e5e56174 get_raw_output 62ms 2026-09-19T20:15:23
tc_2933c96c get_raw_output 62ms 2026-09-19T20:15:43
tc_9db09021 submit_finding 17ms 2026-09-19T20:16:12
tc_a11762fc search 26ms 2026-09-19T20:16:13
tc_8d8ef597 get_raw_output 62ms 2026-09-19T20:16:16
tc_a1493e10 search 5ms 2026-09-19T20:16:28
tc_816dc0f3 get_raw_output 62ms 2026-09-19T20:16:33
tc_1e369e28 search 4ms 2026-09-19T20:16:34
tc_7bfc0604 search 86ms 2026-09-19T20:16:40
tc_65de73b5 get_raw_output 63ms 2026-09-19T20:16:59
tc_944e7581 get_raw_output 62ms 2026-09-19T20:17:06
tc_ebfbb5a1 search 4ms 2026-09-19T20:17:13
tc_58fa9926 get_raw_output 62ms 2026-09-19T20:17:21
tc_acc1c5cc detect_steganography 157ms 2026-09-19T20:17:27
tc_2fb4af09 run_exiftool 343ms 2026-09-19T20:17:32
tc_467c86e6 search 26ms 2026-09-19T20:17:40
tc_429306c8 search 4ms 2026-09-19T20:17:44
tc_73f900c1 search 4ms 2026-09-19T20:17:54
tc_883e67b7 get_raw_output 62ms 2026-09-19T20:18:12
tc_1e01368f get_raw_output 62ms 2026-09-19T20:18:26
tc_2b0946d0 search 4ms 2026-09-19T20:18:32
tc_130a82af bookmark_window 11ms 2026-09-19T20:18:38
tc_d17cd642 update_finding 15ms 2026-09-19T20:18:39
tc_e8292cda submit_finding 14ms 2026-09-19T20:18:48
tc_e061471c submit_finding 17ms 2026-09-19T20:19:02
tc_dcbfff63 track_progress 14ms 2026-09-19T20:19:10
tc_087f5074 search 9ms 2026-09-19T20:19:10
tc_5ba122fe submit_finding 15ms 2026-09-19T20:19:25
tc_99f9f893 get_findings 1ms 2026-09-19T20:19:28
tc_d6cf128b track_progress 13ms 2026-09-19T20:19:38
tc_a95d6f33 get_investigation_summary 5ms 2026-09-19T20:19:49
tc_d33c097b get_investigation_summary 5ms 2026-09-19T20:20:08
tc_ccfcf139 open_case 29ms 2026-09-19T20:20:11
tc_84b891fa get_findings 2ms 2026-09-19T20:20:12
tc_595b70a4 get_findings 1ms 2026-09-19T20:20:14
tc_276f2836 get_investigation_summary 5ms 2026-09-19T20:20:15
tc_9d7e34a5 get_source_stats 62ms 2026-09-19T20:20:16
tc_b9759a4a get_timeline 24ms 2026-09-19T20:20:19
tc_c03cab3c get_bookmarks 2ms 2026-09-19T20:20:21
tc_596df5ce open_case 30ms 2026-09-19T20:20:41
tc_e4172faf analyze_execution_timeline._query(ez.shimcache) 19ms 2026-09-19T20:20:45
tc_6ae088eb analyze_execution_timeline 91ms 2026-09-19T20:20:45
tc_4dc1f0fa find_suspicious_processes._query(volatility.malfind) 98ms 2026-09-19T20:20:45
tc_b7bd45e1 reconstruct_execution_chains._query(volatility.pstree) 115ms 2026-09-19T20:20:45
tc_645b30df find_persistence_mechanisms._query(registry.system) 121ms 2026-09-19T20:20:45
tc_abc1a8ae find_file_staging._search(tsk.filelist) 15ms 2026-09-19T20:20:45
tc_ebac7fbd reconstruct_execution_chains._query(volatility.cmdline) 15ms 2026-09-19T20:20:45
tc_96e22dd8 find_suspicious_processes._query(volatility.cmdline) 20ms 2026-09-19T20:20:45
tc_3d0c0c09 find_lateral_movement_indicators._search(all) 49ms 2026-09-19T20:20:45
tc_ce308579 find_persistence_mechanisms._query(registry.software) 10ms 2026-09-19T20:20:45
tc_71e0457f find_defense_evasion._search(all) 147ms 2026-09-19T20:20:45
tc_d65985ec find_file_staging._search(ez.mft) 5ms 2026-09-19T20:20:45
tc_badc59a5 find_suspicious_processes._query(volatility.netscan) 8ms 2026-09-19T20:20:45
tc_f50f605f find_lateral_movement_indicators._search(all) 4ms 2026-09-19T20:20:45
tc_22f29145 reconstruct_execution_chains._query(volatility.netscan) 16ms 2026-09-19T20:20:45
tc_df3d3e6b find_persistence_mechanisms._query(volatility.svcscan) 7ms 2026-09-19T20:20:45
tc_86608a48 find_defense_evasion._search(ez.mft) 7ms 2026-09-19T20:20:45
tc_69838383 find_suspicious_processes._query(volatility.pstree) 7ms 2026-09-19T20:20:45
tc_98c01ef6 find_lateral_movement_indicators._search(all) 5ms 2026-09-19T20:20:45
tc_61abcb26 reconstruct_execution_chains._query(volatility.malfind) 7ms 2026-09-19T20:20:45
tc_508cfdf6 find_persistence_mechanisms._search(all) 7ms 2026-09-19T20:20:45
tc_ba7812c0 find_suspicious_processes 179ms 2026-09-19T20:20:45
tc_7e61b524 find_defense_evasion._search(all) 8ms 2026-09-19T20:20:45
tc_7e73f71a reconstruct_execution_chains 203ms 2026-09-19T20:20:45
tc_25d2a2ea find_lateral_movement_indicators._query(volatility.netscan) 7ms 2026-09-19T20:20:45
tc_bf106497 find_persistence_mechanisms._search(all) 7ms 2026-09-19T20:20:45
tc_1b4de8ae find_lateral_movement_indicators._search(all) 11ms 2026-09-19T20:20:45
tc_34a071a4 find_persistence_mechanisms._query(ez.shimcache) 10ms 2026-09-19T20:20:45
tc_d2ac7594 find_defense_evasion._search(all) 23ms 2026-09-19T20:20:45
tc_d06b53fa find_lateral_movement_indicators._search(all) 6ms 2026-09-19T20:20:45
tc_acca93e8 find_persistence_mechanisms._search(all) 8ms 2026-09-19T20:20:45
tc_f7b26d8a find_defense_evasion._search(all) 13ms 2026-09-19T20:20:45
tc_8afda6c8 find_lateral_movement_indicators._search(all) 10ms 2026-09-19T20:20:45
tc_d5ce9396 find_defense_evasion 266ms 2026-09-19T20:20:45
tc_33b98ddb find_lateral_movement_indicators 260ms 2026-09-19T20:20:45
tc_16a34aa8 find_file_staging._query(tsk.filelist) 121ms 2026-09-19T20:20:45
tc_093fc4d2 find_persistence_mechanisms._query(tsk.filelist) 353ms 2026-09-19T20:20:45
tc_3e89dd85 find_persistence_mechanisms 657ms 2026-09-19T20:20:45
tc_9cb184a3 detect_timestomping 986ms 2026-09-19T20:20:46
tc_71956c9c find_file_staging._query(ez.mft) 827ms 2026-09-19T20:20:46
tc_31383815 find_file_staging._search(ez.mft) 16ms 2026-09-19T20:20:46
tc_946ae6f2 find_file_staging._search(ez.mft) 4ms 2026-09-19T20:20:46
tc_1d358808 find_file_staging 1483ms 2026-09-19T20:20:46
tc_52de3706 find_data_exfiltration_indicators._query(bulk.url) 1590ms 2026-09-19T20:20:46
tc_852cc034 find_data_exfiltration_indicators._query(bulk.email) 9ms 2026-09-19T20:20:47
tc_71272bc8 find_data_exfiltration_indicators._query(bulk.domain) 77ms 2026-09-19T20:20:47
tc_0efce70d find_data_exfiltration_indicators._search(all) 25ms 2026-09-19T20:20:47
tc_e3309eb9 find_data_exfiltration_indicators 2683ms 2026-09-19T20:20:47
tc_cbedab63 find_execution_evidence._query(ez.shimcache) 9ms 2026-09-19T20:20:50
tc_9eb453d2 find_execution_evidence 53ms 2026-09-19T20:20:50
tc_4e3a152a correlate_across_sources 262ms 2026-09-19T20:20:50
tc_24d46800 correlate_across_sources 297ms 2026-09-19T20:20:50
tc_229c23f6 correlate_across_sources 312ms 2026-09-19T20:20:50
tc_064848b4 correlate_across_sources 324ms 2026-09-19T20:20:50
tc_469a5816 open_case 30ms 2026-09-19T20:21:00
tc_a459080c get_investigation_summary 7ms 2026-09-19T20:21:00
tc_eceb5ec0 get_findings 2ms 2026-09-19T20:21:01
tc_1635e80f get_findings 2ms 2026-09-19T20:21:03
tc_3c1b4fb8 get_raw_output 68ms 2026-09-19T20:21:07
tc_bbc2a3c7 get_raw_output 61ms 2026-09-19T20:21:07
tc_3e7be4a4 get_raw_output 61ms 2026-09-19T20:21:09
tc_873a0874 get_raw_output 61ms 2026-09-19T20:21:09
tc_07b9ba19 get_raw_output 61ms 2026-09-19T20:21:10
tc_f8f33ebc get_raw_output 62ms 2026-09-19T20:21:20
tc_8f8bf397 get_raw_output 62ms 2026-09-19T20:21:20
tc_6cb1c869 get_raw_output 62ms 2026-09-19T20:21:20
tc_0ab1b160 get_raw_output 62ms 2026-09-19T20:21:29
tc_7302d050 get_raw_output 62ms 2026-09-19T20:21:29
tc_8bee7908 search 9ms 2026-09-19T20:21:34
tc_fa16c355 search 6ms 2026-09-19T20:21:34
tc_7b94f005 search 5ms 2026-09-19T20:21:36
tc_de3acdcd search 3ms 2026-09-19T20:21:36
tc_9a17323f search 4ms 2026-09-19T20:21:54
tc_24f5b675 search 2ms 2026-09-19T20:21:54
tc_088f0ae7 search 4ms 2026-09-19T20:22:01
tc_ab7e8a9c search 4ms 2026-09-19T20:22:01
tc_1fe0a35c search 3ms 2026-09-19T20:22:06
tc_5ffdbe80 search 5ms 2026-09-19T20:22:06
tc_799a4a48 search 412ms 2026-09-19T20:22:11
tc_5634f05a search 3ms 2026-09-19T20:22:11
tc_c04b0478 search 3ms 2026-09-19T20:22:16
tc_ae4028aa search 2ms 2026-09-19T20:22:16
tc_ddfb1a68 search 3ms 2026-09-19T20:22:31
tc_882d71f9 search 2ms 2026-09-19T20:22:31
tc_34e19ca4 search 3ms 2026-09-19T20:22:46
tc_e26673aa search 3ms 2026-09-19T20:22:46
tc_2f71534e get_raw_output 27ms 2026-09-19T20:22:50
tc_ca5de7fb search 3ms 2026-09-19T20:22:50
tc_dc2a404d search 3ms 2026-09-19T20:22:59
tc_489e70d4 search 3ms 2026-09-19T20:22:59
tc_e816ff9a search 3ms 2026-09-19T20:23:06
tc_d0d34f7c search 2ms 2026-09-19T20:23:06
tc_0598fd85 get_ioc_summary 485ms 2026-09-19T20:23:11
tc_8168505a search 3ms 2026-09-19T20:23:18
tc_9e26ec10 search 2ms 2026-09-19T20:23:18
tc_fd57c080 search 3ms 2026-09-19T20:23:24
tc_5d9a77fd search 2ms 2026-09-19T20:23:24
tc_18a27e20 search 3ms 2026-09-19T20:23:34
tc_b0dccba4 search 2ms 2026-09-19T20:23:34
tc_e330b53d search 3ms 2026-09-19T20:23:58
tc_70fb8f59 search 2ms 2026-09-19T20:23:58
tc_4c3a7083 get_raw_output 62ms 2026-09-19T20:24:20
tc_c2d8ab72 search 2ms 2026-09-19T20:24:25
tc_d77c8213 search 3ms 2026-09-19T20:24:30
tc_98de66a6 search 3ms 2026-09-19T20:24:43
tc_e27f42f4 search 3ms 2026-09-19T20:24:50
tc_41bf3059 get_raw_output 62ms 2026-09-19T20:24:55
tc_8b26da7a get_raw_output 62ms 2026-09-19T20:25:01
tc_ea0b7a89 search 3ms 2026-09-19T20:25:13
tc_815552ab search 3ms 2026-09-19T20:25:20
tc_9eb99492 search 3ms 2026-09-19T20:25:36
tc_4dcb111b search 3ms 2026-09-19T20:25:42
tc_d36cfd54 search 3ms 2026-09-19T20:25:51
tc_5a473b31 search 5ms 2026-09-19T20:26:00
tc_95f2c565 search 3ms 2026-09-19T20:26:10
tc_e0e8d9c7 search 3ms 2026-09-19T20:26:27
tc_ce80925a search 3ms 2026-09-19T20:26:35
tc_fee7ebc3 search 3ms 2026-09-19T20:26:44
tc_57494c5c search 3ms 2026-09-19T20:26:50
tc_aa9fe694 search 3ms 2026-09-19T20:26:57
tc_4b813f6f search 3ms 2026-09-19T20:27:05
tc_e200da7f search 3ms 2026-09-19T20:27:17
tc_7d418cef search 3ms 2026-09-19T20:27:23
tc_e822d9ef search 3ms 2026-09-19T20:27:30
tc_034d7155 search 3ms 2026-09-19T20:27:42
tc_e5328266 open_case 30ms 2026-09-19T20:27:52
tc_1bdb002f get_investigation_summary 6ms 2026-09-19T20:27:53
tc_487ededd get_findings 1ms 2026-09-19T20:27:53
tc_d090e40c get_source_stats 64ms 2026-09-19T20:27:55
tc_f5065552 get_bookmarks 2ms 2026-09-19T20:27:55
tc_b6ed01a3 get_ioc_summary 542ms 2026-09-19T20:27:58
tc_0ae65dba get_raw_output 62ms 2026-09-19T20:27:58
tc_633d87ae get_raw_output 62ms 2026-09-19T20:28:00
tc_9da29f17 get_raw_output 62ms 2026-09-19T20:28:03
tc_76df5a90 get_raw_output 63ms 2026-09-19T20:28:14
tc_41b15c88 search 63ms 2026-09-19T20:28:18
tc_157b7ca5 search 4ms 2026-09-19T20:28:26
tc_69051e10 search 4ms 2026-09-19T20:28:34
tc_1f434d54 search 3ms 2026-09-19T20:28:37
tc_918f716f get_raw_output 63ms 2026-09-19T20:28:41
tc_b7a1dcc3 get_raw_output 62ms 2026-09-19T20:28:45
tc_d0a625fc search 4ms 2026-09-19T20:28:57
tc_e8e512ef search 3ms 2026-09-19T20:29:00
tc_ee6253e1 get_raw_output 62ms 2026-09-19T20:29:03
tc_7c9fd7a3 get_raw_output 62ms 2026-09-19T20:29:07
tc_76200bc3 get_raw_output 62ms 2026-09-19T20:29:12
tc_59a24a22 get_raw_output 62ms 2026-09-19T20:29:15
tc_0d56b7fa get_raw_output 62ms 2026-09-19T20:29:21
tc_c44f0d58 get_raw_output 62ms 2026-09-19T20:29:25
tc_37fcbc35 get_raw_output 62ms 2026-09-19T20:29:30
tc_dbd7b744 get_raw_output 62ms 2026-09-19T20:29:37
tc_e65a4de6 get_raw_output 62ms 2026-09-19T20:29:50
tc_018d37ed get_raw_output 62ms 2026-09-19T20:29:54
tc_a1ceb062 get_raw_output 62ms 2026-09-19T20:30:08
tc_a422f9a7 get_raw_output 62ms 2026-09-19T20:30:23
tc_b25844ba get_raw_output 61ms 2026-09-19T20:30:32
tc_274887d8 get_raw_output 62ms 2026-09-19T20:30:37
tc_c03e709a get_raw_output 62ms 2026-09-19T20:30:43
tc_0cfaf255 get_raw_output 61ms 2026-09-19T20:30:49
tc_fc74dbca get_raw_output 62ms 2026-09-19T20:31:10
tc_c90daf78 get_raw_output 62ms 2026-09-19T20:31:16
tc_37f2d1d6 get_raw_output 62ms 2026-09-19T20:31:23
tc_a3205763 get_raw_output 62ms 2026-09-19T20:31:35
tc_816c814a get_raw_output 62ms 2026-09-19T20:31:42
tc_9744fa95 get_raw_output 62ms 2026-09-19T20:31:47
tc_c377576d get_raw_output 62ms 2026-09-19T20:31:55
tc_24b041c5 get_raw_output 62ms 2026-09-19T20:32:02
tc_7291dcd2 get_raw_output 62ms 2026-09-19T20:32:18
tc_ccc4faa0 get_raw_output 62ms 2026-09-19T20:32:24
tc_f6c88fc0 get_raw_output 62ms 2026-09-19T20:32:31
tc_161a9af9 get_raw_output 62ms 2026-09-19T20:32:46
tc_44e9c276 get_raw_output 62ms 2026-09-19T20:32:55
tc_2b4397c2 get_raw_output 62ms 2026-09-19T20:33:07
tc_6ebe0050 open_case 30ms 2026-09-19T20:33:17
tc_61bf1929 get_investigation_summary 6ms 2026-09-19T20:33:18
tc_54afb52d get_findings 1ms 2026-09-19T20:33:18
tc_0626b3f8 get_source_stats 63ms 2026-09-19T20:33:22
tc_00fce741 get_ioc_summary 542ms 2026-09-19T20:33:22
tc_c9aa1cc0 get_bookmarks 2ms 2026-09-19T20:33:34
tc_5b279675 get_raw_output 63ms 2026-09-19T20:33:37
tc_9524a8fe search 4ms 2026-09-19T20:34:00
tc_05aa384f search 3ms 2026-09-19T20:34:00
tc_ff4b7c9f update_finding 13ms 2026-09-19T20:34:11
tc_8f2adbd1 delete_finding 12ms 2026-09-19T20:34:14
tc_e2546dc8 update_finding 3ms 2026-09-19T20:34:19
tc_cb56cfa2 delete_finding 11ms 2026-09-19T20:34:28
tc_619db416 delete_finding 10ms 2026-09-19T20:34:35
tc_45188cda delete_finding 11ms 2026-09-19T20:34:39
tc_964fddb9 delete_finding 12ms 2026-09-19T20:34:44
tc_639c1bc6 update_finding 13ms 2026-09-19T20:34:48
tc_1b09b791 delete_finding 11ms 2026-09-19T20:34:51
tc_b5013222 delete_finding 10ms 2026-09-19T20:34:54
tc_cb90e2f1 get_findings 1ms 2026-09-19T20:34:58
tc_c7e089b8 delete_finding 12ms 2026-09-19T20:35:10
tc_663a48ca get_investigation_summary 4ms 2026-09-19T20:35:16
tc_e55a96ed search 2ms 2026-09-19T20:35:27
tc_0ac1fef2 get_raw_output 62ms 2026-09-19T20:35:27
tc_e3e83b38 get_raw_output 63ms 2026-09-19T20:35:31
tc_6d84110a search 2ms 2026-09-19T20:35:31
tc_14271fc6 get_raw_output 61ms 2026-09-19T20:35:48
tc_9b9b389a track_progress 13ms 2026-09-19T20:35:57
tc_deb5bd31 get_investigation_summary 5ms 2026-09-19T20:36:07
tc_5d76b54d open_case 30ms 2026-09-19T20:36:10
tc_7d36c4c8 get_findings 2ms 2026-09-19T20:36:11
tc_31fd451d get_investigation_summary 5ms 2026-09-19T20:36:11
tc_8a628ea6 get_timeline 25ms 2026-09-19T20:36:13
tc_9ed31882 list_sources 3ms 2026-09-19T20:36:13
tc_354f2a2b get_findings 1ms 2026-09-19T20:36:15
tc_d20ee7c5 open_case 31ms 2026-09-19T20:36:35
tc_a3bd3034 search 20ms 2026-09-19T20:36:37
tc_7ac1da8e search 15ms 2026-09-19T20:36:37
tc_faf5b561 search 6ms 2026-09-19T20:36:37
tc_c572464b search 28ms 2026-09-19T20:36:37
tc_093544dd search 20ms 2026-09-19T20:36:37
tc_6a563756 search 22ms 2026-09-19T20:36:37
tc_cfc951b7 search 23ms 2026-09-19T20:36:37
tc_b63087e4 search 22ms 2026-09-19T20:36:37
tc_8d62dee8 search 28ms 2026-09-19T20:36:37
tc_73cf8e97 get_timeline 15ms 2026-09-19T20:36:37
tc_c68e39c1 detect_timestomping 339ms 2026-09-19T20:36:37
tc_2872e93d correlate_across_sources 38ms 2026-09-19T20:36:45
tc_348d52d4 deduplicate_findings 14ms 2026-09-19T20:36:45
tc_71e1462b open_case 30ms 2026-09-19T20:37:07
tc_d711285b get_findings 2ms 2026-09-19T20:37:08
tc_960d331e get_investigation_summary 6ms 2026-09-19T20:37:10
tc_1aea8ad0 search 6ms 2026-09-19T20:37:15
tc_d6d5a244 get_raw_output 64ms 2026-09-19T20:37:17
tc_f5559389 search 6ms 2026-09-19T20:37:19
tc_641db517 search 5ms 2026-09-19T20:37:23
tc_649dbfce get_raw_output 27ms 2026-09-19T20:37:25
tc_dc19885b search 3ms 2026-09-19T20:37:27
tc_e4a86cf2 search 3ms 2026-09-19T20:37:31
tc_1369e93b get_raw_output 62ms 2026-09-19T20:37:33
tc_14edda8b search 3ms 2026-09-19T20:37:35
tc_8a4ed633 search 4ms 2026-09-19T20:37:44
tc_36027510 get_raw_output 62ms 2026-09-19T20:37:46
tc_be0b8029 get_timeline 16ms 2026-09-19T20:37:53
tc_6f7a2110 search 8ms 2026-09-19T20:38:01
tc_3d1c2fc0 search 6ms 2026-09-19T20:38:09
tc_92f61e32 get_raw_output 63ms 2026-09-19T20:38:22
tc_525efd75 get_raw_output 63ms 2026-09-19T20:38:30
tc_952b0bef search 5ms 2026-09-19T20:38:37
tc_f8b9b2ef get_raw_output 62ms 2026-09-19T20:38:42
tc_6756cd46 search 5ms 2026-09-19T20:38:51
tc_b3abc194 get_raw_output 63ms 2026-09-19T20:39:01
tc_8a472714 search 3ms 2026-09-19T20:39:07
tc_60a453c8 search 4ms 2026-09-19T20:39:20
tc_316a049e audit_evidence_coverage 545ms 2026-09-19T20:39:30
tc_ada73ee2 audit_tool_coverage 2ms 2026-09-19T20:39:36
tc_fa6dcb8f search 3ms 2026-09-19T20:39:50
tc_281a8b2c get_ioc_summary 532ms 2026-09-19T20:39:58
tc_638c491f search 7ms 2026-09-19T20:40:10
tc_c44fb6ca update_finding 12ms 2026-09-19T20:40:22
tc_3fd2e1fe update_finding 13ms 2026-09-19T20:40:34
tc_b92f3be1 deduplicate_findings 14ms 2026-09-19T20:40:42
tc_d522818d check_finalize_readiness 4ms 2026-09-19T20:40:54
tc_903f0387 search 6ms 2026-09-19T20:41:05
tc_9c690658 open_case 30ms 2026-09-19T20:41:14
tc_5c5df306 get_investigation_summary 7ms 2026-09-19T20:41:15
tc_0aeb36b0 get_findings 1ms 2026-09-19T20:41:16
tc_b8afe856 check_finalize_readiness 4ms 2026-09-19T20:41:17
tc_77734f78 audit_evidence_coverage 545ms 2026-09-19T20:41:19
tc_e390e1d3 audit_tool_coverage 2ms 2026-09-19T20:41:19
tc_e463d1f4 search 4ms 2026-09-19T20:41:21
tc_90453a55 search 3ms 2026-09-19T20:41:22
tc_8537c80e search 2ms 2026-09-19T20:41:24
tc_1bcd14b0 search 4ms 2026-09-19T20:41:25
tc_12026842 get_raw_output 62ms 2026-09-19T20:41:27
tc_a0ec9ddb search 3ms 2026-09-19T20:41:29
tc_322607b3 search 3ms 2026-09-19T20:41:30
tc_cf938c7a get_raw_output 62ms 2026-09-19T20:41:32
tc_1783d287 search 4ms 2026-09-19T20:41:34
tc_82e47ee0 search 3ms 2026-09-19T20:41:36
tc_a5bb7b69 get_raw_output 62ms 2026-09-19T20:41:38
tc_be8da178 search 3ms 2026-09-19T20:41:40
tc_54db6d54 get_raw_output 61ms 2026-09-19T20:41:41
tc_23be767c search 3ms 2026-09-19T20:41:44
tc_9806a590 search 3ms 2026-09-19T20:41:46
tc_7800ed75 get_raw_output 61ms 2026-09-19T20:41:48
tc_1fe8d098 search 3ms 2026-09-19T20:41:50
tc_cdbc9e9b get_raw_output 7ms 2026-09-19T20:41:52
tc_f515e569 search 3ms 2026-09-19T20:41:54
tc_0bea416f search 4ms 2026-09-19T20:41:56
tc_ea0b330b search 3ms 2026-09-19T20:41:58
tc_a3436d04 search 3ms 2026-09-19T20:42:01
tc_040c4d34 search 3ms 2026-09-19T20:42:03
tc_79059c5d search 4ms 2026-09-19T20:42:06
tc_675a8c3a get_raw_output 63ms 2026-09-19T20:42:08
tc_0df765da get_raw_output 62ms 2026-09-19T20:42:10
tc_36782e01 open_case 31ms 2026-09-19T20:42:21
tc_d0c650b9 get_investigation_summary 7ms 2026-09-19T20:42:22
tc_f2a03c63 get_findings 1ms 2026-09-19T20:42:23
tc_20134039 audit_evidence_coverage 542ms 2026-09-19T20:42:28
tc_6f9ce28f audit_tool_coverage 2ms 2026-09-19T20:42:31
tc_091789f0 search 4ms 2026-09-19T20:42:35
tc_c667a67b get_raw_output 63ms 2026-09-19T20:42:37
tc_a4fbb6cb get_raw_output 62ms 2026-09-19T20:42:39
tc_ee11ac3f get_raw_output 62ms 2026-09-19T20:42:42
tc_253d7f8b get_raw_output 62ms 2026-09-19T20:42:44
tc_c697ff19 get_raw_output 61ms 2026-09-19T20:42:44
tc_f93e4361 get_raw_output 63ms 2026-09-19T20:42:47
tc_ee54d3c1 search 4ms 2026-09-19T20:42:51
tc_cfd5f887 deduplicate_findings 15ms 2026-09-19T20:42:53
tc_8dd704a1 check_finalize_readiness 4ms 2026-09-19T20:42:59
tc_3ca5dc4a search 4ms 2026-09-19T20:43:04
tc_d107dbee get_ioc_summary 530ms 2026-09-19T20:43:09
tc_40fc7268 search 5ms 2026-09-19T20:43:23
tc_aca7aeab track_progress 14ms 2026-09-19T20:43:38
tc_5e16f3de get_investigation_summary 5ms 2026-09-19T20:43:49
tc_a7273884 check_finalize_readiness 4ms 2026-09-19T20:43:49
tc_da44f606 open_case 10ms 2026-09-19T20:43:53
tc_f60489aa get_investigation_summary 6ms 2026-09-19T20:43:54
tc_a2a0c807 get_findings 1ms 2026-09-19T20:43:54
tc_256f1d07 get_ioc_summary 489ms 2026-09-19T20:43:55
tc_7bb4977b get_bookmarks 2ms 2026-09-19T20:43:55
tc_2a871e1d get_source_stats 116ms 2026-09-19T20:43:55
tc_3860a446 get_findings 2ms 2026-09-19T20:43:58
tc_902d0907 get_timeline 19ms 2026-09-19T20:43:58
tc_9f3246c4 audit_evidence_coverage 508ms 2026-09-19T20:44:03
tc_a6c90742 audit_tool_coverage 2ms 2026-09-19T20:44:03
tc_932a538d check_finalize_readiness 5ms 2026-09-19T20:44:08
tc_a0ada833 open_case 11ms 2026-09-19T20:44:12
tc_23f69acb get_investigation_summary 6ms 2026-09-19T20:44:13
tc_33ec4348 get_findings 1ms 2026-09-19T20:44:13
tc_ce5cb962 get_ioc_summary 484ms 2026-09-19T20:44:15
tc_b84827a2 get_bookmarks 2ms 2026-09-19T20:44:15
tc_214d7218 get_source_stats 106ms 2026-09-19T20:44:15
tc_4a99da6e check_finalize_readiness 4ms 2026-09-19T20:44:24
tc_ff5e866f submit_narrative 14ms 2026-09-19T20:45:00
tc_5c4aa7ed check_finalize_readiness 4ms 2026-09-19T20:45:07

Each finding traces back to the specific tool calls that produced the supporting evidence.

Third exfiltration vector: Secret Project Data burned to optical CD/DVD "IAMAN CD" with masqueraded filenames and decoy photos 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_0d5a6790
62ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_d87263a2
64ms
3
search
{ "exclude_sources": null, "max_results": 15, "queries": [ "Author", "Creator", "Company", "GPS", "Serial", "Producer...
tc_1e369e28
4ms
4
search
{ "exclude_sources": null, "max_results": 25, "queries": [ "Koala.jpg", "Tulips.jpg", "Penguins.jpg", "File Type" ], ...
tc_429306c8
4ms
17 files renamed with false extensions (masquerading) on removable media RM#2 to disguise leaked Office documents 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_62a66069
52ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_64dfac60
66ms
3
get_timeline
{ "limit": 50, "t_end": "2015-03-25T00:00:00", "t_start": "2015-03-24T00:00:00" }
tc_1dd92c90
2ms
Sensitive "Secret Project Data" copied from network share \\10.11.11.128\secured_drive to two removable USB drives (RM#1 and RM#2) 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_64dfac60
66ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "10.11.11.128", "regex": false, "source": nul...
tc_553cdb5f
5ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_62a66069
52ms
4
get_timeline
{ "limit": 50, "t_end": "2015-03-25T00:00:00", "t_start": "2015-03-24T00:00:00" }
tc_1dd92c90
2ms
Anti-forensic wiping/cleanup tools Eraser and CCleaner downloaded and executed after the data leak 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_f874bc29
61ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "ez.shimcache" }
tc_4baf803d
62ms
Network Share Access to Secured Drive Containing Secret Project Data 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_1f4618b9
62ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "10.11.11.128", "regex": false, "source": nul...
tc_4677eefe
4ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Secret Project Data", "regex": false, "sourc...
tc_507831a1
3ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "DhcpIPAddress", "regex": false, "source": nu...
tc_fb3af364
3ms
Informant created three unauthorized local Administrator accounts (admin11, ITechTeam, temporary) for persistence 5 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_90f3f830
65ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "chainsaw.hunt" }
tc_ba019ffb
63ms
3
search
{ "exclude_sources": null, "max_results": 30, "queries": [ "4720", "4722", "4724", "4732", "4726", "admin11", "ITechT...
tc_ab4a8f0c
9ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.admin11" }
tc_f58bad5f
63ms
5
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.temporary" }
tc_ecd12658
63ms
Two SanDisk Cruzer Fit USB storage devices connected to the informant PC (RM#1 and RM#2) 3 refs
1
query_registry_value
{ "case_id": "ndlc", "hive": "system", "image_path": "/evidence/cfreds_2015_data_leakage_pc.E01", "key_path": "Contro...
tc_24c2ef91
4372ms
2
query_registry_value
{ "case_id": "ndlc", "hive": "system", "image_path": "/evidence/cfreds_2015_data_leakage_pc.E01", "key_path": "Contro...
tc_c76b6d9d
4322ms
3
query_registry_value
{ "case_id": "ndlc", "hive": "system", "image_path": "/evidence/cfreds_2015_data_leakage_pc.E01", "key_path": "Contro...
tc_427964db
4301ms
Google Drive cloud sync client installed and run; user researched cloud-storage services for leaking data 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "ez.shimcache" }
tc_4baf803d
62ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_f874bc29
61ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Google Drive", "regex": false, "source": nul...
tc_4749446a
4ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "(drive\\.google|docs\\.google|dropbox|mail\\...
tc_f6a52bc3
5839ms
External emails, domains, and IPs on disk that represent potential exfiltration destinations 3 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\\.[A-Za-z]{...
tc_c3514976
150ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Eric_P._Lauer", "regex": false, "source": nu...
tc_ca95f6e7
3ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "10.11.11.128", "regex": false, "source": nul...
tc_553cdb5f
5ms
RM#2 target device contains only deleted files (all content removed); no shadow copies, steganography, or malware found 5 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "r/r\\s+\\d+:\\t(?!\\$)", "regex": true, "sou...
tc_20ae918e
206ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "vshadow.info" }
tc_29a8b73b
63ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "yara.files" }
tc_f6d195c4
62ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "binwalk.scan" }
tc_2e261a93
62ms
5
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_62a66069
52ms
Web search history shows premeditated research into data leakage, anti-forensics, and evidence destruction 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_d87263a2
64ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "how+to+leak+a+secret", "anti-forensic", "information+leak...
tc_4e8fb390
7ms
3
get_timeline
{ "limit": 50, "t_end": "2015-03-22T16:05:00", "t_start": "2015-03-22T14:30:00" }
tc_0ab8643c
14ms
Document metadata on RM#3 attributes the leaked files to author "company" via Microsoft Office; content is NIST / US federal government IT-investment data 4 refs
1
search
{ "exclude_sources": null, "max_results": 60, "queries": [ "Author", "Organization", "Company", "Creator", "Applicati...
tc_0cced7cc
10ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "Embedded OLE Servers", "Comp Obj User Type", "VBA", "Macr...
tc_73f900c1
4ms
3
search
{ "exclude_sources": null, "max_results": 15, "queries": [ "VBA", "vbaProject", "AutoOpen", "AutoExec", "Document_Ope...
tc_2b0946d0
4ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "yara.files" }
tc_1e01368f
62ms

Tool Call Details

Copied to clipboard