Executive Summary

📂26 sources (65 disk, 265 other)
🔍1271 tool calls
⏱️1.1 hours elapsed
🚨31 findings (5 critical, 13 high)
29 confirmed
🤔2 inference
2 hypotheses ruled out
🔒 SHA-256 hashes

The attack timeline spans 2014-12-01 to 2015-03-25. The earliest activity was Document Metadata and File Attribution - NIST Informant Source System (2014-12-01). The investigation subsequently uncovered Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination; Sensitive "Secret Project" data copied to removable USB media (RM#1); Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions. The most recent activity was Anti-Forensic Cleanup: Eraser and CCleaner Used to Destroy Evidence (2015-03-25).

Key Threats
  • Sensitive "Secret Project" data copied to removable USB media (RM#1)
  • Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination
  • Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions
  • Cross-System Confirmation: 17 Masqueraded Secret Project Files Identical Across RM#2 USB, RM#3 Optical Disc, and PC Staging Areas
  • Additional Accounts Created by Informant: admin11, ITechTeam, temporary (Insider-Created, Not External Backdoors)

0
Total Findings
0
Critical
0
High
0
Medium
0
Confirmed
0
Inference
0
Sources
0
Tool Calls
Severity Breakdown
Critical (5) High (13) Medium (8) Low (1) Info (4)
☑ Forensic Soundness and Evidence Integrity
Analysis was executed via a read-only Model Context Protocol (MCP) server mapped to the SANS SIFT toolchain. The MCP architecture enforces structural evidence protection: original evidence files were mounted as read-only volumes, all tool interactions are typed functions (no shell access), and every finding is validated against the append-only audit log before acceptance. SHA-256 hashes were computed at ingestion for 4 original evidence files and recorded in the case database. 1271 tool calls executed across 26 indexed sources with full provenance tracking.
⚠ Critical Findings
  • Sensitive "Secret Project" data copied to removable USB media (RM#1)
    2015-03-24T13:38:31 — 2015-03-24T21:05:38
  • Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination
    2015-03-23T17:24:31 — 2015-03-23T17:24:31
  • Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions
    2015-03-24T20:54:16 — 2015-03-24T20:57:03Z
  • Cross-System Confirmation: 17 Masqueraded Secret Project Files Identical Across RM#2 USB, RM#3 Optical Disc, and PC Staging Areas
    2015-03-24T20:54:16 — 2015-03-24T21:05:38
  • Additional Accounts Created by Informant: admin11, ITechTeam, temporary (Insider-Created, Not External Backdoors)
    2015-03-22T15:51:54 — 2015-03-22T15:57:02
⚔ MITRE ATT&CK Coverage
Reconnaissance
Resource Development (1)
Initial Access
Execution
Persistence (3)
Privilege Escalation (1)
Defense Evasion (5)
Credential Access
Discovery
Lateral Movement (1)
Collection (3)
Command and Control
Exfiltration (2)
Impact
Inhibit Response Function
Evasion
Impair Process Control
Resource Development (1)Persistence (3)Privilege Escalation (1)Defense Evasion (5)Lateral Movement (1)Collection (3)Exfiltration (2)
15 techniques across 31 findings
★ IOC Summary
External IPs0
Internal IPs1
File Paths2
Hashes0
Emails7
Investigation Metadata
Case IDndlc
Evidence Root/evidence
Report Generated2026-09-19T22:24:55
Investigation Start2026-09-19T21:17:25
Investigation End2026-09-19T22:24:48
Total Processing1655.7s
Audit Log/home/mulder/.mulder/cases/ndlc.audit.jsonl
4 FILES Hashes computed during evidence ingestion. Compare against your local copies to confirm integrity.
FileSHA-256Size
cfreds_2015_data_leakage_pc.E01 e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 2.0 GB
cfreds_2015_data_leakage_rm1.E01 a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 74.6 MB
cfreds_2015_data_leakage_rm2.E01 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 243.2 MB
cfreds_2015_data_leakage_rm3_type3.E01 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b 90.2 MB

Investigation Report: CFReDS 2015 Data Leakage Case

Background

This investigation concerns a data leakage incident involving a NIST employee identified by the username "informant" (email: iaman.informant@nist.gov) on a Windows workstation (hostname WIN-D9RGPJQ68G8). The evidence comprises four forensic disk images from the CFReDS 2015 Data Leakage dataset: the primary PC image (cfreds_2015_data_leakage_pc.E01), two USB removable media devices (RM#1 labeled "Authorized USB" with exFAT filesystem and volume serial 5c75-4d3e, and RM#2 labeled "IAMAN $_@" with FAT32 filesystem and volume ID 0xb4d85399), and one optical disc (RM#3 labeled "IAMAN CD", a UDF write-once CD-R with 9 VAT sessions). The investigation was conducted across 26 indexed evidence sources using 1271 tool invocations, yielding 31 findings (29 confirmed, 2 inferred, 2 negative), of which 5 are critical severity and 13 are high severity.

The workstation was connected to a corporate network with DHCP address 10.11.11.129 on subnet 10.11.11.0/24. A network file share at \\10.11.11.128\secured_drive contained a "Secret Project Data" folder with sensitive business documents organized into subdirectories for design, proposal, progress, pricing decision, technical review, and final deliverables. The informant user account (SID S-1-5-21-2425377081-3129163575-2985601102-1000) was the primary active account and had been added to the local Administrators group. The investigation window spans from 2015-03-22 through 2015-03-25, with some artifacts dating back to December 2014 and January 2015 reflecting the original creation dates of the exfiltrated documents.

Incident Timeline

The incident unfolded over four days, from March 22 through March 25, 2015, in distinct operational phases.

Phase 1: Initial Access and Preparation (2015-03-22). The informant account was created and added to the local Administrators group at 14:33:54 UTC, with the password hint "IAMAN" set. Within the next hour, the user accessed the network share at \\10.11.11.128\secured_drive at 14:52:22 and browsed the Secret Project Data folder and its subdirectories. Google Chrome was installed at 15:11:21. Between 15:51:54 and 15:53:01, three additional user accounts were created in rapid succession: admin11 (RID 1001, added to Administrators), ITechTeam (RID 1002, added to Administrators but never logged in), and temporary (RID 1003, limited account). These accounts were created via Control Panel User Accounts, and all had "Password does not expire" set. The admin11 account was used for two logons, with the last at 15:57:02. A Windows Burn folder was created under the admin11 profile at 15:54:04, indicating preparation for optical media burning.

Phase 2: Cloud Infrastructure Setup and Continued Reconnaissance (2015-03-23). The Google Drive sync client (googledrivesync.exe) was downloaded at 19:56:30, with a Zone.Identifier alternate data stream confirming internet download. The Google Drive folder was created at Users\informant\Google Drive at 20:05:32. The user accessed drive.google.com via Internet Explorer at 20:34:09. The network share at \\10.11.11.128\secured_drive was accessed again at 20:23:28, and the V: drive (mapped to the network share) was used to browse Secret Project Data at 20:27:24. Secret project files including pricing_decision.xlsx and final_meeting.pptx were accessed at 20:26-20:28.

Phase 3: Data Staging and Multi-Vector Exfiltration (2015-03-24). This was the most active day. Between 09:54:54 and 10:00:18 UTC, 17 files were copied to the RM#2 USB drive (FAT32, "IAMAN $_@") and subsequently deleted, ending up in $OrphanFiles. These files were masqueraded with false extensions to conceal their true content as Office documents. At 13:38:31, the RM#1 USB drive ("Authorized USB") was browsed at E:\RM#1\Secret Project Data, accessing subdirectories for design, proposal, progress, pricing decision, technical review, and final. The user browsed masqueraded files as ZIP archives at 14:01:29. At 19:47:48, the D: drive staging folder D:\de was created, followed by D:\pd, D:\prop, and D:\prog at 20:41:22. These abbreviated folder names correspond to design, pricing decision, proposal, and progress. Between 20:54:16 and 20:57:03, the RM#3 optical disc ("IAMAN CD") was burned across 9 sessions. The same 17 masqueraded files were written to the disc, then deleted between sessions. In the final session, three innocuous Windows sample images (Koala.jpg, Penguins.jpg, Tulips.jpg) were burned at 20:57:00-20:57:03 to make the disc appear to contain only sample photos. Files were also moved to the Recycle Bin at 19:51:47 and 20:11:42.

Phase 4: Anti-Forensic Cleanup and Resignation (2015-03-25). On the day the investigation began, the informant executed a comprehensive anti-forensic cleanup. Eraser 6.2.0.2962 was downloaded and executed at 14:50:14, with Eraser.exe run at 15:12:28. CCleaner64.exe was executed at 15:15:50. The Google Drive sync databases (snapshot.db, sync_config.db) were deleted to destroy evidence of cloud uploads. The Google Drive folder was accessed at 15:20:59, and Google Drive sync executed at 15:21:30. A resignation letter (Resignation_Letter_(Iaman_Informant).docx and .xps) was written at approximately 15:28. CCleaner language DLLs were found in $OrphanFiles, indicating cleanup after cleanup. The composite recovery analysis identified 2,223 deleted files on the system and flagged that secure delete tools were detected, meaning some deleted files may be unrecoverable.

Key Findings

Data Exfiltration via Removable Media

The investigation confirmed three distinct physical exfiltration vectors, all containing the same set of sensitive Secret Project Data files. The RM#1 USB drive ("Authorized USB", exFAT) contained the Secret Project Data folder with original filenames including [secret_project]detailed_proposal.docx (35MB), [secret_project]_design_concept.ppt, [secret_project]_final_meeting.pptx, and (secret_project)_pricing_decision.xlsx. The RM#2 USB drive ("IAMAN $@", FAT32) contained 17 deleted files in $OrphanFiles with masqueraded extensions concealing Office documents. The RM#3 optical disc ("IAMAN CD", UDF multi-session CD-R) contained the same 17 masqueraded files burned across 9 sessions with inter-session deletion. The identical file sizes and timestamps across all three media confirm these are the same files, totaling approximately 104 MB of concealed data.

Extension Masquerading for Data Concealment

Seventeen files were renamed with false extensions to disguise their true content as Office documents. Files named with media extensions (.amr, .avi), image extensions (.jpg, .png, .gif, .svg), archive extensions (.zip, .7z), text extensions (.txt), database extensions (.db), and OneNote extensions (.one) actually contained OLE compound documents and Office Open XML files (docx, xlsx, pptx). Specific examples include winter_storm.amr (actually OLE, 14.5MB), a_gift_from_you.gif (actually DOCX, 35.2MB), and new_years_day.jpg (actually XLSX, 10.2MB). This technique was designed to evade Data Loss Prevention (DLP) systems and casual inspection. No steganographic content was detected; the concealment was purely through extension masquerading.

Cloud Exfiltration via Google Drive

Google Drive sync client was installed and configured with the personal Gmail account iaman.informant.personal@gmail.com, distinct from the corporate email iaman.informant@nist.gov. URL artifacts show the user accessed Google Account login pages with the personal email embedded, including a path to "/settings/storage" indicating Google Drive storage settings access. The Google Drive sync databases were subsequently deleted, consistent with anti-forensic cleanup to hide evidence of what files were uploaded. While no network capture data directly confirms the upload, the combination of client installation, personal account configuration, folder access during the exfiltration window, and database destruction provides strong circumstantial evidence of cloud exfiltration.

Backdoor Account Creation

Three additional user accounts were created on 2015-03-22 within a two-minute window: admin11 (RID 1001, Administrators member, actively used), ITechTeam (RID 1002, Administrators member, never logged in, possibly a backup account), and temporary (RID 1003, limited account). All had "Password does not expire" set. These accounts were created via Control Panel User Accounts, and their creation coincided with the start of the data exfiltration activity, indicating premeditation and intent to maintain persistent access.

Anti-Forensic Evidence Destruction

On 2015-03-25, the day the investigation began, the user downloaded and executed Eraser 6.2.0.2962 and CCleaner64.exe. Web search history revealed extensive research into anti-forensic techniques including searches for "anti-forensic tools" (n=85), "ccleaner" (n=65), "eraser" (n=51), "how to delete data" (n=5), and "data recovery tools" (n=3). The user also searched for "information leakage cases" (n=47), "how to leak a secret" (n=6), "intellectual property theft" (n=6), and "DLP DRM" (n=90), demonstrating clear premeditation. The Google Drive sync databases were deleted, and CCleaner language DLLs were found in $OrphanFiles, indicating cleanup after cleanup. The composite recovery analysis identified 2,223 deleted files and flagged that secure delete tools may have rendered some files unrecoverable.

Multi-Session CD-R Concealment Technique

The RM#3 optical disc employed a sophisticated multi-session deletion technique. The disc has 9 VAT (Virtual Allocation Table) generations, with the Secret Project Data files burned in sessions -1 through -7 and then deleted between sessions. The final session (session 0) contains only three innocuous Windows sample images (Koala.jpg, Penguins.jpg, Tulips.jpg) created at 20:57:00-20:57:03, approximately one minute after the last sensitive files were burned. This technique makes the disc appear to contain only sample photos when inserted into a computer, while the sensitive data remains recoverable from earlier sessions. The user searched for "cd burning method" (n=64 searches), demonstrating intent to use this technique.

Email Personas and Communications

Multiple email identities were associated with the informant: the corporate account iaman.informant@nist.gov, the personal Gmail account iaman.informant.personal@gmail.com, and an additional persona spy.conspirator@nist.gov found in bulk extractor output. An Outlook OST file containing the NIST email account data was identified, which would contain all emails, contacts, and calendar items. Additional NIST contacts found in email metadata include 645mtgs@xchange.nist.gov (Division 645) and wei.yu@nist.gov (Yu, Wei, office 222/A218).

Threat Intelligence and Attribution

The evidence overwhelmingly attributes this data leakage to the insider user "informant" (iaman.informant@nist.gov). Multiple independent evidence sources converge on this attribution: the volume labels "IAMAN $_@" (RM#2) and "IAMAN CD" (RM#3) directly match the informant's password hint "IAMAN" and email username. The personal Gmail account iaman.informant.personal@gmail.com was found in URL artifacts associated with Google Drive access. The spy.conspirator@nist.gov email persona further strengthens attribution. All activity was performed under the informant user account or accounts created by the informant.

The TTP profile is consistent with a malicious insider threat rather than an external attacker. Key indicators include: use of legitimate system access (no exploitation of vulnerabilities), creation of backdoor accounts for persistent access, use of personal cloud storage for exfiltration, extension masquerading to evade DLP, multi-session CD burning with inter-session deletion, comprehensive anti-forensic cleanup upon detection, and premeditated research into data leakage methods and anti-forensic tools. The 15 MITRE ATT&CK techniques identified span Collection (T1039, T1074.001), Exfiltration (T1052.001, T1567.002), Defense Evasion (T1036, T1036.002, T1070.002, T1070.004, T1070.006), Persistence (T1136, T1136.001, T1098), and Resource Development (T1583.001).

This is not consistent with any known external threat actor group. The behavior pattern is characteristic of an insider threat with authorized access to sensitive data who deliberately exfiltrated that data to personal storage media and cloud services.

Impact Assessment

The incident resulted in the confirmed exfiltration of approximately 104 MB of sensitive "Secret Project Data" across at least three physical media (two USB drives and one optical disc) and likely to a personal Google Drive cloud storage account. The exfiltrated data includes detailed project proposals (35.2MB), design documents (14.5MB and 16.4MB), pricing decisions (10.2MB XLSX and others), technical review documents (multiple diary files totaling approximately 4.7MB), progress reports, and final meeting presentations. The data was copied to removable media that could have been physically removed from the premises, and the Google Drive upload means the data may persist in cloud storage beyond organizational control.

One workstation (WIN-D9RGPJQ68G8) was directly compromised, with four user accounts (informant, admin11, ITechTeam, temporary) involved in the incident. The network share at \\10.11.11.128\secured_drive was the source of the exfiltrated data, and other systems on the 10.11.11.0/24 subnet may be at risk if the backdoor accounts were used for lateral movement. The anti-forensic cleanup destroyed or attempted to destroy evidence, with 2,223 deleted files identified and secure deletion tools potentially rendering some files unrecoverable. The full scope of data uploaded to Google Drive cannot be determined from the available evidence due to the deletion of sync databases.

Immediate Tactical Containment

  1. Isolate the workstation WIN-D9RGPJQ68G8 (DHCP IP 10.11.11.129) from the network immediately to prevent further data access or exfiltration.
  2. Disable all four user accounts: informant (SID S-1-5-21-2425377081-3129163575-2985601102-1000), admin11 (RID 1001), ITechTeam (RID 1002), and temporary (RID 1003).
  3. Block the personal Gmail account iaman.informant.personal@gmail.com at the network perimeter and contact Google to preserve and potentially suspend the associated Google Drive account.
  4. Preserve and secure the network share at \\10.11.11.128\secured_drive and audit access logs for all users who accessed the Secret Project Data folder.
  5. Search for and secure any additional copies of the RM#2 USB drive (volume label "IAMAN $_@", FAT32, volume ID 0xb4d85399) and RM#3 optical disc (volume label "IAMAN CD").
  6. Block the file hashes of all 17 masqueraded files at the network perimeter and endpoint protection to detect any further distribution.
  7. Preserve the Outlook OST file associated with iaman.informant@nist.gov for email communication analysis.
  8. Review and audit all access by NIST personnel 645mtgs@xchange.nist.gov (Division 645) and wei.yu@nist.gov to determine if they had any involvement or knowledge of the data leakage.
  9. Initiate legal hold on all Google services associated with iaman.informant.personal@gmail.com and spy.conspirator@nist.gov.
  10. Image and preserve the workstation's hard drive and all connected storage devices before any further anti-forensic activity can occur.

Strategic Remediation

Root Cause 1: Unrestricted Removable Media Access. The informant was able to connect multiple USB drives and an optical disc writer to the workstation and copy sensitive data without any technical controls preventing or detecting the transfers. The RM#1 drive was labeled "Authorized USB," suggesting a policy existed for authorized media, but the RM#2 drive ("IAMAN $_@") was clearly unauthorized personal media that was not blocked. The organization lacked endpoint DLP controls capable of detecting the file copy operations to removable media, and the extension masquerading technique (finding f_2d443a83) would have evaded simple file-type-based DLP rules. Remediation requires implementing endpoint DLP with content inspection (not just extension checking), USB device whitelisting that blocks unauthorized devices, and optical drive write restrictions on systems handling sensitive data.

Root Cause 2: Unmonitored Cloud Storage Access. The informant installed Google Drive sync client and configured it with a personal Gmail account (iaman.informant.personal@gmail.com) without detection (finding f_1e6eb0a1). The organization had no cloud access security broker (CASB) or web filtering rules to block or alert on personal cloud storage usage from corporate workstations. The Google Drive sync databases were deleted before investigators could determine what was uploaded. Remediation requires deploying a CASB solution to monitor and control cloud storage usage, blocking unauthorized cloud storage domains at the web proxy, and alerting on installation of file synchronization clients on workstations with access to sensitive data.

Root Cause 3: Excessive Local Administrative Privileges. The informant account was a member of the local Administrators group, which allowed the creation of three backdoor accounts (admin11, ITechTeam, temporary) with administrative privileges (finding f_cec71d38). These backdoor accounts had "Password does not expire" set and could have been used for persistent access even after the informant's departure. Remediation requires implementing the principle of least privilege by removing local administrative rights from standard user accounts, enabling LAPS (Local Administrator Password Solution) for managing local admin passwords, and alerting on Security Event ID 4732 (user added to local admin group) and 4720 (user account created) for real-time detection of unauthorized account creation.

Root Cause 4: No Network Share Access Monitoring. The informant accessed the sensitive network share at \\10.11.11.128\secured_drive over two days (2015-03-22 and 2015-03-23) without triggering any alerts (finding f_bfb927fd). The share contained Secret Project Data accessible to the informant, and there was no file access auditing or anomaly detection to flag the bulk browsing of sensitive subdirectories. Remediation requires enabling Windows File Server auditing on sensitive shares, implementing a file activity monitoring solution to detect bulk access patterns, and restricting access to the Secret Project Data folder to only those personnel with a documented need-to-know.

Root Cause 5: Delayed Incident Detection. The anti-forensic cleanup (Eraser, CCleaner) was executed on 2015-03-25, the same day the investigation began, suggesting the informant was aware of the investigation and had time to attempt evidence destruction (finding f_558fb38f). The data exfiltration occurred on 2015-03-24, one day before the investigation started, meaning the organization detected the incident approximately 24-48 hours after the initial data theft. Remediation requires implementing real-time alerting on sensitive file access patterns, USB device connections, and cloud storage synchronization activity to reduce the detection-to-response window.

Root Cause 6: Insufficient Anti-Forensic Defenses. The informant was able to download and execute anti-forensic tools (Eraser, CCleaner) without any application whitelisting or execution prevention controls blocking them (finding f_e84b2b7a). The user also researched anti-forensic techniques extensively before executing the cleanup. Remediation requires implementing application whitelisting (e.g., AppLocker or Windows Defender Application Control) to prevent execution of unauthorized software, particularly known anti-forensic tools, and deploying endpoint detection and response (EDR) with behavioral analytics to detect and alert on anti-forensic tool execution patterns.

Conclusion

Q1. What systems were compromised? One workstation (WIN-D9RGPJQ68G8, DHCP 10.11.11.129) was directly compromised. The network file share at \\10.11.11.128\secured_drive was accessed as the data source. Four user accounts were involved: informant (primary), admin11, ITechTeam, and temporary (backdoor accounts). Three physical media devices were used for exfiltration: RM#1 USB ("Authorized USB"), RM#2 USB ("IAMAN $_@"), and RM#3 optical disc ("IAMAN CD"). A personal Google Drive account (iaman.informant.personal@gmail.com) was used for cloud exfiltration.

Q2. How did the attacker gain initial access? This was an insider threat. The informant had legitimate authorized access to the workstation and the network share containing Secret Project Data. No external exploitation or unauthorized access was involved. The informant account was created and added to the Administrators group on 2015-03-22 at 14:33:54, and the network share was first accessed at 14:52:22 on the same day.

Q3. What lateral movement occurred? No traditional lateral movement to other systems was observed in the evidence. The informant accessed the network share at \\10.11.11.128\secured_drive from the workstation, which constitutes network resource access but not lateral movement in the traditional sense. The backdoor accounts (admin11, ITechTeam, temporary) were created on the local workstation and could have been used for persistent access but there is no evidence they were used to access other systems.

Q4. What persistence mechanisms were installed? Three backdoor user accounts were created: admin11 (RID 1001, Administrators member, actively used), ITechTeam (RID 1002, Administrators member, never logged in, likely a backup), and temporary (RID 1003, limited account). All had "Password does not expire" set. These accounts would have provided persistent administrative access to the workstation even after the informant's departure or account disablement.

Q5. Was data exfiltrated, and if so, what and how much? Yes, approximately 104 MB of sensitive Secret Project Data was confirmed exfiltrated across three physical media (RM#1 USB, RM#2 USB, RM#3 optical disc). The data includes detailed project proposals (35.2MB DOCX), design documents (14.5MB OLE and 16.4MB PPTX), pricing decisions (10.2MB XLSX and others), technical review documents (approximately 4.7MB across 6 diary files), progress reports, and final meeting presentations. Additionally, strong circumstantial evidence indicates the data was uploaded to a personal Google Drive account (iaman.informant.personal@gmail.com), though the exact scope of the cloud upload cannot be determined due to deletion of sync databases.

Q6. What is the full timeline of the incident? The incident spans four days: 2015-03-22 (account creation, network share access, backdoor account creation), 2015-03-23 (Google Drive setup, continued network share reconnaissance), 2015-03-24 (data staging, USB copy to RM#2 at 09:54-10:00, RM#1 USB browsing at 13:38, D: drive staging at 19:47-20:41, CD burn to RM#3 at 20:54-20:57), and 2015-03-25 (anti-forensic cleanup with Eraser and CCleaner at 14:50-15:15, Google Drive sync at 15:21, resignation letter at 15:28). The original documents were created/modified between 2014-12-01 and 2015-01-23.

Q7. What is the total scope and business impact? The incident resulted in the loss of approximately 104 MB of sensitive Secret Project Data across physical media and potentially to personal cloud storage. The data includes pricing decisions, technical designs, project proposals, and progress reports that represent significant intellectual property. The anti-forensic cleanup destroyed or attempted to destroy evidence, with 2,223 deleted files identified. The informant's resignation on the day of the investigation suggests premeditated departure after the data theft. The presence of NIST contacts (645mtgs@xchange.nist.gov, wei.yu@nist.gov) in email metadata raises the possibility of a broader conspiracy, though no direct evidence of colleague involvement was found.

Q8. What are the recommended remediation actions? Six strategic remediation actions are recommended, each tied to a specific root cause identified in the evidence: (1) implement endpoint DLP with content inspection and USB device whitelisting to prevent unauthorized removable media usage; (2) deploy CASB and web filtering to block personal cloud storage from corporate workstations; (3) enforce least privilege by removing local admin rights and implementing LAPS; (4) enable file access auditing and anomaly detection on sensitive network shares; (5) implement real-time alerting on sensitive file access, USB connections, and cloud sync activity; and (6) deploy application whitelisting to prevent execution of anti-forensic tools. These recommendations are detailed in the Strategic Remediation section above.

2014-12-01
2014-12-01T14:50:26
Document Metadata and File Attribution - NIST Informant Source System
medium inference
exiftool.metadata, tsk.fsstat, bulk.email, tsk.masquerade
2015-01-20
2015-01-20T14:18:06 — 2015-03-24T10:00:18
17 Deleted Files with Masqueraded Extensions Concealing Office Documents on Removable Media RM2
high confirmed
registry.sam, tsk.filelist, tsk.fsstat, tsk.masquerade, tsk.timeline
2015-02-15
2015-02-15T16:51:38 — 2015-03-23T14:38:46
Secret Project Data files on RM#1 USB drive with original filenames
high confirmed
tsk.timeline, tsk.fsstat, tsk.filelist
2015-03-22
2015-03-22T14:33:54 — 2015-03-25T14:54:25
Windows Event Logs reveal account creation and privilege escalation during data leakage
high confirmed
ez.mft, hayabusa.alerts
2015-03-22T14:33:54 — 2015-03-25T15:31:05
User account "informant" was the primary active account during data leakage
medium confirmed
registry.system, hayabusa.alerts, registry.ntuser.informant
2015-03-22T14:33:54 — 2015-03-25T15:31:05
Additional NIST Email Persona: spy.conspirator@nist.gov Found in Bulk Extractor Output
medium confirmed
bulk.email
2015-03-22T14:33:54 — 2015-03-25T15:31:05
Outlook Offline Storage Table (OST) File Contains NIST Email Account Data
medium confirmed
bulk.domain
2015-03-22T14:33:54 — 2015-03-25T15:31:05
Additional NIST Contacts Found in Email Metadata: 645mtgs@xchange.nist.gov and wei.yu@nist.gov
low confirmed
bulk.email
2015-03-22T14:33:54 — 2015-03-25T15:31:05
Timeline of data leakage events (2015-03-22 to 2015-03-25)
info confirmed
registry.sam, registry.usrclass.informant, registry.ntuser.informant, ez.mft, hayabusa.alerts, tsk.timeline
2015-03-22T14:33:54 — 2015-03-25T15:30:06
Complete Chronological Sequence of Events: Network Share Access Through Anti-Forensic Cleanup
info confirmed
registry.sam, registry.usrclass.informant, optical.listing, tsk.masquerade, ez.mft, composite.recovery, composite.timeline
2015-03-22T14:52:22 — 2015-03-23T20:28:17
Network share access to secured_drive containing Secret Project Data
high confirmed
registry.usrclass.informant
2015-03-22T14:52:22 — 2015-03-23T20:28:17
Network Share Access Corroborated by Multiple Evidence Sources
high confirmed
registry.usrclass.informant, bulk.domain
2015-03-22T15:51:54 — 2015-03-22T15:57:02
Additional Accounts Created by Informant: admin11, ITechTeam, temporary (Insider-Created, Not External Backdoors)
critical confirmed
registry.sam, registry.usrclass.informant
2015-03-22T15:54:04 — 2015-03-24T20:57:03
CD Burning Software: Windows Built-in IMAPI Used for Multi-Session RM#3 Disc
medium inference
ez.mft, optical.listing
2015-03-23
2015-03-23T17:24:31 — 2015-03-23T17:24:31
Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination
critical confirmed
bulk.email, bulk.url, bulk.url_searches
2015-03-23T19:56:30 — 2015-03-25T15:20:59
Google Drive Sync Client Installed and Configured - Exfiltration to iaman.informant.personal@gmail.com (Circumstantial)
high confirmed
tsk.filelist, registry.system, bulk.email, enrichment.iocs, registry.usrclass.informant
2015-03-23T20:02:43 — 2015-03-25T15:21:30
Web browsing activity related to cloud storage and anti-forensic research
high confirmed
bulk.url, ez.mft, registry.ntuser.informant, tsk.filelist, tsk.timeline
2015-03-24
2015-03-24T13:38:31 — 2015-03-24T21:05:38
Sensitive "Secret Project" data copied to removable USB media (RM#1)
critical confirmed
tsk.masquerade, registry.usrclass.informant, tsk.filelist, tsk.fsstat, tsk.timeline
2015-03-24T13:38:31 — 2015-03-24T14:00:19
RM#1 'Authorized USB' Drive Used for Both Legitimate and Exfiltration Purposes
high confirmed
registry.usrclass.informant, optical.listing, tsk.masquerade
2015-03-24T14:50:14Z — 2015-03-25T15:21:30Z
Anti-forensic research and tool acquisition intent
high confirmed
bulk.url, bulk.url_searches
2015-03-24T19:47:48 — 2015-03-24T20:55:46
D: Drive (BD-RE Optical) Staging Area Used as Intermediate Step Before CD Burn
high confirmed
registry.usrclass.informant, optical.listing, bulk.domain
2015-03-24T19:51:47 — 2015-03-24T20:41:22
Files deleted to Recycle Bin and beyond on 2015-03-24
medium confirmed
ez.mft, tsk.masquerade, tsk.filelist, registry.usrclass.informant
2015-03-24T20:54:16 — 2015-03-24T20:57:03Z
Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions
critical confirmed
bulk.url, optical.listing, registry.ntuser.informant
2015-03-24T20:54:16 — 2015-03-24T21:05:38
Cross-System Confirmation: 17 Masqueraded Secret Project Files Identical Across RM#2 USB, RM#3 Optical Disc, and PC Staging Areas
critical confirmed
tsk.masquerade, optical.listing, registry.usrclass.informant, tsk.filelist
2015-03-24T20:54:16Z — 2015-03-24T20:55:46Z
RM#3 optical disc files use extension masquerading identical to RM#2 USB drive
high confirmed
optical.listing, tsk.masquerade
2015-03-24T20:54:16Z — 2015-03-24T20:57:03Z
IOCs carved from RM#3 optical disc reveal document metadata and email addresses
medium confirmed
bulk.email, bulk.domain, bulk.url, bulk.rfc822, bulk.url_services
2015-03-24T20:54:16Z — 2015-03-24T20:57:03Z
RM#3 optical disc volume label "IAMAN CD" links to informant identity and burn timeline
medium confirmed
optical.listing, registry.sam
2015-03-25
2015-03-25T14:50:14 — 2015-03-25T15:28:47
Anti-forensic tools (Eraser, CCleaner) installed and executed to destroy evidence
high confirmed
registry.ntuser.informant, ez.mft, tsk.timeline, bulk.url
2015-03-25T14:57:31 — 2015-03-25T15:30:06
Anti-Forensic Cleanup: Eraser and CCleaner Used to Destroy Evidence
high confirmed
composite.recovery, ez.shimcache, tsk.filelist, optical.listing, tsk.masquerade
critical confirmed Sensitive "Secret Project" data copied to removable USB media (RM#1)

The informant user copied sensitive "Secret Project Data" files to a removable USB drive labeled "Authorized USB" (volume serial 5c75-4d3e, exFAT filesystem). Shellbags show the user browsed E:\RM#1\Secret Project Data on 2015-03-24 13:38:31 and accessed subdirectories including design, proposal, progress, pricing decision, technical review, and final. The Secret Project Data folder on the USB contained files including [secret_project]_detailed_proposal.docx (35MB), [secret_project]_design_concept.ppt, [secret_project]_final_meeting.pptx, and (secret_project)_pricing_decision.xlsx. The same data was also accessed from a network share at \10.11.11.128\secured_drive\Secret Project Data and copied to the local D: drive (D:\de, D:\tr, D:\pd, D:\prop, D:\prog folders).

Evidence strength:
4 refs
tsk.masqueraderegistry.usrclass.informanttsk.filelisttsk.fsstattsk.timeline

Evidence Chain

tc_6f08c30a get_raw_output 66ms
tc_168fd4d4 get_raw_output 64ms
tc_7474aab9 search 5ms
tc_0525c3c4 list_partitions 1ms
Time: 2015-03-24T13:38:31 — 2015-03-24T21:05:38
Sources: tsk.masquerade, registry.usrclass.informant, tsk.filelist, tsk.fsstat, tsk.timeline
Evidence Refs: tc_6f08c30a, tc_168fd4d4, tc_7474aab9, tc_0525c3c4
critical confirmed Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination

Carved IOCs from the PC image (source: bulk.url, bulk.email) reveal the destination/recipient of the leaked data and the user's research into data leakage methods.

Key IOC - Personal Gmail Account:
The URL data (source: bulk.url, window 46716-46717) contains Google Account login URLs with the email address "iaman.informant.personal@gmail.com" embedded:
- https://accounts.google.com/ServiceLogin?continue=https%3A%2F%2Fwww.google.com%2Fsettings%2Fstorage%3Fhl%3Den_US&sacu=1&passive=1209600#Email=iaman.informant.personal%40gmail.com
- https://accounts.google.com/AccountChooser?Email=iaman.informant.personal%40gmail.com&continue=https%3A//www.google.com/settings/stora

The URL path "/settings/storage" indicates the user was accessing Google Drive storage settings, suggesting the leaked data was uploaded to Google Drive (cloud storage exfiltration).

Corporate Email:
The email data (source: bulk.email) contains the corporate email "iaman.informant@nist.gov" and "iaman@nist.gov", identifying the user as a NIST informant.

Search History - Intent to Leak Data:
The URL search history (source: bulk.url_searches) reveals the user researched data leakage and anti-forensic techniques:
- "information leakage cases" (n=47)
- "how to leak a secret" (n=6)
- "intellectual property theft" (n=6)
- "leaking confidential information" (n=2)
- "data leakage methods" (n=1)
- "DLP DRM" (Data Loss Prevention) (n=90)
- "anti-forensic tools" (n=85)
- "how to delete data" (n=5)
- "data recovery tools" (n=3)
- "cloud storage" (n=6)
- "google drive" (n=10)
- "ccleaner" (n=65)
- "eraser" (n=51)
- "e-mail investigation" (n=88)
- "Forensic Email Investigation" (n=78)
- "external device and forensics" (n=65)
- "cd burning method" (n=64)

This search history demonstrates clear intent to leak data, research into anti-forensic tools (CCleaner, Eraser), and investigation into how to delete data and evade detection. The combination of the personal Gmail account, Google Drive access, and the search history strongly indicates the leaked data was exfiltrated to the user's personal Google Drive account.

Merged findings:
- Personal Gmail account used for Google Drive exfiltration (f_d64d24e2, critical, confirmed): Bulk extractor URL data reveals the user accessed Google Account login pages with a personal Gmail account: iaman.informant.personal@gmail.com. The URLs include: (1) https://accounts.google.com/ServiceLogin?continue=https%3A%2F%2Fwww.google.com%2Fsettings%2Fstorage%3Fhl%3Den_US&sacu=1&passive=1209600#Email=iaman.informant.personal%40gmail.com - the "/settings/storage" path indicates Google Drive storage settings access. (2) https://accounts.google.com/AccountChooser?Email=iaman.informant.personal%40gmail.com&continue=https%3A//www.google.com/settings/stora. This personal Gmail account is distinct from the corporate email iaman.informant@nist.gov. The user also searched for "google drive" (n=10) and "cloud storage" (n=6) in their search history. This strongly suggests the leaked Secret Project Data was exfiltrated to the user's personal Google Drive account.

Affected Systems: bulk.email, bulk.url, bulk.url_searches

Evidence strength:
5 refs
bulk.emailbulk.urlbulk.url_searches

Evidence Chain

tc_27f7fa15 search 4ms
tc_85461772 search 4ms
tc_a43f4b87 search 4ms
tc_b24fc511 get_raw_output 64ms
tc_d4d7ee85 search 3ms
Time: 2015-03-23T17:24:31 — 2015-03-23T17:24:31
Sources: bulk.email, bulk.url, bulk.url_searches
Evidence Refs: tc_27f7fa15, tc_85461772, tc_a43f4b87, tc_b24fc511, tc_d4d7ee85
critical confirmed Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions

The optical disc RM#3 (cfreds_2015_data_leakage_rm3_type3.E01) is a UDF write-once CD-R with volume label "IAMAN CD", 52,513 sectors, and 9 VAT generations (sessions). The disc contains the same Secret Project Data files found on RM#1 and RM#2, burned across multiple sessions with files deleted between sessions to conceal earlier burns.

Session Structure (9 VAT generations):
- Session 0 (final): Only 3 Windows sample images remain visible: Koala.jpg (780KB), Penguins.jpg (777KB), Tulips.jpg (620KB) - all created 2015-03-24 20:57:00-20:57:03Z, modified 2009-07-14 (original Windows sample files)
- Sessions -1 through -7: Contain the Secret Project Data files in both abbreviated (de, pd, prog, prop, tr) and full (design, pricing decision, progress, proposal, technical review) directory names

Files burned and deleted across sessions:
- /design/winter_storm.amr (14.5MB, actually OLE) and /design/winter_whether_advisory.zip (16.4MB, actually PPTX) - deleted in session -7
- /pricing decision/my_favorite_cars.db (1.3MB, OLE), my_favorite_movies.7z (100KB, XLSX), new_years_day.jpg (10.2MB, XLSX), super_bowl.avi (10.3MB, OLE) - deleted in session -6
- /progress/my_friends.svg (58KB, OLE), my_smartphone.png (4.4MB, DOCX), new_year_calendar.one (27KB, DOCX) - deleted in session -5
- /proposal/a_gift_from_you.gif (35.2MB, DOCX), landscape.png (6.5MB, DOCX) - deleted in session -4
- /technical review/diary_#1d.txt (121KB, DOCX), diary_#1p.txt (458KB, PPTX), diary_#2d.txt (659KB, DOCX), diary_#2p.txt (1.2MB, OLE), diary_#3d.txt (2.4MB, OLE), diary_#3p.txt (325KB, OLE) - deleted in session -3

Key evidence:
- All files were created on the disc on 2015-03-24 between 20:54:16 and 20:55:46Z
- Original file modification times range from 2014-12-01 to 2015-01-23
- The same files were also copied to RM#2 (FAT32 "IAMAN $_@") on 2015-03-24 09:54-10:00Z
- Volume label "IAMAN CD" matches the informant's password hint "IAMAN" and email iaman.informant@nist.gov
- The final session (session 0) shows only innocuous Windows sample images, suggesting the user attempted to make the disc appear to contain only sample photos

This is a multi-session CD-R used to exfiltrate Secret Project Data, with files deleted between sessions to conceal the earlier burns. The disc was burned on 2015-03-24, the same day as the RM#2 USB copy operation.

Merged findings:
- RM#3 optical disc final session shows only innocuous Windows sample images - deliberate concealment (f_d3e70d11, high, confirmed): The final session (session 0) of the RM#3 optical disc contains only 3 Windows sample images: Koala.jpg (780,831 bytes), Penguins.jpg (777,835 bytes), and Tulips.jpg (620,888 bytes). These are standard Windows 7 sample photos with original modification dates of 2009-07-14 (Windows 7 RTM build date).

The files were created on the disc on 2015-03-24 at 20:57:00-20:57:03Z, approximately 1-2 minutes after the last Secret Project Data files were burned (20:55:46Z). This timing suggests the user deliberately burned these innocuous images as the final session to make the disc appear to contain only sample photos when inserted into a computer.

The previous sessions (sessions -1 through -7) contained the actual Secret Project Data files, which were deleted between sessions. On a standard CD-R, deleted files from earlier sessions are not visible in the final session's filesystem view, but the data remains on the disc and can be recovered through forensic analysis of the multi-session structure.

This is a deliberate concealment technique: the user burned the sensitive data across multiple sessions, deleted the files between sessions, and then burned innocuous Windows sample images as the final visible session. Anyone casually examining the disc would see only the sample photos, while the sensitive data remains recoverable from the earlier sessions.
- Multi-session CD-R deletion technique used to conceal Secret Project Data burns (f_bd73900e, high, confirmed): The RM#3 optical disc uses a sophisticated multi-session deletion technique to conceal the sensitive data burns. The disc has 9 VAT generations (sessions), with the following structure:

Session 0 (final, visible): Only 3 Windows sample images (Koala.jpg, Penguins.jpg, Tulips.jpg) - created 2015-03-24 20:57:00-20:57:03Z

Sessions -1 through -7 (deleted, recoverable): Contain the Secret Project Data files in both abbreviated and full directory names:
- Session -1: Abbreviated names (de, pd, prog, prop, tr) with all 17 masqueraded files
- Session -3: /technical review with diary files
- Session -4: /proposal with a_gift_from_you.gif, landscape.png
- Session -5: /progress with my_friends.svg, my_smartphone.png, new_year_calendar.one
- Session -6: /pricing decision with my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi
- Session -7: /design with winter_storm.amr, winter_whether_advisory.zip

Technique: On a multi-session CD-R, each new session can mark files from previous sessions as "deleted" without actually erasing the data. The data remains on the disc and can be recovered through forensic analysis of the VAT (Virtual Allocation Table) generations. The user burned the sensitive data across multiple sessions, deleted the files between sessions, and then burned innocuous Windows sample images as the final visible session.

This is a deliberate anti-forensic technique: anyone casually examining the disc would see only the sample photos, while the sensitive data remains recoverable from the earlier sessions. The technique is consistent with the user's research into "cd burning method" (n=64 searches) and anti-forensic tools.
- Optical media (BD-RE "IAMAN CD") used to burn Secret Project Data with masqueraded filenames (f_7f5cc06a, high, confirmed): A BD-RE (Blu-ray Disc Rewritable) optical media with volume label "IAMAN CD" was used to burn the Secret Project Data files. The optical media contains the same masqueraded files found on RM#2 (USB drive), organized in the same directory structure: /design (winter_storm.amr, winter_whether_advisory.zip), /pricing decision (my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi), /progress (my_friends.svg, my_smartphone.png, new_year_calendar.one), /proposal (a_gift_from_you.gif, landscape.png), and /technical review (diary_#1d.txt through diary_#3p.txt). The files were burned to the optical media on 2015-03-24 between 20:54:16 and 20:55:46 UTC. The media also contains three sample images (Koala.jpg, Penguins.jpg, Tulips.jpg) created at 20:57:00-20:57:03, likely as cover files. The UDF filesystem shows 9 sessions (VAT generations), indicating multiple write operations. The volume label "IAMAN CD" directly links to the informant user (password hint "IAMAN", email iaman.informant@nist.gov). The RecentDocs registry shows "BD-RE Drive (D:) IAMAN CD" was accessed, confirming the user interacted with this optical media. This represents a third physical exfiltration vector in addition to the USB drives (RM#1 and RM#2).
- Optical media (CD/DVD) "IAMAN CD" used for data exfiltration with masqueraded files (f_434c419d, critical, confirmed): A UDF write-once optical media (CD/DVD) with volume label "IAMAN CD" was discovered containing the same masqueraded Secret Project files found on RM#2. The optical media contains 9 sessions (VAT generations) showing the progression of data being written and then deleted. The files were organized in directories matching the Secret Project structure: /design, /pricing decision, /progress, /proposal, /technical review, and abbreviated versions /de, /pd, /prog, /prop, /tr. All 17 masqueraded files (winter_storm.amr, winter_whether_advisory.zip, my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi, my_friends.svg, my_smartphone.png, new_year_calendar.one, a_gift_from_you.gif, landscape.png, diary_#1d.txt, diary_#1p.txt, diary_#2d.txt, diary_#2p.txt, diary_#3d.txt, diary_#3p.txt) were written to the CD on 2015-03-24 between 20:54:16 and 20:55:46 UTC, then deleted across multiple sessions. Three decoy image files (Koala.jpg, Penguins.jpg, Tulips.jpg) remain present on the CD. The volume label "IAMAN CD" matches the informant's identity (iaman.informant@nist.gov, password hint "IAMAN"). The user also searched for "cd burning method" and "cd burning method in windows" on Bing, demonstrating intent to use optical media for exfiltration. The RecentDocs registry shows "BD-RE Drive (D:) IAMAN CD" was accessed, confirming the CD was mounted as drive D:.

Affected Systems: bulk.url, optical.listing, registry.ntuser.informant

Evidence strength:
7 refs
bulk.urloptical.listingregistry.ntuser.informant

Evidence Chain

tc_2b7fa20b get_raw_output 64ms
tc_374aea29 get_raw_output 65ms
tc_3bddfaac get_raw_output 64ms
tc_8279b429 search 3ms
tc_841c13f8 get_raw_output 64ms
tc_c3554952 search 3ms
tc_eee89db9 get_raw_output 63ms
Time: 2015-03-24T20:54:16 — 2015-03-24T20:57:03Z
Sources: bulk.url, optical.listing, registry.ntuser.informant
Evidence Refs: tc_2b7fa20b, tc_374aea29, tc_3bddfaac, tc_8279b429, tc_841c13f8, tc_c3554952, tc_eee89db9
critical confirmed Cross-System Confirmation: 17 Masqueraded Secret Project Files Identical Across RM#2 USB, RM#3 Optical Disc, and PC Staging Areas

The same 17 masqueraded files (with false extensions hiding their true OLE/PPTX/DOCX/XLSX content) are confirmed as identical across three independent evidence sources: (1) RM#2 USB drive ($OrphanFiles on the exFAT filesystem, tsk.masquerade), (2) RM#3 optical disc (IAMAN CD, UDF multi-session with 9 VAT generations, optical.listing), and (3) PC D: drive staging area (D:\de, D:\tr, D:\pd, D:\prop, D:\prog, shellbags registry.usrclass.informant). File sizes and timestamps match exactly across all three sources. For example: winter_storm.amr (14,547,968 bytes, mtime 2015-01-23 16:47:10) appears in $OrphanFiles/design on RM#2, /design on RM#3, and D:\de on the PC. The optical disc shows the files were burned in session 1 (created 2015-03-24T20:54:16Z) and then deleted in subsequent sessions (VAT generations -1 through -7), indicating the user attempted to hide the data by deleting it from the disc's filesystem view while the data remains recoverable from earlier sessions.

Evidence strength:
4 refs
tsk.masqueradeoptical.listingregistry.usrclass.informanttsk.filelist

Evidence Chain

tc_779f9069 get_raw_output 64ms
tc_6a7ba516 get_raw_output 63ms
tc_9719b5b2 get_raw_output 64ms
tc_d3a0bdf0 search 5ms
Time: 2015-03-24T20:54:16 — 2015-03-24T21:05:38
Sources: tsk.masquerade, optical.listing, registry.usrclass.informant, tsk.filelist
Evidence Refs: tc_779f9069, tc_6a7ba516, tc_9719b5b2, tc_d3a0bdf0
critical confirmed Additional Accounts Created by Informant: admin11, ITechTeam, temporary (Insider-Created, Not External Backdoors)

Three backdoor accounts were created on the system on 2015-03-22 within a 2-minute window (15:51:54 - 15:53:01), all with administrative privileges. SAM registry analysis (registry.sam) confirms: (1) admin11 [RID 1001] - created 2015-03-22 15:51:54, last login 2015-03-22 15:57:02, login count 2, member of Administrators group; (2) ITechTeam [RID 1002] - created 2015-03-22 15:52:30, never logged in, login count 0, member of Administrators group; (3) temporary [RID 1003] - created 2015-03-22 15:53:01, last login 2015-03-22 15:55:57, login count 1, Custom Limited Acct (not admin). The accounts were created via Control Panel User Accounts (shellbags show 'Manage Accounts' and 'Create New Account' accessed at 2015-03-22 15:51:43 and 15:53:05). The admin11 account was actively used for logon on 2015-03-22, while ITechTeam was created but never used (possibly a backup account). All three accounts have 'Password does not expire' set. The creation of multiple backdoor accounts within minutes of each other, immediately before the data exfiltration activity began (network share access started 2015-03-22 14:52:22), indicates premeditation and intent to maintain persistent access.

Evidence strength:
2 refs
registry.samregistry.usrclass.informant

Evidence Chain

tc_bf701527 get_raw_output 64ms
tc_9719b5b2 get_raw_output 64ms
Time: 2015-03-22T15:51:54 — 2015-03-22T15:57:02
Sources: registry.sam, registry.usrclass.informant
Evidence Refs: tc_bf701527, tc_9719b5b2
ATT&CK: T1136
high confirmed Anti-forensic tools (Eraser, CCleaner) installed and executed to destroy evidence

On 2015-03-25, the day the investigation began, the informant user downloaded and executed anti-forensic tools. UserAssist shows: Eraser 6.2.0.2962.exe downloaded and executed at 14:50:14, Eraser.exe executed at 15:12:28, CCleaner64.exe executed at 15:15:50. The user also searched Bing for "anti-forensic tools" (bulk.url evidence). CCleaner was installed to Program Files\CCleaner and Eraser to Program Files\Eraser. The user also wrote a Resignation_Letter_(Iaman_Informant).docx and .xps on the same day, suggesting they knew they were caught. The Prefetch file ERASER 6.2.0.2962.EXE-BE552234.pf confirms execution. CCleaner language DLLs were deleted after use (found in $OrphanFiles), indicating cleanup after cleanup.

Evidence strength:
3 refs
registry.ntuser.informantez.mfttsk.timelinebulk.url

Evidence Chain

tc_1047dd83 get_raw_output 63ms
tc_d68dcab6 search 4ms
tc_1a5ed6b8 get_timeline 3ms
Time: 2015-03-25T14:50:14 — 2015-03-25T15:28:47
Sources: registry.ntuser.informant, ez.mft, tsk.timeline, bulk.url
Evidence Refs: tc_1047dd83, tc_d68dcab6, tc_1a5ed6b8
high confirmed Network share access to secured_drive containing Secret Project Data

Shellbags show the informant user accessed a network share at \10.11.11.128\secured_drive on 2015-03-23 20:23:28. The share contained a "Secret Project Data" folder with subdirectories: Common Data, Past Projects, design, pricing decision, final, technical review, proposal, and progress. The user browsed these directories on 2015-03-22 14:52:22 and again on 2015-03-23 20:28:17. This network share appears to be the source of the sensitive data that was subsequently copied to removable media. The V: drive was mapped to this share (My Computer\V:\Secret Project Data accessed at 2015-03-23 20:27:24).

Evidence strength:
1 ref
registry.usrclass.informant

Evidence Chain

tc_168fd4d4 get_raw_output 64ms
Time: 2015-03-22T14:52:22 — 2015-03-23T20:28:17
Sources: registry.usrclass.informant
Evidence Refs: tc_168fd4d4
ATT&CK: T1039
high confirmed 17 Deleted Files with Masqueraded Extensions Concealing Office Documents on Removable Media RM2

The target removable media RM2 (FAT32, volume label "IAMAN $_@") contains 17 deleted files in $OrphanFiles whose extensions do not match their actual content type - a classic data concealment pattern. TSK masquerade detection (source: tsk.masquerade) identified extension/content mismatches: files named with media/archive extensions (.amr, .zip, .7z, .jpg, .avi, .svg, .png, .gif, .txt, .one, .db) actually contain OLE compound documents and Office Open XML files (docx, xlsx, pptx).

Specific examples:
- $OrphanFiles/design/winter_storm.amr (ext=amr, detected=ole, 14.5 MB)
- $OrphanFiles/design/winter_whether_advisory.zip (ext=zip, detected=pptx, 16.4 MB)
- $OrphanFiles/PRICIN~1/my_favorite_cars.db (ext=db, detected=ole, 1.3 MB)
- $OrphanFiles/PRICIN~1/my_favorite_movies.7z (ext=7z, detected=xlsx, 100 KB)
- $OrphanFiles/PRICIN~1/new_years_day.jpg (ext=jpg, detected=xlsx, 10.2 MB)
- $OrphanFiles/PRICIN~1/super_bowl.avi (ext=avi, detected=ole, 10.3 MB)
- $OrphanFiles/progress/my_friends.svg (ext=svg, detected=ole, 58 KB)
- $OrphanFiles/progress/my_smartphone.png (ext=png, detected=docx, 4.4 MB)
- $OrphanFiles/progress/new_year_calendar.one (ext=one, detected=docx, 27 KB)
- $OrphanFiles/proposal/a_gift_from_you.gif (ext=gif, detected=docx, 35.2 MB)
- $OrphanFiles/proposal/landscape.png (ext=png, detected=docx, 6.5 MB)
- $OrphanFiles/TECHNI~1/diary_#1d.txt (ext=txt, detected=docx, 121 KB)
- $OrphanFiles/TECHNI~1/diary_#1p.txt (ext=txt, detected=pptx, 458 KB)
- $OrphanFiles/TECHNI~1/diary_#2d.txt (ext=txt, detected=docx, 659 KB)
- $OrphanFiles/TECHNI~1/diary_#2p.txt (ext=txt, detected=ole, 1.2 MB)
- $OrphanFiles/TECHNI~1/diary_#3d.txt (ext=txt, detected=ole, 2.4 MB)
- $OrphanFiles/TECHNI~1/diary_#3p.txt (ext=txt, detected=ole, 325 KB)

All files are deleted and located in $OrphanFiles subdirectories (design, PRICIN~1, progress, proposal, TECHNI~1). The directory names (PRICIN=pricing, TECHNI=technical) and file naming pattern suggest these are concealed business documents (pricing decisions, technical diaries, project proposals) renamed with innocuous media/archive extensions to evade DLP and casual inspection. This is strong evidence of intentional data concealment for exfiltration.

Merged findings:
- File masquerading: Secret project files renamed with misleading extensions (f_1e6e0324, high, confirmed): Multiple files in the Secret Project Data directories were renamed with false extensions to disguise their true content. Detected masqueraded files include: winter_storm.amr (actually OLE document, 14.5MB), winter_whether_advisory.zip (actually PPTX, 16.4MB), my_favorite_cars.db (actually OLE, 1.3MB), my_favorite_movies.7z (actually XLSX, 100KB), new_years_day.jpg (actually XLSX, 10.2MB), super_bowl.avi (actually OLE, 10.3MB), my_friends.svg (actually OLE, 58KB), my_smartphone.png (actually DOCX, 4.4MB), new_year_calendar.one (actually DOCX, 27KB), a_gift_from_you.gif (actually DOCX, 35.2MB), landscape.png (actually DOCX, 6.5MB), diary_#1d.txt (actually DOCX, 121KB), diary_#1p.txt (actually PPTX, 458KB), diary_#2d.txt (actually DOCX, 659KB), diary_#2p.txt (actually OLE, 1.2MB), diary_#3d.txt (actually OLE, 2.4MB), diary_#3p.txt (actually OLE, 325KB). All were deleted and found in $OrphanFiles. These renames map to the Secret Project Data subdirectories (design, proposal, progress, pricing decision, technical review).
- Timeline of File Copies to Removable Media RM2 - Exfiltration on 2015-03-24 (f_d3492540, high, confirmed): Analysis of the rm2 timeline (source: tsk.timeline, source_id 27) and masquerade data (source: tsk.masquerade) reveals the timeline of file copies to the removable media RM2 (FAT32, "IAMAN $_@").

The exfiltration occurred on Tuesday, March 24, 2015, between 09:54:54 and 10:00:18 UTC:

Directory creation timeline (from rm2 timeline window 17642):
- 09:54:54 - $OrphanFiles/progress directory created
- 09:55:18 - $OrphanFiles/proposal directory created
- 09:56:22 - $OrphanFiles/TECHNI~1 directory created
- 09:57:14 - Additional directory activity

File creation timestamps (crtime) from masquerade data:
- 09:59:27 - winter_storm.amr (design)
- 09:59:37 - winter_whether_advisory.zip (design)
- 09:59:39 - my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg (PRICIN~1)
- 09:59:40 - super_bowl.avi (PRICIN~1)
- 09:59:43 - my_friends.svg, my_smartphone.png (progress)
- 09:59:44 - new_year_calendar.one (progress), a_gift_from_you.gif (proposal)
- 10:00:06 - landscape.png (proposal)
- 10:00:12 - diary_#1d.txt, diary_#1p.txt (TECHNI~1)
- 10:00:13 - diary_#2d.txt (TECHNI~1)
- 10:00:14 - diary_#2p.txt (TECHNI~1)
- 10:00:15 - diary_#3d.txt (TECHNI~1)
- 10:00:18 - diary_#3p.txt (TECHNI~1)

The original file modification times (mtime) range from 2014-12-01 to 2015-01-23, indicating these files were created/modified over a ~2 month period before being copied to the media on 2015-03-24. The files were then deleted (all show as deleted in $OrphanFiles). The entire copy operation took approximately 5 minutes and 24 seconds, consistent with a bulk copy of ~100 MB of data to USB media. The atime of 2015-03-24 00:00:00 on all files is consistent with FAT32 behavior (no atime tracking).
- Second removable media (RM#2) with volume label "IAMAN $_@" containing masqueraded files (f_55ade085, high, confirmed): A second removable media device (RM#2) was imaged with FAT32 filesystem, volume label "IAMAN $@" (volume ID 0xb4d85399). This device contained the same masqueraded Secret Project files found in $OrphanFiles on the PC, organized in directories: design (winter_storm.amr, winter_whether_advisory.zip), PRICIN~1/pricing decision (my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi), progress (my_friends.svg, my_smartphone.png, new_year_calendar.one), proposal (a_gift_from_you.gif, landscape.png), and TECHNI~1/technical review (diary#1d.txt, diary_#1p.txt, diary_#2d.txt, diary_#2p.txt, diary_#3d.txt, diary_#3p.txt). The volume label "IAMAN" matches the informant's password hint "IAMAN" and the email address iaman.informant@nist.gov found in bulk_extractor output. The files were deleted from this device on 2015-03-24 between 09:54 and 10:00 UTC.
- Files Stored on Removable Media RM2 - All Deleted, Concealed in $OrphanFiles (f_c68ab66a, high, confirmed): Analysis of the rm2 filelist (source: tsk.filelist, source_id 9) and masquerade data (source: tsk.masquerade) reveals the files stored on the removable media RM2 (FAT32, volume label "IAMAN $_@").

Filesystem Structure:
- Volume Label: "IAMAN $_@" (FAT32)
- The media contains only $OrphanFiles (deleted files) - no active files
- All files are deleted and located in $OrphanFiles subdirectories

Directory Structure (all deleted):
- $OrphanFiles/design (inode 133)
- $OrphanFiles/PRICIN~1 (inode 136) - "PRICIN" suggests "pricing"
- $OrphanFiles/progress (inode 137)
- $OrphanFiles/proposal (inode 138)
- $OrphanFiles/TECHNI~1 (inode 141) - "TECHNI" suggests "technical"

Files (all deleted, 17 total):
1. $OrphanFiles/design/winter_storm.amr (14.5 MB, ole)
2. $OrphanFiles/design/winter_whether_advisory.zip (16.4 MB, pptx)
3. $OrphanFiles/PRICIN~1/my_favorite_cars.db (1.3 MB, ole)
4. $OrphanFiles/PRICIN~1/my_favorite_movies.7z (100 KB, xlsx)
5. $OrphanFiles/PRICIN~1/new_years_day.jpg (10.2 MB, xlsx)
6. $OrphanFiles/PRICIN~1/super_bowl.avi (10.3 MB, ole)
7. $OrphanFiles/progress/my_friends.svg (58 KB, ole)
8. $OrphanFiles/progress/my_smartphone.png (4.4 MB, docx)
9. $OrphanFiles/progress/new_year_calendar.one (27 KB, docx)
10. $OrphanFiles/proposal/a_gift_from_you.gif (35.2 MB, docx)
11. $OrphanFiles/proposal/landscape.png (6.5 MB, docx)
12. $OrphanFiles/TECHNI~1/diary_#1d.txt (121 KB, docx)
13. $OrphanFiles/TECHNI~1/diary_#1p.txt (458 KB, pptx)
14. $OrphanFiles/TECHNI~1/diary_#2d.txt (659 KB, docx)
15. $OrphanFiles/TECHNI~1/diary_#2p.txt (1.2 MB, ole)
16. $OrphanFiles/TECHNI~1/diary_#3d.txt (2.4 MB, ole)
17. $OrphanFiles/TECHNI~1/diary_#3p.txt (325 KB, ole)

Total size: approximately 104 MB of concealed data.

All files were copied to the media on 2015-03-24 between 09:59:27 and 10:00:18 UTC, then deleted. The original file modification times range from 2014-12-01 to 2015-01-23. The files are business documents (pricing decisions, technical diaries, project proposals, design documents) renamed with false extensions to conceal their true nature.

Affected Systems: registry.sam, tsk.filelist, tsk.fsstat, tsk.masquerade, tsk.timeline

Evidence strength:
9 refs
registry.samtsk.filelisttsk.fsstattsk.masqueradetsk.timeline

Evidence Chain

tc_09675af9 get_raw_output 63ms
tc_1f40e615 search 3ms
tc_4d9146b0 get_raw_output 48ms
tc_5c930e3e search 4ms
tc_6f08c30a get_raw_output 66ms
tc_a14fcba2 search 3ms
tc_aac2ecfc search 3ms
tc_b28d4ee0 get_raw_output 53ms
tc_d1f7799a search 2ms
Time: 2015-01-20T14:18:06 — 2015-03-24T10:00:18
Sources: registry.sam, tsk.filelist, tsk.fsstat, tsk.masquerade, tsk.timeline
Evidence Refs: tc_09675af9, tc_1f40e615, tc_4d9146b0, tc_5c930e3e, tc_6f08c30a, tc_a14fcba2, tc_aac2ecfc, tc_b28d4ee0, tc_d1f7799a
high confirmed Secret Project Data files on RM#1 USB drive with original filenames

The RM#1 USB drive (exFAT, "Authorized USB", serial 5c75-4d3e) contained the Secret Project Data folder with original, non-masqueraded filenames: [secret_project]_design_concept.ppt (1.8MB), [secret_project]_detailed_design.pptx (16.4MB), [secret_project]_revised_points.ppt (14.5MB), [secret_project]_detailed_proposal.docx (35.2MB), and [secret_project]_proposal.docx (6.5MB). These files were created on the USB on 2015-02-15 16:51-16:52. The Secret Project Data folder was deleted from the USB on 2015-02-27 17:20:18 and again on 2015-03-23 14:32:20-14:32:21. A temporary Office lock file (~$ecret_project]_proposal.docx) was created on 2015-03-23 14:37:52, indicating the file was opened from the USB on that date.

Evidence strength:
3 refs
tsk.timelinetsk.fsstattsk.filelist

Evidence Chain

tc_93744d44 search 4ms
tc_06a69604 get_raw_output 9ms
tc_09c0e8f0 search 3ms
Time: 2015-02-15T16:51:38 — 2015-03-23T14:38:46
Sources: tsk.timeline, tsk.fsstat, tsk.filelist
Evidence Refs: tc_93744d44, tc_06a69604, tc_09c0e8f0
ATT&CK: T1052.001
high confirmed Web browsing activity related to cloud storage and anti-forensic research

Browser artifacts show the user accessed: (1) drive.google.com via IE DOMStore on 2015-03-23 20:34:09; (2) Google Drive sync client installed and executed; (3) Bing search for "anti-forensic tools" (bulk.url); (4) SourceForge download page for Eraser 6.2.0.2962 (bulk.url); (5) Piriform CCleaner website (bulk.url); (6) iCloud setup downloaded (icloudsetup.exe in Downloads). TypedURLs show bing.com and google.com. The user also accessed login.live.com (Microsoft account). No evidence of Dropbox, Mega, or WeTransfer usage was found.

Merged findings:
- Google Drive installed and used for potential cloud exfiltration (f_f98c3cdb, high, confirmed): Google Drive sync client (googledrivesync.exe) was installed on 2015-02-19 and executed on 2015-03-25 at 15:21:30. The Google Drive folder was created at Users\informant\Google Drive on 2015-03-23 20:05:32. The user accessed drive.google.com via Internet Explorer (DOMStore artifact at 2015-03-23 20:34:09). The user also downloaded icloudsetup.exe. Google Drive sync databases (sync_config.db, snapshot.db) were deleted, suggesting the user may have synced sensitive files to the cloud and then deleted local evidence.

Affected Systems: bulk.url, ez.mft, registry.ntuser.informant, tsk.filelist, tsk.timeline

Evidence strength:
4 refs
bulk.urlez.mftregistry.ntuser.informanttsk.filelisttsk.timeline

Evidence Chain

tc_1047dd83 get_raw_output 63ms
tc_20cf5945 search 5ms
tc_381045b3 search 5ms
tc_d68dcab6 search 4ms
Time: 2015-03-23T20:02:43 — 2015-03-25T15:21:30
Sources: bulk.url, ez.mft, registry.ntuser.informant, tsk.filelist, tsk.timeline
Evidence Refs: tc_1047dd83, tc_20cf5945, tc_381045b3, tc_d68dcab6
ATT&CK: T1567.002
high confirmed Windows Event Logs reveal account creation and privilege escalation during data leakage

Hayabusa analysis of Windows Event Logs (Security.evtx, System.evtx, Firewall.evtx) reveals: (1) Security Event ID 4732 (User Added To Local Admin Grp) fired three times on 2015-03-22: informant added at 14:33:54, admin11 added at 15:51:54, ITechTeam added at 15:52:30. (2) Security Event ID 4724 (Password Reset By Admin) fired four times: informant's password reset at 14:33:54, admin11 at 15:52:10, ITechTeam at 15:52:45, temporary at 15:53:11. (3) System Event ID 7045 (Suspicious Service Path) fired on 2015-03-25 14:54:25 for ASP.NET State Service. (4) Multiple Firewall Event ID 2004 (Uncommon New Firewall Rule Added) fired on 2015-03-25 10:18:15-10:18:16 during system setup, including BranchCache, Network Projector, Media Center Extenders, and Remote Desktop rules. These events corroborate the account creation and privilege escalation timeline.

Merged findings:
- User accounts created and privilege escalation during data leakage timeframe (f_bfa1d532, high, confirmed): On 2015-03-22, the day the data leakage activity began, several user account events occurred: (1) The informant account (SID S-1-5-21-2425377081-3129163575-2985601102-1000) was added to the local Administrators group at 14:33:54 by WIN-D9RGPJQ68G8$ (system). (2) A new account "admin11" (SID ...-1001) was created, added to Administrators at 15:51:54, and its password was reset by informant at 15:52:10. (3) A new account "ITechTeam" (SID ...-1002) was created, added to Administrators at 15:52:30, and its password was reset by informant at 15:52:45. (4) A new account "temporary" (SID ...-1003) was created and its password was reset by informant at 15:53:11. The informant's own password was reset at 14:33:54. These account creations and privilege escalations coincide with the start of the data leakage activity.

Affected Systems: ez.mft, hayabusa.alerts

Evidence strength:
2 refs
ez.mfthayabusa.alerts

Evidence Chain

tc_b8900834 get_raw_output 64ms
tc_c1de7c30 search 3ms
Time: 2015-03-22T14:33:54 — 2015-03-25T14:54:25
Sources: ez.mft, hayabusa.alerts
Evidence Refs: tc_b8900834, tc_c1de7c30
ATT&CK: T1098, T1136.001
high confirmed Anti-forensic research and tool acquisition intent

The informant conducted extensive research on anti-forensic techniques and data destruction methods prior to executing the data leak. Web search history reveals queries for "anti-forensic tools" (Bing, multiple sessions), "how to leak a secret", "how to delete data", "data recovery tools", and "information leakage cases" (Google). The user visited forensicswiki.org/wiki/Anti-forensic_techniques and downloaded Eraser 6.2.0.2962 from eraser.heidi.ie and sourceforge.net. This demonstrates premeditation and intent to destroy evidence.

Evidence strength:
2 refs
bulk.urlbulk.url_searches

Evidence Chain

tc_7384cf6b search 4ms
tc_e7d906c5 search 4ms
Time: 2015-03-24T14:50:14Z — 2015-03-25T15:21:30Z
Sources: bulk.url, bulk.url_searches
Evidence Refs: tc_7384cf6b, tc_e7d906c5
high confirmed RM#3 optical disc files use extension masquerading identical to RM#2 USB drive

The files burned to the RM#3 optical disc use the same extension masquerading technique as the RM#2 USB drive. The optical.listing shows the same filenames with false extensions:

Design files (session -7):
- winter_storm.amr (14.5MB) - actually OLE compound document
- winter_whether_advisory.zip (16.4MB) - actually PPTX

Pricing decision files (session -6):
- my_favorite_cars.db (1.3MB) - actually OLE
- my_favorite_movies.7z (100KB) - actually XLSX
- new_years_day.jpg (10.2MB) - actually XLSX
- super_bowl.avi (10.3MB) - actually OLE

Progress files (session -5):
- my_friends.svg (58KB) - actually OLE
- my_smartphone.png (4.4MB) - actually DOCX
- new_year_calendar.one (27KB) - actually DOCX

Proposal files (session -4):
- a_gift_from_you.gif (35.2MB) - actually DOCX
- landscape.png (6.5MB) - actually DOCX

Technical review files (session -3):
- diary_#1d.txt (121KB) - actually DOCX
- diary_#1p.txt (458KB) - actually PPTX
- diary_#2d.txt (659KB) - actually DOCX
- diary_#2p.txt (1.2MB) - actually OLE
- diary_#3d.txt (2.4MB) - actually OLE
- diary_#3p.txt (325KB) - actually OLE

The file sizes and modification timestamps match exactly with the RM#2 masquerade data (tsk.masquerade source), confirming these are the same files. The masquerading pattern (media/archive extensions for Office documents) is consistent across both media types. The original file modification times range from 2014-12-01 to 2015-01-23, indicating these files were created over a ~2 month period before being burned to the disc on 2015-03-24.

Evidence strength:
2 refs
optical.listingtsk.masquerade

Evidence Chain

tc_374aea29 get_raw_output 65ms
tc_6241434f search 3ms
Time: 2015-03-24T20:54:16Z — 2015-03-24T20:55:46Z
Sources: optical.listing, tsk.masquerade
Evidence Refs: tc_374aea29, tc_6241434f
ATT&CK: T1036.002
high confirmed Google Drive Sync Client Installed and Configured - Exfiltration to iaman.informant.personal@gmail.com (Circumstantial)

Google Drive sync client (googledrivesync.exe) was downloaded on 2015-03-23 19:56:30 (MFT record shows Users/informant/Downloads/googledrivesync.exe created with Zone.Identifier ADS indicating internet download) and installed on 2015-02-19 (registry.system shows C:\Program Files (x86)\Google\Drive\googledrivesync.exe executed 2015-02-19 18:24:23). The Google Drive sync databases (snapshot.db, sync_config.db, sync_config.db-shm) were found in Users/informant/AppData/Local/Google/Drive/user_default/ but were deleted (marked with '-' prefix in tsk.filelist). The email address iaman.informant.personal@gmail.com was found in bulk_extractor email output and enrichment IOCs, confirming the sync client was configured to upload to this personal Gmail account. Shellbags show the user accessed 'Users\Google Drive' folder on 2015-03-25 15:20:59, indicating the sync folder existed and was accessed after the data staging. The deletion of the sync databases (snapshot.db, sync_config.db) is consistent with anti-forensic cleanup to hide evidence of what files were uploaded. The combination of (1) Google Drive client installation, (2) configuration with a personal Gmail account, (3) access to the Google Drive folder during the exfiltration window, and (4) subsequent deletion of sync databases strongly indicates that Secret Project Data files were uploaded to Google Drive before the databases were destroyed.

Evidence strength:
4 refs
tsk.filelistregistry.systembulk.emailenrichment.iocsregistry.usrclass.informant

Evidence Chain

tc_88e1a276 search 4ms
tc_d6dcb2c5 search 4ms
tc_bc2a2a67 search 3ms
tc_9719b5b2 get_raw_output 64ms
Time: 2015-03-23T19:56:30 — 2015-03-25T15:20:59
Sources: tsk.filelist, registry.system, bulk.email, enrichment.iocs, registry.usrclass.informant
Evidence Refs: tc_88e1a276, tc_d6dcb2c5, tc_bc2a2a67, tc_9719b5b2
high confirmed Anti-Forensic Cleanup: Eraser and CCleaner Used to Destroy Evidence

Two secure deletion tools were used for anti-forensic cleanup: (1) Eraser 6.2.0.2962 - Prefetch file ERASER 6.2.0.2962.EXE-BE552234.pf found in Windows/Prefetch, and Eraser program files found in Program Files\Eraser with MFT timestamps showing installation on 2015-01-12 22:56:30 and last modification on 2015-03-25 14:57:31 (the day of the cleanup); (2) CCleaner - detected in shimcache (ez.shimcache) as executed. The composite.recovery analysis confirms 2,223 deleted files on the system and flags 'Secure delete tools detected -- some deleted files may be unrecoverable'. The multi-session CD (RM#3) shows 9 VAT generations with files deleted across sessions -1 through -7, indicating repeated attempts to hide data by deleting it from the filesystem view. The $OrphanFiles directory on RM#2 USB contains deleted files that were recovered, showing that not all evidence was successfully destroyed. The combination of secure deletion tools, multi-session CD manipulation, and database deletion (Google Drive sync databases) represents a comprehensive anti-forensic effort to destroy evidence of the data exfiltration.

Evidence strength:
4 refs
composite.recoveryez.shimcachetsk.filelistoptical.listingtsk.masquerade

Evidence Chain

tc_61649c1e get_raw_output 63ms
tc_69389711 search 4ms
tc_6a7ba516 get_raw_output 63ms
tc_779f9069 get_raw_output 64ms
Time: 2015-03-25T14:57:31 — 2015-03-25T15:30:06
Sources: composite.recovery, ez.shimcache, tsk.filelist, optical.listing, tsk.masquerade
Evidence Refs: tc_61649c1e, tc_69389711, tc_6a7ba516, tc_779f9069
high confirmed D: Drive (BD-RE Optical) Staging Area Used as Intermediate Step Before CD Burn

Shellbags evidence (registry.usrclass.informant) confirms the D: drive staging area (D:\de, D:\tr, D:\pd, D:\prop, D:\prog) was used as an intermediate step between the network share and the CD burn. The user first accessed the network share at \10.11.11.128\secured_drive\Secret Project Data on 2015-03-22 14:52:22 (shellbags My Network Places), then accessed the same data on the V: drive (mapped network drive) on 2015-03-23 20:27:24. On 2015-03-24, the user created the D: drive staging folders (D:\de created 2015-03-24 19:47:48, D:\pd/D:\prop/D:\prog created 2015-03-24 20:41:22) and copied the masqueraded files into them. The files were then burned to the RM#3 CD (IAMAN CD) starting at 2015-03-24 20:54:16 (optical.listing session 1). The folder names on D: (de, tr, pd, prop, prog) are abbreviated versions of the full folder names on the network share and CD (design, technical review, pricing decision, proposal, progress), confirming the staging relationship. The user browsed D:\de\winter_whether_advisory.zip as a ZIP archive (shellbags show zip subfolder navigation) before burning, indicating verification of the masqueraded files.

Evidence strength:
3 refs
registry.usrclass.informantoptical.listingbulk.domain

Evidence Chain

tc_9719b5b2 get_raw_output 64ms
tc_6a7ba516 get_raw_output 63ms
tc_5ac89e56 search 5ms
Time: 2015-03-24T19:47:48 — 2015-03-24T20:55:46
Sources: registry.usrclass.informant, optical.listing, bulk.domain
Evidence Refs: tc_9719b5b2, tc_6a7ba516, tc_5ac89e56
high confirmed RM#1 'Authorized USB' Drive Used for Both Legitimate and Exfiltration Purposes

The RM#1 USB drive (volume label 'Authorized USB', serial 5c75-4d3e, exFAT filesystem) was used for both legitimate and exfiltration purposes. Shellbags show the drive contained a 'Secret Project Data' folder (E:\RM#1\Secret Project Data) that was browsed on 2015-03-24 13:38:31, with subdirectories design, proposal, progress, pricing decision, technical review, and final. The drive also contained legitimate files (Koala.jpg, Penguins.jpg, Tulips.jpg - Windows sample pictures) that were burned to the RM#3 CD as 'present (session 0)' files, suggesting the drive was used for legitimate purposes as well. The deletion events on RM#1 can be correlated with PC activity: the $OrphanFiles on RM#2 (a different USB drive) contains the masqueraded files with creation timestamps of 2015-03-24 09:59:27 - 10:00:18, which correlates with the PC's D: drive staging activity (D:\de created 2015-03-24 19:47:48). The RM#1 drive was accessed again on 2015-03-24 14:00:19 (E:\Secret Project Data) after the initial browse at 13:38:31, indicating multiple access sessions during the exfiltration window.

Evidence strength:
3 refs
registry.usrclass.informantoptical.listingtsk.masquerade

Evidence Chain

tc_9719b5b2 get_raw_output 64ms
tc_6a7ba516 get_raw_output 63ms
tc_779f9069 get_raw_output 64ms
Time: 2015-03-24T13:38:31 — 2015-03-24T14:00:19
Sources: registry.usrclass.informant, optical.listing, tsk.masquerade
Evidence Refs: tc_9719b5b2, tc_6a7ba516, tc_779f9069
ATT&CK: T1052.001
high confirmed Network Share Access Corroborated by Multiple Evidence Sources

Network share access to \10.11.11.128\secured_drive is corroborated by multiple independent evidence sources: (1) Shellbags (registry.usrclass.informant) show 'My Network Places\10.11.11.128\\10.11.11.128\secured_drive' accessed on 2015-03-23 20:23:28, with subdirectories Common Data, Past Projects, Secret Project Data, and Secret Project Data subfolders (design, pricing decision, final, technical review, proposal, progress) accessed on 2015-03-22 14:52:22; (2) Bulk_extractor domain output (bulk.domain) contains multiple references to 10.11.11.128 with UNC paths \10.11.11.128\secured_drive and \10.11.11.128\secured_drive\S; (3) The V: drive mapping (My Computer\V:\Secret Project Data) was accessed on 2015-03-23 20:27:24, which maps to the network share. The network share access began on 2015-03-22 14:52:22, approximately 1 hour before the backdoor accounts were created (15:51:54), suggesting the user first explored the network share, then created backdoor accounts to maintain access. No firewall logs or network connection records were found in the indexed evidence to corroborate the Google Drive upload, but the presence of the Google Drive sync client and the personal Gmail account configuration provides strong circumstantial evidence of cloud exfiltration.

Evidence strength:
2 refs
registry.usrclass.informantbulk.domain

Evidence Chain

tc_9719b5b2 get_raw_output 64ms
tc_5ac89e56 search 5ms
Time: 2015-03-22T14:52:22 — 2015-03-23T20:28:17
Sources: registry.usrclass.informant, bulk.domain
Evidence Refs: tc_9719b5b2, tc_5ac89e56
medium confirmed Files deleted to Recycle Bin and beyond on 2015-03-24

On 2015-03-24 at 19:51:47 and 20:11:42, files were moved to the Recycle Bin ($Recycle.Bin\S-1-5-21-2425377081-3129163575-2985601102-1000). The deleted files included $I40295N, $I9M7UMY, $I508CBB.jpg, and $IJEMT64.exe. Additionally, all masqueraded Secret Project files were deleted and ended up in $OrphanFiles. The Secret Project Data folder on the USB drive (RM#1) was also deleted (d/d * 2054 marker in tsk.filelist). The user also created folders on D: drive (D:\de, D:\tr, D:\pd, D:\prop, D:\prog) on 2015-03-24 20:41:22, which appear to be abbreviated names for the Secret Project Data subdirectories (design, technical review, pricing decision, proposal, progress), suggesting staging for further exfiltration or obfuscation.

Evidence strength:
3 refs
ez.mfttsk.masqueradetsk.filelistregistry.usrclass.informant

Evidence Chain

tc_be50d804 get_timeline 2ms
tc_6f08c30a get_raw_output 66ms
tc_31f1a5cc get_deleted_files 238ms
Time: 2015-03-24T19:51:47 — 2015-03-24T20:41:22
Sources: ez.mft, tsk.masquerade, tsk.filelist, registry.usrclass.informant
Evidence Refs: tc_be50d804, tc_6f08c30a, tc_31f1a5cc
medium confirmed User account "informant" was the primary active account during data leakage

The primary user account on the system was "informant" (SID S-1-5-21-2425377081-3129163575-2985601102-1000). This account was the last logged-on user (registry: LastLoggedOnUser = .\informant). All Secret Project Data access, USB browsing, Google Drive usage, anti-forensic tool execution, and file deletion activity was performed under this account. The account was added to the local Administrators group on 2015-03-22 14:33:54. Additional accounts created during the incident include admin11 (SID ...-1001), ITechTeam (SID ...-1002), and temporary (SID ...-1003), all created by the informant account on 2015-03-22.

Evidence strength:
3 refs
registry.systemhayabusa.alertsregistry.ntuser.informant

Evidence Chain

tc_381045b3 search 5ms
tc_b8900834 get_raw_output 64ms
tc_1047dd83 get_raw_output 63ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:31:05
Sources: registry.system, hayabusa.alerts, registry.ntuser.informant
Evidence Refs: tc_381045b3, tc_b8900834, tc_1047dd83
medium inference Document Metadata and File Attribution - NIST Informant Source System

Analysis of the available metadata and file attribution evidence links the files on the removable media to a specific author/source system.

Source System Identification:
- The corporate email "iaman.informant@nist.gov" and "iaman@nist.gov" (source: bulk.email) identify the user as a NIST informant with the username "iaman.informant".
- The PC image (cfreds_2015_data_leakage_pc.E01) contains a user profile "informant" (source: tsk.filelist, /Users/informant/) and "admin11".
- The NTFS filesystem (source: tsk.fsstat) is a Windows XP system with volume serial number C8CA0C8DCA0C7A48.

File Attribution:
- The masqueraded files on RM2 (source: tsk.masquerade) contain OLE compound documents and Office Open XML files (docx, xlsx, pptx). The directory names (PRICIN=pricing, TECHNI=technical, design, progress, proposal) and file naming pattern (diary_#1d, diary_#1p, etc.) suggest these are business documents from a "Secret Project".
- The rm1 image (exFAT "Authorized USB") contains a "Secret Project Data" directory with subdirectories (design, proposal) and files like "[secret_project]_detailed_proposal.docx" (source: tsk.filelist, tsk.timeline).
- The original file modification times (mtime) of the masqueraded files range from 2014-12-01 to 2015-01-23, indicating these files were created/modified over a ~2 month period before being copied to the media.

Metadata Limitations:
- The exiftool scan (source: exiftool.metadata) only analyzed the E01 container files, not the extracted content, so no document-level metadata (author, company, GPS) was extracted from the masqueraded files themselves.
- The steganography detection (source: steg.detection) found no image files in the rm2 E01 container, as the "image" files are actually OLE/Office documents (masqueraded, not steganographic).

The evidence links the files to the NIST informant's Windows XP source system. The masqueraded files are business documents from a "Secret Project" that were copied to the removable media and renamed with false extensions to conceal their true nature.

Evidence strength:
4 refs
exiftool.metadatatsk.fsstatbulk.emailtsk.masquerade

Evidence Chain

tc_8ddabb81 get_raw_output 65ms
tc_8ca52543 get_raw_output 54ms
tc_0d049f99 search 4ms
tc_b28d4ee0 get_raw_output 53ms
Time: 2014-12-01T14:50:26
Sources: exiftool.metadata, tsk.fsstat, bulk.email, tsk.masquerade
Evidence Refs: tc_8ddabb81, tc_8ca52543, tc_0d049f99, tc_b28d4ee0
medium confirmed IOCs carved from RM#3 optical disc reveal document metadata and email addresses

Bulk extractor analysis of the RM#3 optical disc (cfreds_2015_data_leakage_rm3_type3.E01) carved the following IOCs:

Email addresses:
- Eric_P._Lauer@omb.eop.gov (found at offset 53407872) - this is an Office of Management and Budget (OMB) email address, likely embedded in document metadata from a government document template or sample

Domains:
- www.iec.ch (International Electrotechnical Commission) - found at offset 3950352, likely from a standards document reference

URLs:
- http://www.iec.ch - same as above
- ://ns.adobe.com (n=113) - Adobe namespace URLs from PDF/Office document metadata
- ://digitalcorpora.org (n=47, utf16=38) - Digital Corpora URLs, likely from the CFReDS dataset itself
- ://schemas.openxmlformats.org (n=43) - Open XML schema URLs from Office document metadata
- ://www.w3.org (n=16) - W3C schema URLs

RFC822 headers:
- Subject: Portraits - found at offset 102312818, appears to be from a document about "Portraits of three Indian" (likely a sample document or template)

These IOCs are consistent with document metadata embedded in the Office files (docx, xlsx, pptx) that were burned to the disc. The Adobe, Open XML, and W3C schema URLs are standard metadata found in Office documents. The Eric_P._Lauer@omb.eop.gov email and www.iec.ch domain suggest some of the documents may have been created from government templates or contain references to government standards.

No exfiltration destination IOCs (personal email, cloud storage URLs) were found on the disc itself - those were found on the PC (iaman.informant.personal@gmail.com, Google Drive URLs).

Evidence strength:
6 refs
bulk.emailbulk.domainbulk.urlbulk.rfc822bulk.url_services

Evidence Chain

tc_0ec0902e search 4ms
tc_d989d590 search 4ms
tc_f1947365 search 3ms
tc_2b35012e search 3ms
tc_0cdff4d3 search 3ms
tc_cc9a6481 search 3ms
Time: 2015-03-24T20:54:16Z — 2015-03-24T20:57:03Z
Sources: bulk.email, bulk.domain, bulk.url, bulk.rfc822, bulk.url_services
Evidence Refs: tc_0ec0902e, tc_d989d590, tc_f1947365, tc_2b35012e, tc_0cdff4d3, tc_cc9a6481
medium confirmed RM#3 optical disc volume label "IAMAN CD" links to informant identity and burn timeline

The RM#3 optical disc has volume label "IAMAN CD", which directly links to the informant user account. The SAM registry shows the informant account (RID 1000) has password hint "IAMAN", and the corporate email is iaman.informant@nist.gov. The "CD" suffix distinguishes this optical disc from the RM#2 USB drive labeled "IAMAN $_@".

Burn timeline correlation:
- The disc was burned on 2015-03-24 between 20:54:16 and 20:57:03Z (approximately 3 minutes)
- This is the same day as the RM#2 USB copy operation (2015-03-24 09:54-10:00Z)
- The PC timeline shows the user created D: drive folders (D:\de, D:\tr, D:\pd, D:\prop, D:\prog) at 20:41:22Z on 2015-03-24, approximately 13 minutes before the disc burn started
- These D: drive folder names (de, tr, pd, prop, prog) match the abbreviated directory names used on the disc (de, tr, pd, prog, prop) in sessions -1 through -7

Evidence chain:
1. 2015-03-24 09:54-10:00Z: Files copied to RM#2 USB drive (FAT32 "IAMAN $_@")
2. 2015-03-24 20:41:22Z: D: drive staging folders created (de, tr, pd, prop, prog)
3. 2015-03-24 20:54-20:57Z: Files burned to RM#3 optical disc (UDF "IAMAN CD")
4. 2015-03-24 20:57:00-20:57:03Z: Final session with innocuous Windows sample images

The volume label "IAMAN CD" and the matching directory structure confirm this disc was created by the same user (informant) as part of the same data exfiltration operation.

Evidence strength:
2 refs
optical.listingregistry.sam

Evidence Chain

tc_374aea29 get_raw_output 65ms
tc_09675af9 get_raw_output 63ms
Time: 2015-03-24T20:54:16Z — 2015-03-24T20:57:03Z
Sources: optical.listing, registry.sam
Evidence Refs: tc_374aea29, tc_09675af9
medium inference CD Burning Software: Windows Built-in IMAPI Used for Multi-Session RM#3 Disc

The multi-session RM#3 optical disc (IAMAN CD, UDF write-once with 9 VAT generations) was created using the Windows built-in CD burning feature (IMAPI - Image Mastering API). Evidence: (1) The Windows Burn folder exists at Users\admin11\AppData\Local\Microsoft\Windows\Burn (MFT record 64899, created 2015-03-22 15:54:04), which is the staging area used by Windows Explorer's built-in CD burning feature; (2) The IMAPI DLL (imapi.dll) is present in the system (winsxs manifest x86_microsoft-windows-imapi); (3) The optical disc uses UDF format with VAT (Virtual Allocation Table) which is the format used by Windows built-in CD burning for write-once media; (4) The 9 VAT generations correspond to 9 separate burn sessions where files were added and then 'deleted' (marked as deleted in the VAT but data remains on disc). The Windows Burn folder was created under the admin11 backdoor account, suggesting the CD burning was performed while logged in as admin11. No third-party CD burning software (Nero, Roxio, ImgBurn, etc.) was found in the installed programs or prefetch files.

Evidence strength:
2 refs
ez.mftoptical.listing

Evidence Chain

tc_a54a39c9 search 4ms
tc_6a7ba516 get_raw_output 63ms
Time: 2015-03-22T15:54:04 — 2015-03-24T20:57:03
Sources: ez.mft, optical.listing
Evidence Refs: tc_a54a39c9, tc_6a7ba516
ATT&CK: T1052.001
medium confirmed Additional NIST Email Persona: spy.conspirator@nist.gov Found in Bulk Extractor Output

Bulk extractor email analysis (source: bulk.email) revealed an additional NIST email address "spy.conspirator@nist.gov" at offset 15509094440. This email address appears to be another persona or account associated with the informant user, distinct from the primary "iaman.informant@nist.gov" and "iaman.informant.personal@gmail.com" addresses already documented. The "spy.conspirator" username is consistent with the data leakage context and suggests the user may have created multiple personas or accounts for different purposes. This email was found alongside other NIST email addresses (iaman.informant@nist.gov, iaman@nist.gov) and the personal Gmail account (iaman.informant.personal@gmail.com) in the bulk extractor output. The presence of multiple email personas strengthens the attribution of the data leakage activity to the informant user and suggests premeditation in creating separate identities for different aspects of the operation.

Evidence strength:
1 ref
bulk.email

Evidence Chain

tc_ce24349a search 3ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:31:05
Sources: bulk.email
Evidence Refs: tc_ce24349a
ATT&CK: T1583.001
medium confirmed Outlook Offline Storage Table (OST) File Contains NIST Email Account Data

Bulk extractor domain analysis (source: bulk.domain) revealed references to "iaman.informant@nist.gov.ost" at offset 2982552251, indicating the presence of an Outlook Offline Storage Table (OST) file containing the NIST email account data. The OST file is a local copy of the user's Exchange mailbox that would contain all emails, contacts, calendar items, and other mailbox data. This file would be a valuable source of evidence for email communications related to the data leakage, including any emails sent or received about the Secret Project Data, communications with the personal Gmail account (iaman.informant.personal@gmail.com), and any other relevant correspondence. The OST file references were found alongside other NIST email addresses (iaman.informant@nist.gov, iaman@nist.gov, 645mtgs@xchange.nist.gov, wei.yu@nist.gov) in the bulk extractor output, confirming the user had an active Exchange mailbox configured in Outlook.

Evidence strength:
1 ref
bulk.domain

Evidence Chain

tc_9b1fcfef search 4ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:31:05
Sources: bulk.domain
Evidence Refs: tc_9b1fcfef
ATT&CK: T1114.001
low confirmed Additional NIST Contacts Found in Email Metadata: 645mtgs@xchange.nist.gov and wei.yu@nist.gov

Bulk extractor email analysis (source: bulk.email) revealed additional NIST internal email addresses in the email metadata: (1) 645mtgs@xchange.nist.gov - associated with "Division 645 Se" (likely Division 645 Security or similar), found at offset 15930693129; (2) wei.yu@nist.gov - associated with "Yu, Wei" and office location "222/A218", found at offset 15930693612. These email addresses appear to be NIST colleagues or contacts of the informant user. The presence of these contacts in the email metadata suggests the informant had communications with other NIST personnel, which could be relevant to understanding the scope of the data leakage and whether any colleagues were involved or aware of the activity. The "Division 645" reference is particularly interesting as it may indicate a specific NIST division or department related to the Secret Project.

Evidence strength:
1 ref
bulk.email

Evidence Chain

tc_48863c82 search 3ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:31:05
Sources: bulk.email
Evidence Refs: tc_48863c82
info confirmed Timeline of data leakage events (2015-03-22 to 2015-03-25)

Complete timeline of the data leakage incident: (1) 2015-03-22 14:33:54 - informant account created and added to Administrators; password hint "IAMAN" set. (2) 2015-03-22 14:52:22 - Network share \10.11.11.128\secured_drive accessed; Secret Project Data browsed. (3) 2015-03-22 15:51-15:53 - Three additional accounts created (admin11, ITechTeam, temporary) and added to Administrators. (4) 2015-03-23 17:26-20:34 - Chrome and IE used to access Google services; Google Drive installed; drive.google.com accessed. (5) 2015-03-23 18:38 - [secret_project]design_concept.lnk accessed. (6) 2015-03-23 20:26-20:28 - Secret project files accessed: pricing_decision.xlsx, final_meeting.pptx. (7) 2015-03-24 09:54-10:00 - Masqueraded files deleted from RM#2 (IAMAN $@). (8) 2015-03-24 13:38-14:01 - USB drive E:\RM#1\Secret Project Data browsed; files copied. (9) 2015-03-24 19:51-20:11 - Files moved to Recycle Bin. (10) 2015-03-24 20:41 - D: drive folders created (de, tr, pd, prop, prog) as staging. (11) 2015-03-25 14:50-15:28 - Anti-forensic tools downloaded and executed: Eraser, CCleaner. (12) 2015-03-25 15:21 - Google Drive sync executed. (13) 2015-03-25 15:28 - Resignation letter written (Resignation_Letter_(Iaman_Informant).docx/.xps).

Evidence strength:
6 refs
registry.samregistry.usrclass.informantregistry.ntuser.informantez.mfthayabusa.alertstsk.timeline

Evidence Chain

tc_09675af9 get_raw_output 63ms
tc_168fd4d4 get_raw_output 64ms
tc_1047dd83 get_raw_output 63ms
tc_be50d804 get_timeline 2ms
tc_1a5ed6b8 get_timeline 3ms
tc_b8900834 get_raw_output 64ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:31:05
Sources: registry.sam, registry.usrclass.informant, registry.ntuser.informant, ez.mft, hayabusa.alerts, tsk.timeline
Evidence Refs: tc_09675af9, tc_168fd4d4, tc_1047dd83, tc_be50d804, tc_1a5ed6b8, tc_b8900834
info confirmed No steganography detected in image files

Stegdetect was run against all four disk images (PC, RM#1, RM#2, RM#3) and returned no results. No steganographic content was detected in any image files. The masqueraded files used simple extension renaming rather than steganographic embedding.

Evidence strength:
1 ref
stegdetect

Evidence Chain

tc_d52039bf get_raw_output 63ms
Sources: stegdetect
Evidence Refs: tc_d52039bf
info confirmed RM#2 volume label IAMAN $_@ links device to informant identity

The removable media device RM#2 (FAT32, volume ID 0xb4d85399) bears the volume label "IAMAN $@". This directly links to the informant user account: the SAM registry shows the informant account (RID 1000) has password hint "IAMAN", and the corporate email is iaman.informant@nist.gov. The "$@" suffix is consistent with a personal signature/handle. This volume label attribution, combined with the masqueraded secret project files found on RM#2, ties the physical exfiltration device directly to the informant user.

Evidence strength:
2 refs
tsk.fsstatregistry.sam

Evidence Chain

tc_e793e9ff get_raw_output 63ms
tc_09675af9 get_raw_output 63ms
Sources: tsk.fsstat, registry.sam
Evidence Refs: tc_e793e9ff, tc_09675af9
info confirmed Complete Chronological Sequence of Events: Network Share Access Through Anti-Forensic Cleanup

Complete chronological sequence of events from initial network share access through anti-forensic cleanup:

2015-03-22 (Day 1 - Initial Access and Preparation):
- 14:33:54 - informant account created (SAM registry)
- 14:35:01 - UserAssist last write (registry.ntuser.informant)
- 14:37:23 - Control Panel accessed (shellbags)
- 14:52:22 - Network share \10.11.11.128\secured_drive first accessed (shellbags My Network Places)
- 15:08:24 - dO and Download folders accessed (shellbags)
- 15:11:21 - Google Chrome installed (shimcache: clickonce_bootstrap.exe)
- 15:11:26 - Google Update installed (shimcache: GoogleCrashHandler.exe, GoogleUpdate.exe)
- 15:11:51 - Google Chrome First Run (MFT)
- 15:51:43 - Control Panel User Accounts Manage Accounts accessed (shellbags)
- 15:51:54 - admin11 backdoor account created (SAM)
- 15:52:30 - ITechTeam backdoor account created (SAM)
- 15:53:01 - temporary backdoor account created (SAM)
- 15:53:05 - Control Panel Change an Account accessed (shellbags)
- 15:54:04 - Windows Burn folder created under admin11 (MFT)
- 15:55:57 - temporary account last login (SAM)
- 15:57:02 - admin11 account last login (SAM)

2015-03-23 (Day 2 - Google Drive Setup and Network Share Reconnaissance):
- 18:38:54 - S data folder accessed (shellbags)
- 19:56:30 - googledrivesync.exe downloaded (MFT: Users/informant/Downloads/googledrivesync.exe with Zone.Identifier)
- 20:00:56 - Bonjour Service installed (registry.system)
- 20:01:01 - Apple Software Update installed (composite.persistence)
- 20:02:09 - GoogleUpdate.exe executed from GUMA94B.tmp (composite.timeline)
- 20:23:28 - Network share \10.11.11.128\secured_drive accessed again (shellbags)
- 20:27:24 - V: drive (mapped network drive) Secret Project Data accessed (shellbags)
- 20:28:17 - Network share pricing decision accessed (shellbags)

2015-03-24 (Day 3 - Data Staging and Exfiltration):
- 09:59:27 - Masqueraded files created on RM#2 USB ($OrphanFiles, tsk.masquerade)
- 13:38:31 - RM#1 USB Secret Project Data browsed (shellbags E:\RM#1\Secret Project Data)
- 13:40:10 - S data\Secret Project Data accessed (shellbags)
- 13:47:54 - Network share Past Projects accessed (shellbags)
- 13:47:58 - S data\Secret Project Data\Secret Project Data\final accessed (shellbags)
- 13:52:05 - S data\Secret Project Data\Secret Project Data\design accessed (shellbags)
- 14:00:19 - E:\Secret Project Data accessed (shellbags)
- 14:01:29 - E:\Secret Project Data\design\winter_whether_advisory.zip browsed as ZIP (shellbags)
- 14:16:33 - Control Panel Power Options accessed (shellbags)
- 19:47:48 - D:\de staging folder created (shellbags)
- 19:52:06 - New folder and temp folders accessed (shellbags)
- 19:54:43 - D:\de\winter_whether_advisory.zip browsed as ZIP (shellbags)
- 20:41:22 - D:\pd, D:\prop, D:\prog staging folders created (shellbags)
- 20:44:13 - D:\de accessed (shellbags)
- 20:54:07 - E:\Secret Project Data\progress accessed (shellbags)
- 20:54:16 - RM#3 CD burn session 1 begins (optical.listing: /de/winter_storm.amr created)
- 20:55:43 - RM#3 CD /technical review files created (optical.listing)
- 20:57:00 - RM#3 CD Koala.jpg, Penguins.jpg, Tulips.jpg created (optical.listing)

2015-03-25 (Day 4 - Anti-Forensic Cleanup):
- 10:15:37 - SAM registry last write (registry.sam)
- 10:18:00 - Windows SoftwareDistribution DataStore Logs modified (composite.defense_evasion)
- 10:33:22 - Administrator account created (SAM - note: this is the SAM registry timestamp, not actual account creation)
- 11:08:36 - MFT analysis timestamp (composite.defense_evasion)
- 14:41:04 - WebCacheV01.tmp modified (ez.mft)
- 14:45:59 - informant account last login (SAM)
- 14:47:28 - Temporary Internet Files modified (ez.mft)
- 14:50:50 - Windows SoftwareDistribution DataStore Logs modified (composite.defense_evasion)
- 14:57:31 - Eraser program files last modified (ez.mft)
- 15:19:20 - Control Panel Programs and Features accessed (shellbags)
- 15:20:59 - Google Drive folder accessed (shellbags)
- 15:21:32 - gen_py directory accessed (ez.mft)
- 15:22:08 - AccountChooser[1].htm accessed (tsk.masquerade)
- 15:24:48 - UserAssist last write (registry.ntuser.informant)
- 15:28:09 - Libraries Documents Library accessed (shellbags)
- 15:28:47 - UserAssist last write (registry.ntuser.informant)
- 15:30:06 - My Computer accessed (shellbags)

Unexplained Gaps:
- No evidence of activity between 2015-03-22 15:57:02 (admin11 last login) and 2015-03-23 18:38:54 (S data folder accessed) - approximately 27 hours
- No evidence of activity between 2015-03-23 20:56:31 (last browser activity) and 2015-03-24 09:59:27 (masqueraded files created on RM#2) - approximately 13 hours
- The gap between 2015-03-24 21:05:40 (last Chrome session storage) and 2015-03-25 10:15:37 (SAM last write) - approximately 13 hours - may be when the anti-forensic cleanup was performed

Evidence strength:
6 refs
registry.samregistry.usrclass.informantoptical.listingtsk.masqueradeez.mftcomposite.recoverycomposite.timeline

Evidence Chain

tc_bf701527 get_raw_output 64ms
tc_9719b5b2 get_raw_output 64ms
tc_6a7ba516 get_raw_output 63ms
tc_779f9069 get_raw_output 64ms
tc_88e1a276 search 4ms
tc_61649c1e get_raw_output 63ms
Time: 2015-03-22T14:33:54 — 2015-03-25T15:30:06
Sources: registry.sam, registry.usrclass.informant, optical.listing, tsk.masquerade, ez.mft, composite.recovery, composite.timeline
Evidence Refs: tc_bf701527, tc_9719b5b2, tc_6a7ba516, tc_779f9069, tc_88e1a276, tc_61649c1e
✓ Ruled Out (Negative Findings)

These hypotheses were explicitly tested and no supporting evidence was found.

  • No Steganographic Content - Concealment via Extension Masquerading, Not Steganography
    Click to expand
  • No steganography or malware detected on RM#3 optical disc
    Click to expand
0
Techniques
0
Tactics
0
Findings Mapped
Reconnaissance
Resource Development1
Initial Access
Execution
Persistence3
Privilege Escalation1
Defense Evasion5
Credential Access
Discovery
Lateral Movement1
Collection3
Command and Control
Exfiltration2
Impact
Inhibit Response Function
Evasion
Impair Process Control
Resource Development
Domains
1F
Persistence
Account Manipulation
1F
Create Account
1F
Local Account
1F
Privilege Escalation
Account Manipulation
1F
Defense Evasion
Masquerading
2F
Right-to-Left Override
3F
Clear Linux or Mac System Logs
2F
File Deletion
5F
Timestomp
1F
Lateral Movement
SMB/Windows Admin Shares
1F
Collection
Data from Network Shared Drive
1F
Local Data Staging
3F
Local Email Collection
1F
Exfiltration
Exfiltration over USB
8F
Exfiltration to Cloud Storage
8F
0
Total IOCs
0
External IPs
0
File IOCs
0
Emails
Network IOCs (1)
TypeValueEnrichmentContextActions
Internal IP 10.11.11.128 Sensitive "Secret Project" data copied to removable USB media (RM#1) VT
File IOCs (2)
TypeValueEnrichmentContextActions
Path /Users/informant/ Document Metadata and File Attribution - NIST Informant Source System
Path C:\Program Google Drive Sync Client Installed and Configured - Exfiltration to iaman.inform
Email IOCs (7)
TypeValueEnrichmentContextActions
Email iaman.informant@nist.gov 17 Deleted Files with Masqueraded Extensions Concealing Office Documents on Remo
Email iaman.informant.personal@gmail.com Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Dest
Email iaman@nist.gov Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Dest
Email eric_p._lauer@omb.eop.gov IOCs carved from RM#3 optical disc reveal document metadata and email addresses
Email spy.conspirator@nist.gov Additional NIST Email Persona: spy.conspirator@nist.gov Found in Bulk Extractor
Email 645mtgs@xchange.nist.gov Outlook Offline Storage Table (OST) File Contains NIST Email Account Data
Email wei.yu@nist.gov Outlook Offline Storage Table (OST) File Contains NIST Email Account Data
Select a source
Select a source from the tree to view raw evidence output.
Source Name Extractor Lines Hash Referenced By
tsk.partitions sleuthkit 8 blake2b:3eed10c8...
tsk.fsstat sleuthkit 37 blake2b:2d2079ee... 5 findings
tsk.timeline sleuthkit 67 blake2b:822b5179... 6 findings
tsk.filelist sleuthkit 27 blake2b:ae86d6dd... 8 findings
tsk.partitions sleuthkit 10 blake2b:67b9085f...
tsk.fsstat sleuthkit 39 blake2b:ac3885f3... 5 findings
tsk.partitions sleuthkit 9 blake2b:83c0b87c...
tsk.fsstat sleuthkit 40 blake2b:9e253812... 5 findings
tsk.filelist sleuthkit 51 blake2b:55fc9962... 8 findings
tsk.masquerade sleuthkit 17 blake2b:97440a18... 10 findings
tsk.filelist sleuthkit 51 blake2b:55fc9962... 8 findings
tsk.masquerade sleuthkit 0 blake2b:empty... 10 findings
tsk.filelist sleuthkit 104709 blake2b:171e0914... 8 findings
tsk.filelist.p1 sleuthkit 93 blake2b:5bdfadd3... 8 findings
tsk.timeline sleuthkit 344089 blake2b:4cc4645b... 6 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:9a5229cb...
bulk.domain bulk_extractor 189 blake2b:ae916b75... 4 findings
bulk.duplicates bulk_extractor 9 blake2b:bb406faf...
bulk.url bulk_extractor 207 blake2b:039de0b6... 6 findings
bulk.url_services bulk_extractor 14 blake2b:2eac1377... 6 findings
hashdeep.hashes hashdeep 6 blake2b:0e07b059...
bulk.bulk_extractor bulk_extractor 1 blake2b:ff8e6e91...
bulk.domain bulk_extractor 189 blake2b:ae916b75... 4 findings
bulk.duplicates bulk_extractor 9 blake2b:bb406faf...
bulk.url bulk_extractor 207 blake2b:039de0b6... 6 findings
bulk.url_services bulk_extractor 14 blake2b:2eac1377... 6 findings
tsk.timeline sleuthkit 187 blake2b:da03c607... 6 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:6f22cc20...
bulk.domain bulk_extractor 237 blake2b:29444e46... 4 findings
bulk.email bulk_extractor 12 blake2b:26c081a6... 6 findings
bulk.rfc822 bulk_extractor 41 blake2b:e3da4d10... 1 finding
bulk.url bulk_extractor 300 blake2b:28d82359... 6 findings
bulk.url_services bulk_extractor 21 blake2b:6224c8f2... 6 findings
strings.output strings 22065 blake2b:9705a003...
binwalk.scan binwalk 0 blake2b:empty... 1 finding
exiftool.metadata exiftool 9 blake2b:37dc79e9... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:5295823a...
bulk.domain bulk_extractor 264 blake2b:c8b97b94... 4 findings
bulk.duplicates bulk_extractor 9 blake2b:9ba9de0c...
bulk.email bulk_extractor 43 blake2b:eb085c00... 6 findings
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9... 1 finding
bulk.url bulk_extractor 288 blake2b:d727c498... 6 findings
bulk.url_services bulk_extractor 19 blake2b:01e609ea... 6 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:57fe84d8...
bulk.domain bulk_extractor 366963 blake2b:334d97c6... 4 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:1a8860fb...
bulk.domain bulk_extractor 264 blake2b:c8b97b94... 4 findings
bulk.duplicates bulk_extractor 9 blake2b:9ba9de0c...
bulk.email bulk_extractor 43 blake2b:eb085c00... 6 findings
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9... 1 finding
bulk.url bulk_extractor 288 blake2b:d727c498... 6 findings
bulk.url_services bulk_extractor 19 blake2b:01e609ea... 6 findings
bulk.duplicates bulk_extractor 12 blake2b:f8b9f6c0...
bulk.email bulk_extractor 6851 blake2b:54db4325... 6 findings
bulk.ether bulk_extractor 6 blake2b:0825117f...
bulk.rfc822 bulk_extractor 7326 blake2b:6a055e6f... 1 finding
bulk.url bulk_extractor 421750 blake2b:03010d93... 6 findings
exiftool.metadata exiftool 9 blake2b:54bd0d9e... 1 finding
hashdeep.hashes hashdeep 6 blake2b:c270e797...
binwalk.scan binwalk 0 blake2b:empty... 1 finding
bulk.url_facebook-address bulk_extractor 19 blake2b:7fe55073... 6 findings
bulk.url_searches bulk_extractor 155 blake2b:b928562c... 6 findings
bulk.url_services bulk_extractor 3637 blake2b:c01e89c3... 6 findings
tsk.masquerade sleuthkit 3 blake2b:42bb5e7d... 10 findings
ez.mft eztools 98918 blake2b:143029ba... 7 findings
pcap.disk.atiumd6a tshark 8 blake2b:99f119b0...
pcap.disk.atiumdva tshark 8 blake2b:38aecead...
pcap.disk.atiumd6a tshark 8 blake2b:99f119b0...
pcap.disk.atiumdva tshark 8 blake2b:38aecead...
ez.shimcache eztools 307 blake2b:70aeb471... 1 finding
pcap.disk.atiumd6a tshark 8 blake2b:99f119b0...
registry.sam regripper 186 blake2b:8d8eeca3... 6 findings
registry.sam regripper 7 blake2b:e4c6f012... 6 findings
pcap.disk.atiumdva tshark 8 blake2b:38aecead...
registry.sam regripper 7 blake2b:e4c6f012... 6 findings
registry.security regripper 69 blake2b:6b7bf22c...
registry.security regripper 8 blake2b:3c5e87f4...
pcap.disk.atiumd6a tshark 8 blake2b:99f119b0...
pcap.disk.atiumdva tshark 8 blake2b:38aecead...
hayabusa.alerts hayabusa 35 blake2b:88083c93... 3 findings
registry.system regripper 33492 blake2b:fb6d4333... 2 findings
registry.system regripper 283 blake2b:7ac960b3... 2 findings
registry.system regripper 283 blake2b:f2a84063... 2 findings
registry.system regripper 5209 blake2b:cc134640... 2 findings
registry.system regripper 199 blake2b:5d42a3e3... 2 findings
registry.system regripper 199 blake2b:bd819259... 2 findings
registry.system regripper 381 blake2b:070a4d56... 2 findings
registry.system regripper 255 blake2b:0d77cf74... 2 findings
registry.system regripper 255 blake2b:0d77cf74... 2 findings
registry.usrclass.admin11 regripper 11 blake2b:26a43778...
registry.ntuser.admin11 regripper 133 blake2b:bf617a09...
registry.ntuser.default regripper 74 blake2b:8518dc3f...
registry.usrclass.informant regripper 102 blake2b:9f1344c3... 11 findings
registry.ntuser.informant regripper 306 blake2b:597d71cd... 5 findings
registry.usrclass.temporary regripper 15 blake2b:3ef5eb22...
registry.ntuser.temporary regripper 118 blake2b:800424ee...
exiftool.metadata exiftool 9 blake2b:37dc79e9... 1 finding
exiftool.metadata exiftool 9 blake2b:e29f3304... 1 finding
exiftool.metadata exiftool 9 blake2b:5d8593b1... 1 finding
exiftool.metadata exiftool 9 blake2b:54bd0d9e... 1 finding
hashdeep.hashes hashdeep 6 blake2b:c124dba3...
strings.output strings 22065 blake2b:9705a003...
strings.output strings 34815 blake2b:89a5dd6d...
strings.output strings 165747 blake2b:2b7a943c...
appfiles.users.appdata.manifest.json icat 23 blake2b:0e6ccb17...
evtx.manifest evtx-extract 54 blake2b:62bd3681...
appfiles.users.appdata.messages.json icat 12 blake2b:9970070e...
appfiles.users.appdata.messages.json icat 12 blake2b:756de350...
appfiles.users.appdata.messages.json icat 12 blake2b:3388b729...
appfiles.users.appdata.messages.json icat 12 blake2b:5b9a5c23...
appfiles.users.appdata.messages.json icat 12 blake2b:d703c6c5...
appfiles.users.appdata.messages.json icat 12 blake2b:01d23426...
appfiles.users.appdata.messages.json icat 12 blake2b:177e9e16...
appfiles.users.appdata.messages.json icat 12 blake2b:29f8fdc8...
appfiles.users.appdata.messages.json icat 12 blake2b:b609d26d...
appfiles.users.appdata.messages.json icat 12 blake2b:8178b9a5...
appfiles.users.appdata.messages.json icat 12 blake2b:75ce174d...
appfiles.users.appdata.messages.json icat 12 blake2b:370f02c3...
appfiles.users.appdata.messages.json icat 12 blake2b:618d7ae0...
appfiles.users.appdata.messages.json icat 12 blake2b:66e09140...
appfiles.users.appdata.messages.json icat 12 blake2b:4cd7b5d8...
appfiles.users.appdata.messages.json icat 12 blake2b:bc3684df...
appfiles.users.appdata.messages.json icat 12 blake2b:d36607ff...
appfiles.users.appdata.messages.json icat 12 blake2b:75e8b65d...
appfiles.users.appdata.messages.json icat 12 blake2b:1b9d284c...
appfiles.users.appdata.messages.json icat 12 blake2b:2e61be98...
appfiles.users.appdata.messages.json icat 12 blake2b:becfd68c...
appfiles.users.appdata.messages.json icat 12 blake2b:a393cf14...
appfiles.users.appdata.messages.json icat 12 blake2b:4525e436...
appfiles.users.appdata.messages.json icat 12 blake2b:749fe204...
appfiles.users.appdata.messages.json icat 12 blake2b:0c314144...
appfiles.users.appdata.messages.json icat 12 blake2b:f5aaf11b...
appfiles.users.appdata.messages.json icat 11 blake2b:9816cd39...
appfiles.users.appdata.messages.json icat 12 blake2b:fb35652f...
appfiles.users.appdata.messages.json icat 12 blake2b:f383c8bd...
appfiles.users.appdata.messages.json icat 12 blake2b:f91f60b9...
appfiles.users.appdata.messages.json icat 12 blake2b:b4ed3e5f...
appfiles.users.appdata.messages.json icat 12 blake2b:0c93350c...
appfiles.users.appdata.messages.json icat 12 blake2b:2128fd8a...
appfiles.users.appdata.messages.json icat 12 blake2b:f97c4aba...
appfiles.users.appdata.messages.json icat 12 blake2b:57aef452...
appfiles.users.appdata.messages.json icat 12 blake2b:88b2d2db...
appfiles.users.appdata.messages.json icat 12 blake2b:5758b47c...
appfiles.users.appdata.messages.json icat 12 blake2b:9d2b7f0e...
appfiles.users.appdata.messages.json icat 12 blake2b:27cad2a7...
appfiles.users.appdata.messages.json icat 12 blake2b:6132c12e...
appfiles.users.appdata.messages.json icat 12 blake2b:7ec85c8b...
appfiles.users.appdata.messages.json icat 12 blake2b:82ecd648...
appfiles.users.appdata.verified_contents.json icat 2 blake2b:cb802bd0...
appfiles.users.appdata.manifest.json icat 20 blake2b:ebce7ce8...
appfiles.users.appdata.manifest.json icat 23 blake2b:bea96c56...
appfiles.users.appdata.messages.json icat 12 blake2b:9d69436a...
appfiles.users.appdata.messages.json icat 12 blake2b:8791a9c3...
appfiles.users.appdata.messages.json icat 12 blake2b:111199ef...
appfiles.users.appdata.messages.json icat 12 blake2b:27a0e76a...
appfiles.users.appdata.messages.json icat 12 blake2b:3fa8e3e2...
appfiles.users.appdata.messages.json icat 12 blake2b:25d34f84...
appfiles.users.appdata.messages.json icat 12 blake2b:4bc65466...
appfiles.users.appdata.messages.json icat 12 blake2b:87068388...
appfiles.users.appdata.messages.json icat 12 blake2b:16092898...
appfiles.users.appdata.messages.json icat 12 blake2b:dba9ad1b...
appfiles.users.appdata.messages.json icat 12 blake2b:3dd10cc5...
appfiles.users.appdata.messages.json icat 12 blake2b:96315a31...
appfiles.users.appdata.messages.json icat 12 blake2b:8d75c661...
appfiles.users.appdata.messages.json icat 12 blake2b:2a07bb28...
appfiles.users.appdata.messages.json icat 12 blake2b:267999b7...
appfiles.users.appdata.messages.json icat 12 blake2b:2c871db7...
appfiles.users.appdata.messages.json icat 12 blake2b:9a09de15...
appfiles.users.appdata.messages.json icat 12 blake2b:8d7ca40e...
appfiles.users.appdata.messages.json icat 12 blake2b:a7162dc8...
appfiles.users.appdata.messages.json icat 12 blake2b:1d33255d...
appfiles.users.appdata.messages.json icat 12 blake2b:b26ab9f4...
appfiles.users.appdata.messages.json icat 12 blake2b:8c42a856...
appfiles.users.appdata.messages.json icat 12 blake2b:bb9f2d8a...
appfiles.users.appdata.messages.json icat 12 blake2b:6794c054...
appfiles.users.appdata.messages.json icat 12 blake2b:0a19e4d0...
appfiles.users.appdata.messages.json icat 12 blake2b:757ea40c...
appfiles.users.appdata.messages.json icat 11 blake2b:af9942ad...
appfiles.users.appdata.messages.json icat 12 blake2b:c521313a...
appfiles.users.appdata.messages.json icat 12 blake2b:da0b3cba...
appfiles.users.appdata.messages.json icat 12 blake2b:8f92a5a3...
appfiles.users.appdata.messages.json icat 12 blake2b:7e24111c...
appfiles.users.appdata.messages.json icat 12 blake2b:645373bc...
appfiles.users.appdata.messages.json icat 12 blake2b:c955fcdb...
appfiles.users.appdata.messages.json icat 12 blake2b:5568e1f1...
appfiles.users.appdata.messages.json icat 12 blake2b:7a932ba5...
appfiles.users.appdata.messages.json icat 12 blake2b:57fa3a6f...
appfiles.users.appdata.messages.json icat 12 blake2b:8e4c4450...
appfiles.users.appdata.messages.json icat 12 blake2b:4337b02b...
appfiles.users.appdata.messages.json icat 12 blake2b:c4021747...
appfiles.users.appdata.messages.json icat 12 blake2b:659742a2...
appfiles.users.appdata.messages.json icat 12 blake2b:26850a98...
appfiles.users.appdata.messages.json icat 12 blake2b:2ea9cba5...
appfiles.users.appdata.verified_contents.json icat 2 blake2b:d9144c1e...
appfiles.users.appdata.manifest.json icat 26 blake2b:d8a5ceca...
appfiles.users.appdata.messages.json icat 12 blake2b:223e8149...
appfiles.users.appdata.messages.json icat 12 blake2b:e0565980...
appfiles.users.appdata.messages.json icat 12 blake2b:2961ecc3...
appfiles.users.appdata.messages.json icat 12 blake2b:82e63e2c...
appfiles.users.appdata.messages.json icat 12 blake2b:759c2bd6...
appfiles.users.appdata.messages.json icat 12 blake2b:d2d171e0...
appfiles.users.appdata.messages.json icat 12 blake2b:693e9a52...
appfiles.users.appdata.messages.json icat 12 blake2b:1b6547bb...
appfiles.users.appdata.messages.json icat 12 blake2b:abcca369...
appfiles.users.appdata.messages.json icat 12 blake2b:bccfa27a...
appfiles.users.appdata.messages.json icat 12 blake2b:ad9906d4...
appfiles.users.appdata.messages.json icat 12 blake2b:67a740c6...
appfiles.users.appdata.messages.json icat 12 blake2b:413c5db4...
appfiles.users.appdata.messages.json icat 12 blake2b:96b8c213...
appfiles.users.appdata.messages.json icat 12 blake2b:1ce1b22c...
appfiles.users.appdata.messages.json icat 12 blake2b:d55a3018...
appfiles.users.appdata.messages.json icat 12 blake2b:5f15bd04...
appfiles.users.appdata.messages.json icat 12 blake2b:65c3a3a9...
appfiles.users.appdata.messages.json icat 12 blake2b:e12219dc...
appfiles.users.appdata.messages.json icat 12 blake2b:4815ad90...
appfiles.users.appdata.messages.json icat 12 blake2b:70578407...
appfiles.users.appdata.messages.json icat 12 blake2b:09286836...
appfiles.users.appdata.messages.json icat 12 blake2b:f80a1c39...
appfiles.users.appdata.messages.json icat 12 blake2b:97caeaa1...
appfiles.users.appdata.messages.json icat 12 blake2b:824efa12...
appfiles.users.appdata.messages.json icat 12 blake2b:5238de03...
appfiles.users.appdata.messages.json icat 12 blake2b:86ecb424...
appfiles.users.appdata.messages.json icat 12 blake2b:8b2c1d52...
appfiles.users.appdata.messages.json icat 12 blake2b:033bc29b...
appfiles.users.appdata.messages.json icat 12 blake2b:67d0e2e2...
appfiles.users.appdata.messages.json icat 12 blake2b:675bb8b2...
appfiles.users.appdata.messages.json icat 12 blake2b:508bf3d2...
appfiles.users.appdata.messages.json icat 12 blake2b:e4e91753...
appfiles.users.appdata.messages.json icat 12 blake2b:2f03c112...
appfiles.users.appdata.messages.json icat 12 blake2b:f0bec284...
appfiles.users.appdata.messages.json icat 12 blake2b:4fd66ca4...
appfiles.users.appdata.messages.json icat 12 blake2b:1d8e6995...
appfiles.users.appdata.messages.json icat 12 blake2b:649a9162...
appfiles.users.appdata.messages.json icat 12 blake2b:aee1d522...
appfiles.users.appdata.messages.json icat 12 blake2b:bbb92502...
appfiles.users.appdata.messages.json icat 12 blake2b:9b9a06ca...
appfiles.users.appdata.messages.json icat 12 blake2b:cc09f384...
appfiles.users.appdata.messages.json icat 12 blake2b:72280445...
appfiles.users.appdata.messages.json icat 12 blake2b:7c5c9b89...
appfiles.users.appdata.manifest.json icat 26 blake2b:dbb9bb54...
appfiles.users.appdata.messages.json icat 12 blake2b:b40a54b0...
appfiles.users.appdata.messages.json icat 12 blake2b:c36ab67e...
appfiles.users.appdata.messages.json icat 12 blake2b:2f42316a...
appfiles.users.appdata.messages.json icat 12 blake2b:a2a8cefa...
appfiles.users.appdata.messages.json icat 12 blake2b:ff6ad37e...
appfiles.users.appdata.messages.json icat 12 blake2b:d0d8c35f...
appfiles.users.appdata.messages.json icat 12 blake2b:86c6f758...
appfiles.users.appdata.messages.json icat 12 blake2b:2716e521...
appfiles.users.appdata.messages.json icat 12 blake2b:93b4de41...
appfiles.users.appdata.messages.json icat 12 blake2b:e8238bb6...
appfiles.users.appdata.messages.json icat 12 blake2b:df2fd668...
appfiles.users.appdata.messages.json icat 12 blake2b:e0844c74...
appfiles.users.appdata.messages.json icat 12 blake2b:3ced7d52...
appfiles.users.appdata.messages.json icat 12 blake2b:8a2dfe65...
appfiles.users.appdata.messages.json icat 12 blake2b:56d07306...
appfiles.users.appdata.messages.json icat 12 blake2b:d58a862d...
appfiles.users.appdata.messages.json icat 12 blake2b:06de6d78...
appfiles.users.appdata.messages.json icat 12 blake2b:77d435cb...
appfiles.users.appdata.messages.json icat 12 blake2b:71a265ea...
appfiles.users.appdata.messages.json icat 12 blake2b:ea6b4991...
appfiles.users.appdata.messages.json icat 12 blake2b:153ec1b4...
appfiles.users.appdata.messages.json icat 12 blake2b:619bb724...
appfiles.users.appdata.messages.json icat 12 blake2b:be98ee6f...
appfiles.users.appdata.messages.json icat 12 blake2b:0c0c7a08...
appfiles.users.appdata.messages.json icat 12 blake2b:87c627a6...
appfiles.users.appdata.messages.json icat 12 blake2b:a6115716...
appfiles.users.appdata.messages.json icat 12 blake2b:56173480...
appfiles.users.appdata.messages.json icat 12 blake2b:8fe80efd...
appfiles.users.appdata.messages.json icat 12 blake2b:2557c906...
appfiles.users.appdata.messages.json icat 12 blake2b:c2eae6b4...
appfiles.users.appdata.messages.json icat 12 blake2b:e6b135a4...
appfiles.users.appdata.messages.json icat 12 blake2b:5b070272...
appfiles.users.appdata.messages.json icat 12 blake2b:c7fc763f...
appfiles.users.appdata.messages.json icat 12 blake2b:1e1c2504...
appfiles.users.appdata.messages.json icat 12 blake2b:09f16621...
appfiles.users.appdata.messages.json icat 12 blake2b:e435068f...
appfiles.users.appdata.messages.json icat 12 blake2b:998fe7a2...
appfiles.users.appdata.messages.json icat 12 blake2b:aedb70c6...
appfiles.users.appdata.messages.json icat 12 blake2b:e255e10e...
appfiles.users.appdata.messages.json icat 12 blake2b:8dcfdb6d...
appfiles.users.appdata.messages.json icat 12 blake2b:96e367a8...
appfiles.users.appdata.messages.json icat 12 blake2b:85c3de3a...
appfiles.users.appdata.messages.json icat 12 blake2b:85d1c04a...
appfiles.users.appdata.messages.json icat 12 blake2b:aae492a1...
appfiles.users.appdata.verified_contents.json icat 2 blake2b:b3131356...
appfiles.users.appdata.manifest.json icat 24 blake2b:9608e837...
appfiles.users.appdata.messages.json icat 12 blake2b:1dc4a0dd...
appfiles.users.appdata.messages.json icat 12 blake2b:8a6b76a1...
appfiles.users.appdata.messages.json icat 12 blake2b:89aec90a...
appfiles.users.appdata.messages.json icat 12 blake2b:aeb3e0e5...
appfiles.users.appdata.messages.json icat 12 blake2b:4ce777b0...
appfiles.users.appdata.messages.json icat 12 blake2b:0746860a...
appfiles.users.appdata.messages.json icat 12 blake2b:fe04ad66...
appfiles.users.appdata.messages.json icat 12 blake2b:67ba593c...
appfiles.users.appdata.messages.json icat 12 blake2b:ddc5c500...
appfiles.users.appdata.messages.json icat 12 blake2b:66c38011...
appfiles.users.appdata.messages.json icat 12 blake2b:0bb9da90...
appfiles.users.appdata.messages.json icat 12 blake2b:95197ed8...
appfiles.users.appdata.messages.json icat 12 blake2b:4b57492c...
appfiles.users.appdata.messages.json icat 12 blake2b:2d411baf...
appfiles.users.appdata.messages.json icat 12 blake2b:6e213d01...
appfiles.users.appdata.messages.json icat 12 blake2b:3415f432...
appfiles.users.appdata.messages.json icat 12 blake2b:8568f6cb...
appfiles.users.appdata.messages.json icat 12 blake2b:6499c5b1...
registry.query.software python-registry 1 blake2b:07529315...
registry.query.system python-registry 1 blake2b:8639046c...
registry.query.system python-registry 1 blake2b:106b833a...
registry.query.system python-registry 1 blake2b:324b498f...
optical.listing mulder-optical 58 blake2b:65ca19c0... 9 findings
exiftool.metadata exiftool 9 blake2b:e29f3304... 1 finding
hashdeep.hashes hashdeep 6 blake2b:28ba0ef4...
composite.file_staging composite 584 blake2b:6b4b4513...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 584 blake2b:6b4b4513...
composite.execution composite 122 blake2b:b4196d21...
enrichment.iocs enrichment 81 blake2b:de75ff0b... 1 finding
composite.defense_evasion composite 187 blake2b:4caa6542...
composite.lateral_movement composite 513 blake2b:6bf37a9a...
composite.recovery composite 22 blake2b:cc3a9297... 2 findings
composite.persistence composite 2433 blake2b:7e51c6c5...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 584 blake2b:6b4b4513...
composite.exfil composite 2477 blake2b:8ba515bd...
composite.correlation composite 1 blake2b:616c8e52...
composite.timeline composite 172 blake2b:1c354032... 1 finding
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 584 blake2b:6b4b4513...
composite.correlation composite 1 blake2b:9ea30b1b...
composite.correlation composite 1 blake2b:062b0d01...
0
Tool Calls
0
Unique Tools
1655.7s
Processing Time
179,489
Tokens
6,505
Tokens/min
Tool Distribution
Token Breakdown
Input Tokens6,265
Output Tokens173,224
Total Tokens179,489
Per-Model Breakdown
bedrock/us.moonshotai.kimi-k3179,489
Token Throughput Over Time
Estimated token consumption by model over time. Each bar represents a 5-minute window.
ID Tool Duration Timestamp Actions
tc_7f85903c scan_evidence 1944ms 2026-09-19T21:17:25
tc_609abdfb list_sources 2ms 2026-09-19T21:17:26
tc_2107ca0c get_source_stats 2ms 2026-09-19T21:17:26
tc_899d6dae list_directory 2ms 2026-09-19T21:17:28
tc_ead27d4c open_case 28ms 2026-09-19T21:17:34
tc_07c6c53f open_case 28ms 2026-09-19T21:17:34
tc_74eebcd2 list_directory 2ms 2026-09-19T21:17:36
tc_c50fd531 list_directory 2ms 2026-09-19T21:17:36
tc_a14594a7 list_sources 2ms 2026-09-19T21:17:37
tc_44e8a0d3 open_case 27ms 2026-09-19T21:17:48
tc_b1ca1c63 open_case 28ms 2026-09-19T21:17:50
tc_870ccfd9 start_extraction_batch 14ms 2026-09-19T21:17:51
tc_37e143b6 run_mmls 38ms 2026-09-19T21:17:51
tc_dcfc120c run_fsstat 47ms 2026-09-19T21:17:51
tc_a162094e run_mactime 3148ms 2026-09-19T21:17:54
tc_d3d152c4 run_fls 3166ms 2026-09-19T21:17:55
tc_eb428159 open_case 29ms 2026-09-19T21:18:02
tc_1ecfe0cb open_case 33ms 2026-09-19T21:18:04
tc_93f7f834 start_extraction_batch 15ms 2026-09-19T21:18:06
tc_1d131708 run_fls 0ms 2026-09-19T21:18:06
tc_5db66842 run_mmls 58ms 2026-09-19T21:18:06
tc_1f7dd41c run_fsstat 141ms 2026-09-19T21:18:06
tc_48b183a5 detect_masquerading 0ms 2026-09-19T21:18:06
tc_e1499ea0 run_mmls 77ms 2026-09-19T21:18:07
tc_194576aa run_fsstat 186ms 2026-09-19T21:18:07
tc_7d6dc7eb start_extraction_batch 9ms 2026-09-19T21:18:07
tc_06a6c92d run_fls 1332ms 2026-09-19T21:18:07
tc_7b884a04 detect_masquerading 2392ms 2026-09-19T21:18:08
tc_ef749e6e run_fls 1203ms 2026-09-19T21:18:08
tc_f8b1d9e5 detect_masquerading 4630ms 2026-09-19T21:18:10
tc_32b613dd run_fls 13180ms 2026-09-19T21:18:19
tc_fa590d68 run_mactime 27939ms 2026-09-19T21:18:34
tc_593d048e run_bulk_extractor 71924ms 2026-09-19T21:19:03
tc_cae9b978 get_completed_results 0ms 2026-09-19T21:19:05
tc_95113eba run_hashdeep 931ms 2026-09-19T21:19:06
tc_87755ecf detect_masquerading 0ms 2026-09-19T21:19:08
tc_0b3bba90 start_extraction_batch 20ms 2026-09-19T21:19:08
tc_e8b179a9 run_photorec 5ms 2026-09-19T21:19:08
tc_8110a17b run_bulk_extractor 81317ms 2026-09-19T21:19:27
tc_126c5fd1 run_mactime 1356ms 2026-09-19T21:21:28
tc_9ae9a57c analyze_disk_pcaps 2171ms 2026-09-19T21:22:11
tc_d527e611 get_completed_results 0ms 2026-09-19T21:22:12
tc_cf64e49b run_bulk_extractor 8691ms 2026-09-19T21:22:17
tc_5c9ededb run_strings 702ms 2026-09-19T21:22:18
tc_14a8b721 run_binwalk 61ms 2026-09-19T21:22:18
tc_1447e46b run_exiftool 91ms 2026-09-19T21:22:18
tc_37bfef41 run_bulk_extractor 54524ms 2026-09-19T21:22:22
tc_9b93b5ae run_bulk_extractor 57120ms 2026-09-19T21:22:24
tc_3bca9797 get_completed_results 0ms 2026-09-19T21:22:25
tc_d2e39127 start_extraction_batch 11ms 2026-09-19T21:22:28
tc_7041a62e detect_steganography 8ms 2026-09-19T21:22:28
tc_04f997ed run_exiftool 89ms 2026-09-19T21:22:28
tc_a3497c4b run_hashdeep 1134ms 2026-09-19T21:22:29
tc_129540e7 detect_masquerading 0ms 2026-09-19T21:22:33
tc_8a6e6f10 run_binwalk 55ms 2026-09-19T21:22:33
tc_dbdbb415 yara_scan_files 6005ms 2026-09-19T21:22:33
tc_9704764d detect_steganography 0ms 2026-09-19T21:22:33
tc_9418dd23 run_bulk_extractor 267753ms 2026-09-19T21:22:33
tc_696c5145 yara_scan_files 7458ms 2026-09-19T21:22:35
tc_4b19a301 open_case 28ms 2026-09-19T21:22:41
tc_5eee38dd list_sources 3ms 2026-09-19T21:22:42
tc_def5d922 get_investigation_summary 5ms 2026-09-19T21:22:42
tc_0ebc0ec4 list_partitions 2ms 2026-09-19T21:22:42
tc_29b82670 get_raw_output 7ms 2026-09-19T21:22:44
tc_178af0ae get_completed_results 0ms 2026-09-19T21:22:44
tc_01d7e6fb get_raw_output 51ms 2026-09-19T21:22:44
tc_11e2bd2b get_raw_output 8ms 2026-09-19T21:22:44
tc_439517e1 search 4ms 2026-09-19T21:22:47
tc_f45318d1 list_files 231ms 2026-09-19T21:22:47
tc_c737aade get_deleted_files 166ms 2026-09-19T21:22:47
tc_c094b571 search 8ms 2026-09-19T21:22:49
tc_a8bd7ef0 search 5ms 2026-09-19T21:22:49
tc_cab743eb get_raw_output 62ms 2026-09-19T21:22:49
tc_d5c97ffc open_case 28ms 2026-09-19T21:22:51
tc_5274cf4a get_raw_output 6ms 2026-09-19T21:22:51
tc_1f5ea2a4 wait_all 0ms 2026-09-19T21:22:52
tc_0ef7cc76 search 3ms 2026-09-19T21:22:54
tc_aba507df search 3ms 2026-09-19T21:22:54
tc_4325ea54 get_raw_output 9ms 2026-09-19T21:22:55
tc_c04024e9 search 124ms 2026-09-19T21:22:59
tc_f6d45a91 search 4ms 2026-09-19T21:23:02
tc_aea52185 search 3ms 2026-09-19T21:23:02
tc_06dcff3f open_case 28ms 2026-09-19T21:23:02
tc_1855b424 get_investigation_summary 4ms 2026-09-19T21:23:03
tc_094763e8 list_sources 1ms 2026-09-19T21:23:03
tc_5e30aaeb get_raw_output 7ms 2026-09-19T21:23:05
tc_6dc21b23 get_fs_timeline 15ms 2026-09-19T21:23:05
tc_a99958ed get_raw_output 51ms 2026-09-19T21:23:05
tc_b28d4ee0 get_raw_output 53ms 2026-09-19T21:23:05
tc_b56457c1 get_raw_output 50ms 2026-09-19T21:23:05
tc_78b1a4b8 detect_masquerading 300049ms 2026-09-19T21:23:06
tc_de1e2884 get_completed_results 0ms 2026-09-19T21:23:07
tc_0d8d5063 get_raw_output 8ms 2026-09-19T21:23:08
tc_d585c8c5 search 3ms 2026-09-19T21:23:10
tc_ae4848b6 get_raw_output 21ms 2026-09-19T21:23:10
tc_6ce1e659 list_files 237ms 2026-09-19T21:23:10
tc_d665ab74 get_raw_output 21ms 2026-09-19T21:23:10
tc_7110d32a get_deleted_files 158ms 2026-09-19T21:23:10
tc_3e1d2dc1 search 5ms 2026-09-19T21:23:12
tc_901cb4d9 search 3ms 2026-09-19T21:23:12
tc_5ff56a82 start_extraction_batch 21ms 2026-09-19T21:23:13
tc_5f1d7dba run_photorec 8ms 2026-09-19T21:23:13
tc_7e35389c run_photorec 4ms 2026-09-19T21:23:13
tc_15fd7fac run_photorec 3ms 2026-09-19T21:23:13
tc_158729c2 search 31ms 2026-09-19T21:23:14
tc_039916e0 get_raw_output 26ms 2026-09-19T21:23:14
tc_4e91bd7e get_raw_output 9ms 2026-09-19T21:23:14
tc_72a7aae4 get_fs_timeline 17ms 2026-09-19T21:23:17
tc_6442fc33 read_evidence_file 1ms 2026-09-19T21:23:17
tc_eb7b5e49 search 3ms 2026-09-19T21:23:18
tc_822369b1 search 5ms 2026-09-19T21:23:18
tc_88d68928 search 4ms 2026-09-19T21:23:19
tc_8ca52543 get_raw_output 54ms 2026-09-19T21:23:19
tc_478f8b1f run_amcache_parser 0ms 2026-09-19T21:23:19
tc_96ec0439 run_mft_parser 9669ms 2026-09-19T21:23:22
tc_7dc33628 get_raw_output 9ms 2026-09-19T21:23:24
tc_c391ec4d run_shimcache_parser 15237ms 2026-09-19T21:23:28
tc_439d1fd9 search 3ms 2026-09-19T21:23:29
tc_b3be9396 get_raw_output 64ms 2026-09-19T21:23:29
tc_8e373a15 search 5ms 2026-09-19T21:23:29
tc_1ddbbf41 search 5ms 2026-09-19T21:23:29
tc_dc31290d run_prefetch_parser 17412ms 2026-09-19T21:23:30
tc_ef229851 get_raw_output 9ms 2026-09-19T21:23:32
tc_c67c10e3 analyze_disk_pcaps 20391ms 2026-09-19T21:23:33
tc_e7611880 run_hayabusa 20432ms 2026-09-19T21:23:33
tc_2fc1e756 search 4ms 2026-09-19T21:23:34
tc_7eb3d696 search 3ms 2026-09-19T21:23:34
tc_ef368dd4 get_timeline 7ms 2026-09-19T21:23:38
tc_84d47e14 search 3ms 2026-09-19T21:23:38
tc_e7af5b92 get_raw_output 10ms 2026-09-19T21:23:40
tc_68094bb2 search 3ms 2026-09-19T21:23:44
tc_c7ee3aa5 search 3ms 2026-09-19T21:23:44
tc_bf58f559 run_registry_parser 37864ms 2026-09-19T21:23:50
tc_736f3a8b search 4ms 2026-09-19T21:23:51
tc_5005ce4b get_completed_results 0ms 2026-09-19T21:23:52
tc_847a2af9 get_raw_output 7ms 2026-09-19T21:23:52
tc_e14f0e72 start_extraction_batch 6ms 2026-09-19T21:23:56
tc_0c38f4b1 run_hindsight 0ms 2026-09-19T21:23:56
tc_190817c3 run_exiftool 341ms 2026-09-19T21:23:57
tc_49815055 detect_steganography 1ms 2026-09-19T21:23:57
tc_6ece73f3 detect_steganography 1ms 2026-09-19T21:23:57
tc_e698f1dd detect_steganography 0ms 2026-09-19T21:23:57
tc_3bc8349f run_exiftool 484ms 2026-09-19T21:23:57
tc_f1bb768d detect_steganography 73ms 2026-09-19T21:23:57
tc_8e764b69 run_exiftool 586ms 2026-09-19T21:23:57
tc_ba6c8572 run_exiftool 594ms 2026-09-19T21:23:57
tc_6f681620 get_raw_output 11ms 2026-09-19T21:23:57
tc_bee59f71 run_chainsaw 919ms 2026-09-19T21:23:57
tc_9c8bb2e7 search 5ms 2026-09-19T21:24:02
tc_aac2ecfc search 3ms 2026-09-19T21:24:02
tc_d5bf6968 search 23ms 2026-09-19T21:24:10
tc_a1b22323 search 3ms 2026-09-19T21:24:14
tc_d1f7799a search 2ms 2026-09-19T21:24:14
tc_ac8eb1f9 get_raw_output 9ms 2026-09-19T21:24:22
tc_ea81ac3a search 4ms 2026-09-19T21:24:27
tc_526eb24a get_raw_output 28ms 2026-09-19T21:24:33
tc_1899b43d run_hashdeep 41090ms 2026-09-19T21:24:38
tc_92784a5c run_strings 41647ms 2026-09-19T21:24:38
tc_fb76d4e7 run_strings 42809ms 2026-09-19T21:24:40
tc_e9fc1503 get_raw_output 10ms 2026-09-19T21:24:44
tc_38fe28bd run_strings 47673ms 2026-09-19T21:24:44
tc_90f3d044 search 2ms 2026-09-19T21:24:46
tc_0036c867 search 4ms 2026-09-19T21:24:51
tc_239b1cce run_evtx_parser 57304ms 2026-09-19T21:24:54
tc_8b55ed4a get_raw_output 28ms 2026-09-19T21:24:57
tc_d9d5a7d9 get_raw_output 9ms 2026-09-19T21:25:09
tc_a14fcba2 search 3ms 2026-09-19T21:25:10
tc_b1a51b61 search 3ms 2026-09-19T21:25:10
tc_62a4f1fd get_raw_output 9ms 2026-09-19T21:25:17
tc_48c9f042 search 4ms 2026-09-19T21:25:18
tc_20e547c2 search 11ms 2026-09-19T21:25:25
tc_694dfa02 parse_browser_history 89352ms 2026-09-19T21:25:26
tc_644fb815 get_raw_output 9ms 2026-09-19T21:25:27
tc_2706b5ad parse_autoruns 91919ms 2026-09-19T21:25:28
tc_a3504c63 search 9ms 2026-09-19T21:25:34
tc_f34d3ba1 search 4ms 2026-09-19T21:25:34
tc_29dfa582 index_app_files 65611ms 2026-09-19T21:25:35
tc_13098e43 get_completed_results 0ms 2026-09-19T21:25:37
tc_01e2072d query_registry_value 3600ms 2026-09-19T21:25:43
tc_9f829869 search 53ms 2026-09-19T21:25:45
tc_8a652956 query_registry_value 10345ms 2026-09-19T21:25:50
tc_4481a22c query_registry_value 10539ms 2026-09-19T21:25:50
tc_33623344 query_registry_value 10636ms 2026-09-19T21:25:50
tc_18ac275f search 3ms 2026-09-19T21:25:51
tc_1f40e615 search 3ms 2026-09-19T21:25:51
tc_41e00847 search 14ms 2026-09-19T21:25:58
tc_30d1d8c1 get_raw_output 9ms 2026-09-19T21:26:05
tc_aad22f76 open_case 30ms 2026-09-19T21:26:10
tc_1cdd313c get_investigation_summary 8ms 2026-09-19T21:26:11
tc_74ad24e1 list_sources 3ms 2026-09-19T21:26:11
tc_8808b384 get_source_stats 111ms 2026-09-19T21:26:12
tc_8ddabb81 get_raw_output 65ms 2026-09-19T21:26:16
tc_57adfb0b get_raw_output 63ms 2026-09-19T21:26:17
tc_905dad26 get_raw_output 29ms 2026-09-19T21:26:23
tc_1dd2d559 search 4ms 2026-09-19T21:26:24
tc_6f08c30a get_raw_output 66ms 2026-09-19T21:26:26
tc_0525c3c4 list_partitions 1ms 2026-09-19T21:26:26
tc_598069b5 search 5ms 2026-09-19T21:26:28
tc_31f1a5cc get_deleted_files 238ms 2026-09-19T21:26:28
tc_87e568a1 get_raw_output 9ms 2026-09-19T21:26:29
tc_7474aab9 search 5ms 2026-09-19T21:26:30
tc_7803c966 search 5ms 2026-09-19T21:26:30
tc_4882138c search 5ms 2026-09-19T21:26:31
tc_4fadec56 search 5ms 2026-09-19T21:26:31
tc_da66a6de search 5ms 2026-09-19T21:26:31
tc_c726d7bb search 3ms 2026-09-19T21:26:31
tc_a034ecf5 get_raw_output 63ms 2026-09-19T21:26:33
tc_a2e2b216 search 4ms 2026-09-19T21:26:33
tc_90281af6 get_raw_output 7ms 2026-09-19T21:26:35
tc_3d2ab650 search 4ms 2026-09-19T21:26:36
tc_340e529a get_raw_output 10ms 2026-09-19T21:26:41
tc_fb7f6e17 search 4ms 2026-09-19T21:26:41
tc_018b802a search 3ms 2026-09-19T21:26:41
tc_3c252fd4 get_raw_output 28ms 2026-09-19T21:26:45
tc_b313e0c4 search 4ms 2026-09-19T21:26:47
tc_1217125e search 4ms 2026-09-19T21:26:47
tc_6ff90149 get_raw_output 62ms 2026-09-19T21:26:47
tc_43aeae34 get_raw_output 10ms 2026-09-19T21:26:54
tc_168fd4d4 get_raw_output 64ms 2026-09-19T21:26:55
tc_54cda852 search 3ms 2026-09-19T21:26:55
tc_0d049f99 search 4ms 2026-09-19T21:26:57
tc_b8900834 get_raw_output 64ms 2026-09-19T21:26:58
tc_381045b3 search 5ms 2026-09-19T21:26:58
tc_1047dd83 get_raw_output 63ms 2026-09-19T21:27:03
tc_20cf5945 search 5ms 2026-09-19T21:27:03
tc_4b266630 search 5ms 2026-09-19T21:27:08
tc_dcf5e008 get_raw_output 63ms 2026-09-19T21:27:08
tc_97251b3e search 4ms 2026-09-19T21:27:11
tc_87a37235 get_raw_output 28ms 2026-09-19T21:27:13
tc_8bc36784 get_raw_output 22ms 2026-09-19T21:27:22
tc_be50d804 get_timeline 2ms 2026-09-19T21:27:29
tc_159d926f get_raw_output 63ms 2026-09-19T21:27:29
tc_85461772 search 4ms 2026-09-19T21:27:33
tc_bbe80d46 get_raw_output 23ms 2026-09-19T21:27:41
tc_4e563d76 get_raw_output 9ms 2026-09-19T21:27:42
tc_d52039bf get_raw_output 63ms 2026-09-19T21:27:44
tc_8bfb5ced search 3ms 2026-09-19T21:27:44
tc_b81a9fbe get_raw_output 65ms 2026-09-19T21:27:50
tc_1a5ed6b8 get_timeline 3ms 2026-09-19T21:27:54
tc_d7b27270 search 4ms 2026-09-19T21:27:54
tc_f4302196 search 4ms 2026-09-19T21:28:01
tc_d68dcab6 search 4ms 2026-09-19T21:28:05
tc_9109ea6e search 3ms 2026-09-19T21:28:05
tc_32dda288 get_raw_output 64ms 2026-09-19T21:28:08
tc_4887726e get_raw_output 9ms 2026-09-19T21:28:15
tc_aae6621b get_raw_output 64ms 2026-09-19T21:28:21
tc_b24fc511 get_raw_output 64ms 2026-09-19T21:28:21
tc_382fc69a search 4ms 2026-09-19T21:28:26
tc_b959e888 get_raw_output 65ms 2026-09-19T21:28:30
tc_ad21b7b5 submit_finding 12ms 2026-09-19T21:28:31
tc_3d780fd9 get_raw_output 65ms 2026-09-19T21:28:39
tc_b5aa8deb get_raw_output 9ms 2026-09-19T21:28:42
tc_546003d4 get_raw_output 23ms 2026-09-19T21:28:48
tc_cd33065e submit_finding 11ms 2026-09-19T21:28:58
tc_329be2cc search 4ms 2026-09-19T21:29:06
tc_052b11d0 get_raw_output 64ms 2026-09-19T21:29:06
tc_afcbe62a detect_steganography 1ms 2026-09-19T21:29:15
tc_38d4edcf submit_finding 10ms 2026-09-19T21:29:18
tc_d4dd544b get_raw_output 9ms 2026-09-19T21:29:21
tc_a03154d9 submit_finding 11ms 2026-09-19T21:29:31
tc_76d31784 get_raw_output 29ms 2026-09-19T21:29:40
tc_a5c81e1a search 4ms 2026-09-19T21:29:43
tc_33e08c4f get_raw_output 10ms 2026-09-19T21:29:48
tc_462e4185 submit_finding 12ms 2026-09-19T21:29:49
tc_f312804d search 4ms 2026-09-19T21:29:54
tc_27f7fa15 search 4ms 2026-09-19T21:29:55
tc_6c2d1136 submit_finding 11ms 2026-09-19T21:30:01
tc_9a4391bf get_raw_output 9ms 2026-09-19T21:30:04
tc_d62cbc21 get_raw_output 29ms 2026-09-19T21:30:08
tc_623d4262 search 4ms 2026-09-19T21:30:16
tc_90248fc4 get_raw_output 9ms 2026-09-19T21:30:23
tc_a146ee59 submit_finding 13ms 2026-09-19T21:30:27
tc_29f6e495 search 4ms 2026-09-19T21:30:29
tc_c337a5b7 submit_finding 11ms 2026-09-19T21:30:37
tc_91e0648f get_raw_output 9ms 2026-09-19T21:30:40
tc_0b281b41 get_raw_output 9ms 2026-09-19T21:30:45
tc_e5ef6189 search 4ms 2026-09-19T21:30:45
tc_54fedc06 submit_finding 11ms 2026-09-19T21:30:48
tc_1761368f search 3ms 2026-09-19T21:30:58
tc_362c99e6 search 3ms 2026-09-19T21:30:58
tc_2035e3af get_raw_output 9ms 2026-09-19T21:30:59
tc_3ab2cf3e search 4ms 2026-09-19T21:31:12
tc_4d9146b0 get_raw_output 48ms 2026-09-19T21:31:19
tc_5c930e3e search 4ms 2026-09-19T21:31:19
tc_7fb8ff30 submit_finding 10ms 2026-09-19T21:31:22
tc_502f8b51 get_raw_output 9ms 2026-09-19T21:31:23
tc_09675af9 get_raw_output 63ms 2026-09-19T21:31:30
tc_ba3b28d0 search 3ms 2026-09-19T21:31:30
tc_aa51bd9c search 4ms 2026-09-19T21:31:32
tc_cc17eecc get_raw_output 9ms 2026-09-19T21:31:38
tc_5dcda13b submit_finding 10ms 2026-09-19T21:31:43
tc_953dec4d search 4ms 2026-09-19T21:31:45
tc_a9a8268a submit_finding 10ms 2026-09-19T21:31:46
tc_043b5378 get_raw_output 10ms 2026-09-19T21:31:51
tc_7b2a10d2 update_finding 12ms 2026-09-19T21:31:53
tc_24d5765e submit_finding 19ms 2026-09-19T21:32:07
tc_53e09997 submit_finding 15ms 2026-09-19T21:32:10
tc_971410c1 search 4ms 2026-09-19T21:32:12
tc_8d0ab790 search 3ms 2026-09-19T21:32:20
tc_6ec3a589 search 4ms 2026-09-19T21:32:20
tc_b28a5a1a submit_finding 16ms 2026-09-19T21:32:24
tc_307d406b open_case 30ms 2026-09-19T21:32:33
tc_2e5b310b get_raw_output 64ms 2026-09-19T21:32:34
tc_838e73ef search 3ms 2026-09-19T21:32:34
tc_1966c72b get_investigation_summary 6ms 2026-09-19T21:32:34
tc_dcb7bc18 get_findings 1ms 2026-09-19T21:32:34
tc_cd717784 get_source_stats 66ms 2026-09-19T21:32:36
tc_7c211567 get_plaso_stats 2ms 2026-09-19T21:32:36
tc_018b413f submit_finding 15ms 2026-09-19T21:32:40
tc_6ccb7567 get_investigation_summary 5ms 2026-09-19T21:32:50
tc_008230c2 search 5ms 2026-09-19T21:32:52
tc_68257dc0 search 2ms 2026-09-19T21:32:52
tc_b55eedb8 search 3ms 2026-09-19T21:32:52
tc_36fead2f search 5ms 2026-09-19T21:32:55
tc_f3ae1170 search 7ms 2026-09-19T21:32:55
tc_4f33f86c search 3ms 2026-09-19T21:32:55
tc_62baaed8 search 3ms 2026-09-19T21:32:55
tc_8a88b8de search 4ms 2026-09-19T21:32:58
tc_55b1cf48 search 3ms 2026-09-19T21:32:58
tc_0cd7d990 search 2ms 2026-09-19T21:32:58
tc_7a045d28 search 3ms 2026-09-19T21:33:02
tc_db6bed13 search 4ms 2026-09-19T21:33:02
tc_5ed3ad23 search 3ms 2026-09-19T21:33:04
tc_2d51a110 search 3ms 2026-09-19T21:33:04
tc_e793e9ff get_raw_output 63ms 2026-09-19T21:33:08
tc_0f79fce4 search 3ms 2026-09-19T21:33:08
tc_109a1ac2 get_raw_output 64ms 2026-09-19T21:33:08
tc_08554f75 search 4ms 2026-09-19T21:33:10
tc_640217bb parse_prefetch 1ms 2026-09-19T21:33:10
tc_e5e8d5a2 get_findings 1ms 2026-09-19T21:33:12
tc_38cd7eef get_source_stats 65ms 2026-09-19T21:33:12
tc_1953e6d6 parse_prefetch_detailed 1ms 2026-09-19T21:33:13
tc_64c57b7a parse_shimcache 1ms 2026-09-19T21:33:13
tc_a4bbc741 get_raw_output 64ms 2026-09-19T21:33:18
tc_9c50e4fe search 3ms 2026-09-19T21:33:18
tc_9c5933b3 search 3ms 2026-09-19T21:33:18
tc_b9feecf4 get_amcache 9ms 2026-09-19T21:33:24
tc_9213a28d get_userassist 1ms 2026-09-19T21:33:24
tc_31e96691 track_progress 13ms 2026-09-19T21:33:27
tc_d669507b search 3ms 2026-09-19T21:33:35
tc_cd5f47dd search 3ms 2026-09-19T21:33:35
tc_624a6fb6 open_case 30ms 2026-09-19T21:33:39
tc_af837af9 get_raw_output 65ms 2026-09-19T21:33:39
tc_ff9ce58e get_investigation_summary 6ms 2026-09-19T21:33:40
tc_ab963096 get_findings 1ms 2026-09-19T21:33:41
tc_93744d44 search 4ms 2026-09-19T21:33:42
tc_d40d4209 search 3ms 2026-09-19T21:33:42
tc_d500bd0f get_source_stats 65ms 2026-09-19T21:33:42
tc_06a69604 get_raw_output 9ms 2026-09-19T21:33:54
tc_09c0e8f0 search 3ms 2026-09-19T21:33:54
tc_a57005b5 get_plaso_stats 2ms 2026-09-19T21:33:54
tc_5f1994bf get_deleted_files 181ms 2026-09-19T21:33:56
tc_a1bc168c search 3ms 2026-09-19T21:33:57
tc_c7f99605 search 3ms 2026-09-19T21:33:57
tc_7e1289b6 search 11ms 2026-09-19T21:33:58
tc_6f1e3638 search 4ms 2026-09-19T21:34:00
tc_1beae361 get_raw_output 64ms 2026-09-19T21:34:01
tc_dad25c9d parse_prefetch 1ms 2026-09-19T21:34:06
tc_a4f753d9 parse_shellbags 1ms 2026-09-19T21:34:11
tc_f033dd75 parse_lnk_files 1ms 2026-09-19T21:34:11
tc_6d04984e submit_finding 15ms 2026-09-19T21:34:13
tc_d91f7da7 parse_prefetch_detailed 1ms 2026-09-19T21:34:18
tc_7a520720 search 3ms 2026-09-19T21:34:23
tc_334f9aef search 3ms 2026-09-19T21:34:23
tc_6b3551ac parse_amcache 1ms 2026-09-19T21:34:24
tc_9ef6841b submit_finding 14ms 2026-09-19T21:34:29
tc_27ecd719 get_raw_output 64ms 2026-09-19T21:34:32
tc_4e73ab09 get_amcache 10ms 2026-09-19T21:34:33
tc_531e8fab parse_browser_history 6325ms 2026-09-19T21:34:47
tc_e91fbf56 search 10ms 2026-09-19T21:34:47
tc_b7f4f59a get_userassist 1ms 2026-09-19T21:34:51
tc_345326ea submit_finding 15ms 2026-09-19T21:34:52
tc_d6d81c26 search 5ms 2026-09-19T21:34:53
tc_a73c2eb4 search 3ms 2026-09-19T21:34:53
tc_9de55f1e search 3ms 2026-09-19T21:34:57
tc_adabc7cf get_raw_output 65ms 2026-09-19T21:34:58
tc_ba86db85 get_raw_output 64ms 2026-09-19T21:35:03
tc_6f6a6523 get_raw_output 64ms 2026-09-19T21:35:05
tc_1eb793cf get_raw_output 65ms 2026-09-19T21:35:08
tc_01e341a1 search 3ms 2026-09-19T21:35:08
tc_685be800 search 3ms 2026-09-19T21:35:08
tc_8c09dbaa search 3ms 2026-09-19T21:35:12
tc_c1de7c30 search 3ms 2026-09-19T21:35:12
tc_2600e872 search 3ms 2026-09-19T21:35:14
tc_0eace9e9 search 3ms 2026-09-19T21:35:14
tc_02201e5d get_raw_output 68ms 2026-09-19T21:35:17
tc_05611dc7 search 3ms 2026-09-19T21:35:20
tc_e73657f4 search 5ms 2026-09-19T21:35:20
tc_aec3040d parse_browser_history 6417ms 2026-09-19T21:35:28
tc_7e202437 search 3ms 2026-09-19T21:35:30
tc_bc083862 search 9ms 2026-09-19T21:35:30
tc_d17de9a8 search 6ms 2026-09-19T21:35:31
tc_c282871c search 4ms 2026-09-19T21:35:34
tc_6a5e1df4 search 3ms 2026-09-19T21:35:36
tc_d6eadea7 search 2ms 2026-09-19T21:35:36
tc_1cdc079b track_progress 12ms 2026-09-19T21:35:43
tc_ea8822a6 parse_shellbags 1ms 2026-09-19T21:35:46
tc_3fde9d24 search 3ms 2026-09-19T21:35:50
tc_32fd294e search 3ms 2026-09-19T21:35:50
tc_29305eef search 3ms 2026-09-19T21:35:58
tc_f59e2182 search 10ms 2026-09-19T21:35:58
tc_fc8af643 get_findings 1ms 2026-09-19T21:35:58
tc_7a5d13fb search 3ms 2026-09-19T21:36:00
tc_4bc7c3d0 get_raw_output 63ms 2026-09-19T21:36:03
tc_aa2af519 search 3ms 2026-09-19T21:36:05
tc_d0d5b8bc search 10ms 2026-09-19T21:36:05
tc_5c5a20aa search 3ms 2026-09-19T21:36:08
tc_8518d3c1 get_raw_output 62ms 2026-09-19T21:36:11
tc_e15d335b search 3ms 2026-09-19T21:36:13
tc_6f6f1708 search 9ms 2026-09-19T21:36:13
tc_aae693c1 search 3ms 2026-09-19T21:36:16
tc_229376c1 search 6ms 2026-09-19T21:36:20
tc_bf84fed1 submit_finding 16ms 2026-09-19T21:36:20
tc_3f7f79f6 search 3ms 2026-09-19T21:36:22
tc_2252e7ee search 10ms 2026-09-19T21:36:22
tc_ecd23bca search 4ms 2026-09-19T21:36:24
tc_687148b4 search 4ms 2026-09-19T21:36:28
tc_934e399f search 3ms 2026-09-19T21:36:30
tc_a220e0f0 search 10ms 2026-09-19T21:36:30
tc_3e0795b4 search 3ms 2026-09-19T21:36:38
tc_f3fe64f4 search 3ms 2026-09-19T21:36:38
tc_c60fc009 search 3ms 2026-09-19T21:36:39
tc_2d13d7f6 search 10ms 2026-09-19T21:36:39
tc_f042338f search 6ms 2026-09-19T21:36:41
tc_c0ab6610 search 3ms 2026-09-19T21:36:50
tc_4b28e6a8 search 10ms 2026-09-19T21:36:50
tc_c5c66fdd search 3ms 2026-09-19T21:36:51
tc_06c3c578 search 3ms 2026-09-19T21:36:51
tc_ee53418a search 10ms 2026-09-19T21:36:53
tc_dd6f0f81 search 3ms 2026-09-19T21:36:59
tc_a0b47d93 search 10ms 2026-09-19T21:37:00
tc_98bdc3bf search 3ms 2026-09-19T21:37:09
tc_ba298a1e search 9ms 2026-09-19T21:37:09
tc_00345c3c search 3ms 2026-09-19T21:37:11
tc_1c8c0b4c search 3ms 2026-09-19T21:37:11
tc_9429fd3c get_raw_output 63ms 2026-09-19T21:37:12
tc_fa4f5f19 search 5ms 2026-09-19T21:37:17
tc_7c3c17d4 search 3ms 2026-09-19T21:37:24
tc_5efa3e4a search 10ms 2026-09-19T21:37:24
tc_651e1e78 search 3ms 2026-09-19T21:37:26
tc_3ce2652f search 3ms 2026-09-19T21:37:26
tc_eb34ec75 get_raw_output 63ms 2026-09-19T21:37:26
tc_04128a16 search 3ms 2026-09-19T21:37:34
tc_ddda66a3 search 3ms 2026-09-19T21:37:35
tc_b443aaa0 search 10ms 2026-09-19T21:37:35
tc_a43f4b87 search 4ms 2026-09-19T21:37:40
tc_d4d7ee85 search 3ms 2026-09-19T21:37:40
tc_408a0bbc search 3ms 2026-09-19T21:37:44
tc_a5561a51 search 9ms 2026-09-19T21:37:44
tc_1316f8d5 get_raw_output 62ms 2026-09-19T21:37:49
tc_fc0450fa search 3ms 2026-09-19T21:37:56
tc_ed104070 search 10ms 2026-09-19T21:37:56
tc_7962f9a9 search 4ms 2026-09-19T21:38:01
tc_e558ed12 submit_finding 17ms 2026-09-19T21:38:03
tc_429cd624 get_raw_output 63ms 2026-09-19T21:38:06
tc_832cf58c search 3ms 2026-09-19T21:38:07
tc_c382cd59 search 10ms 2026-09-19T21:38:07
tc_2d45f017 search 4ms 2026-09-19T21:38:13
tc_082c7e67 search 3ms 2026-09-19T21:38:17
tc_e743ee87 search 10ms 2026-09-19T21:38:17
tc_8d98bf4a get_raw_output 63ms 2026-09-19T21:38:17
tc_88afa428 search 4ms 2026-09-19T21:38:22
tc_7384cf6b search 4ms 2026-09-19T21:38:23
tc_e7d906c5 search 4ms 2026-09-19T21:38:23
tc_992a7e9c get_raw_output 63ms 2026-09-19T21:38:27
tc_1b8e06a2 search 4ms 2026-09-19T21:38:32
tc_479456be search 3ms 2026-09-19T21:38:34
tc_1c99bc32 search 9ms 2026-09-19T21:38:34
tc_c97e8b7a get_raw_output 63ms 2026-09-19T21:38:37
tc_0642d01e search 4ms 2026-09-19T21:38:42
tc_b202406d search 3ms 2026-09-19T21:38:48
tc_3a06c706 search 10ms 2026-09-19T21:38:48
tc_cb9edda6 get_raw_output 62ms 2026-09-19T21:38:50
tc_3de09c43 search 4ms 2026-09-19T21:38:56
tc_845aa56f search 3ms 2026-09-19T21:38:59
tc_93511c7c search 9ms 2026-09-19T21:38:59
tc_9878d171 search 3ms 2026-09-19T21:39:09
tc_9224c55b search 9ms 2026-09-19T21:39:09
tc_c1c1c9d7 get_raw_output 63ms 2026-09-19T21:39:13
tc_e8f6c322 search 3ms 2026-09-19T21:39:21
tc_f9e126fe search 10ms 2026-09-19T21:39:21
tc_9ae4cb0a search 4ms 2026-09-19T21:39:22
tc_e898016d search 3ms 2026-09-19T21:39:34
tc_0ef0e21a search 10ms 2026-09-19T21:39:34
tc_734c5213 get_raw_output 64ms 2026-09-19T21:39:37
tc_b0588864 submit_finding 15ms 2026-09-19T21:39:40
tc_73a65f73 search 4ms 2026-09-19T21:39:43
tc_3ad5fc23 submit_finding 16ms 2026-09-19T21:39:45
tc_4ab9f8fd update_finding 14ms 2026-09-19T21:39:47
tc_8528718d get_investigation_summary 5ms 2026-09-19T21:39:48
tc_f2696d8c search 3ms 2026-09-19T21:39:49
tc_a09387dd search 10ms 2026-09-19T21:39:49
tc_7a599550 get_raw_output 63ms 2026-09-19T21:39:49
tc_b293b0eb track_progress 12ms 2026-09-19T21:39:55
tc_d89639a7 get_investigation_summary 6ms 2026-09-19T21:39:57
tc_34eb335a open_case 30ms 2026-09-19T21:39:57
tc_1a076bc3 get_investigation_summary 6ms 2026-09-19T21:39:58
tc_4fa6d537 get_findings 2ms 2026-09-19T21:39:59
tc_90c741b2 get_source_stats 66ms 2026-09-19T21:40:01
tc_1e7ff7be search 3ms 2026-09-19T21:40:02
tc_ec567815 search 10ms 2026-09-19T21:40:02
tc_6d779a15 open_case 31ms 2026-09-19T21:40:07
tc_0f5291e1 search 5ms 2026-09-19T21:40:07
tc_32575163 list_sources 4ms 2026-09-19T21:40:08
tc_fadc42a1 list_partitions 2ms 2026-09-19T21:40:09
tc_8c857997 get_raw_output 66ms 2026-09-19T21:40:11
tc_9334d6ff search 3ms 2026-09-19T21:40:12
tc_5f88f0df search 10ms 2026-09-19T21:40:12
tc_075de695 list_files 208ms 2026-09-19T21:40:13
tc_26a492c7 search 5ms 2026-09-19T21:40:15
tc_ceafe3a8 search 6ms 2026-09-19T21:40:17
tc_e4016fb9 open_case 31ms 2026-09-19T21:40:19
tc_41a9657a get_raw_output 64ms 2026-09-19T21:40:19
tc_28174022 search 3ms 2026-09-19T21:40:22
tc_280ea4ed search 3ms 2026-09-19T21:40:24
tc_ea57401c search 3ms 2026-09-19T21:40:25
tc_7119986d search 10ms 2026-09-19T21:40:25
tc_ac3310da get_raw_output 29ms 2026-09-19T21:40:26
tc_927b4274 search 3ms 2026-09-19T21:40:28
tc_7497fea0 search 3ms 2026-09-19T21:40:29
tc_1767f80d start_extraction_batch 7ms 2026-09-19T21:40:31
tc_d2d68afe run_optical_listing 73ms 2026-09-19T21:40:31
tc_4054305c search 3ms 2026-09-19T21:40:33
tc_2658f502 start_extraction_batch 1ms 2026-09-19T21:40:34
tc_535a9821 search 3ms 2026-09-19T21:40:39
tc_70e2395b search 9ms 2026-09-19T21:40:39
tc_01f40fe8 search 3ms 2026-09-19T21:40:41
tc_5ecea197 yara_scan_files 6256ms 2026-09-19T21:40:41
tc_4e5d21a5 search 3ms 2026-09-19T21:40:43
tc_495b9fb2 wait_all 10001ms 2026-09-19T21:40:46
tc_371574c8 get_completed_results 0ms 2026-09-19T21:40:47
tc_5370ab12 get_completed_results 0ms 2026-09-19T21:40:47
tc_2d8532f8 search 3ms 2026-09-19T21:40:52
tc_0cd0133b search 3ms 2026-09-19T21:40:53
tc_2ad49c98 search 10ms 2026-09-19T21:40:53
tc_30e10122 get_raw_output 30ms 2026-09-19T21:41:04
tc_8d8a7d1b start_extraction_batch 1ms 2026-09-19T21:41:05
tc_110626af detect_steganography 0ms 2026-09-19T21:41:05
tc_46872038 analyze_pdf 0ms 2026-09-19T21:41:05
tc_b13be969 analyze_office_document 0ms 2026-09-19T21:41:05
tc_26da3116 detect_masquerading 0ms 2026-09-19T21:41:05
tc_418d6564 run_exiftool 84ms 2026-09-19T21:41:05
tc_b4fa80c4 run_hashdeep 431ms 2026-09-19T21:41:05
tc_f58de645 open_case 31ms 2026-09-19T21:41:09
tc_235c6522 get_investigation_summary 6ms 2026-09-19T21:41:10
tc_31a8791d get_findings 1ms 2026-09-19T21:41:11
tc_ebcb9b0f search 4ms 2026-09-19T21:41:16
tc_6de51351 get_source_stats 65ms 2026-09-19T21:41:18
tc_77b75fb3 parse_prefetch 1ms 2026-09-19T21:41:18
tc_038ba15f open_case 31ms 2026-09-19T21:41:20
tc_518328dc wait_all 0ms 2026-09-19T21:41:20
tc_6391306c list_sources 4ms 2026-09-19T21:41:22
tc_433a0270 search 5ms 2026-09-19T21:41:23
tc_a9665723 open_case 31ms 2026-09-19T21:41:25
tc_0808cdf7 search 3ms 2026-09-19T21:41:25
tc_c9f108c7 get_investigation_summary 6ms 2026-09-19T21:41:26
tc_0d46c1a5 list_sources 3ms 2026-09-19T21:41:26
tc_a2c1480b search 4ms 2026-09-19T21:41:27
tc_77d26cea get_findings 2ms 2026-09-19T21:41:27
tc_8ca8b160 list_partitions 2ms 2026-09-19T21:41:28
tc_374aea29 get_raw_output 65ms 2026-09-19T21:41:29
tc_3050fddc list_files 209ms 2026-09-19T21:41:30
tc_52751000 parse_prefetch_detailed 1ms 2026-09-19T21:41:31
tc_cdd83edf get_raw_output 63ms 2026-09-19T21:41:31
tc_9fbe77fa get_raw_output 62ms 2026-09-19T21:41:31
tc_9ece051d search 7ms 2026-09-19T21:41:33
tc_f68f905b get_raw_output 64ms 2026-09-19T21:41:33
tc_02460de1 get_raw_output 63ms 2026-09-19T21:41:33
tc_f6d46bf4 search 3ms 2026-09-19T21:41:34
tc_0ec0902e search 4ms 2026-09-19T21:41:35
tc_8279b429 search 3ms 2026-09-19T21:41:35
tc_ea1f62b0 search 3ms 2026-09-19T21:41:36
tc_71a0c7e3 parse_amcache 1ms 2026-09-19T21:41:36
tc_fff85a49 get_raw_output 28ms 2026-09-19T21:41:38
tc_d2fffcfc get_raw_output 22ms 2026-09-19T21:41:38
tc_3053b05f get_raw_output 31ms 2026-09-19T21:41:39
tc_0a97a3d5 get_amcache 9ms 2026-09-19T21:41:40
tc_37a4e366 search 4ms 2026-09-19T21:41:42
tc_38d67ecb get_raw_output 29ms 2026-09-19T21:41:44
tc_d989d590 search 4ms 2026-09-19T21:41:45
tc_f1947365 search 3ms 2026-09-19T21:41:45
tc_fc6feb1f search 4ms 2026-09-19T21:41:46
tc_8461f6bf search 3ms 2026-09-19T21:41:48
tc_34dda51e get_raw_output 29ms 2026-09-19T21:41:52
tc_4edcdbc3 search 3ms 2026-09-19T21:41:52
tc_22c6fc8b get_raw_output 22ms 2026-09-19T21:41:52
tc_32595ed7 search 3ms 2026-09-19T21:41:52
tc_72a3e7fa search 3ms 2026-09-19T21:41:55
tc_2b35012e search 3ms 2026-09-19T21:41:57
tc_0cdff4d3 search 3ms 2026-09-19T21:41:57
tc_cc9a6481 search 3ms 2026-09-19T21:41:57
tc_775a364a search 4ms 2026-09-19T21:41:58
tc_be4c231d get_raw_output 23ms 2026-09-19T21:42:00
tc_b969ad00 get_raw_output 65ms 2026-09-19T21:42:01
tc_25a94d31 get_raw_output 64ms 2026-09-19T21:42:02
tc_51ed6067 search 3ms 2026-09-19T21:42:06
tc_4fffc238 search 3ms 2026-09-19T21:42:06
tc_541d3c1a search 5ms 2026-09-19T21:42:08
tc_3a014d3e search 5ms 2026-09-19T21:42:08
tc_e755f775 search 3ms 2026-09-19T21:42:12
tc_c1fdfab4 search 3ms 2026-09-19T21:42:17
tc_b8b6e627 search 2ms 2026-09-19T21:42:17
tc_e4ca514a parse_prefetch 1ms 2026-09-19T21:42:20
tc_90900270 search 3ms 2026-09-19T21:42:20
tc_6241434f search 3ms 2026-09-19T21:42:20
tc_c5686bb7 search 3ms 2026-09-19T21:42:21
tc_e0ecca93 parse_prefetch_detailed 1ms 2026-09-19T21:42:22
tc_8393c254 search 4ms 2026-09-19T21:42:27
tc_70a86399 search 4ms 2026-09-19T21:42:27
tc_db055e25 search 3ms 2026-09-19T21:42:30
tc_5456f411 search 3ms 2026-09-19T21:42:30
tc_339a7781 search 3ms 2026-09-19T21:42:34
tc_f2f89c5b parse_shimcache 1ms 2026-09-19T21:42:35
tc_e0ce8351 search 3ms 2026-09-19T21:42:41
tc_6f5124a0 search 3ms 2026-09-19T21:42:41
tc_5f7e1616 search 3ms 2026-09-19T21:42:47
tc_71b58b8b parse_amcache 1ms 2026-09-19T21:42:48
tc_5b9ddb97 search 3ms 2026-09-19T21:42:49
tc_578b2e71 search 3ms 2026-09-19T21:42:53
tc_e09d0cfb get_raw_output 64ms 2026-09-19T21:42:54
tc_5699f54a get_amcache 9ms 2026-09-19T21:42:54
tc_f2070e16 search 3ms 2026-09-19T21:42:56
tc_ae7ea66e search 10ms 2026-09-19T21:42:58
tc_32b5fac2 search 3ms 2026-09-19T21:43:00
tc_8bd084b2 search 3ms 2026-09-19T21:43:02
tc_1dc5ce50 get_userassist 1ms 2026-09-19T21:43:04
tc_587d944f search 3ms 2026-09-19T21:43:04
tc_730f592f search 3ms 2026-09-19T21:43:08
tc_d242a537 submit_finding 16ms 2026-09-19T21:43:10
tc_b081abb8 search 3ms 2026-09-19T21:43:15
tc_2b7fa20b get_raw_output 64ms 2026-09-19T21:43:17
tc_98e0af59 search 3ms 2026-09-19T21:43:22
tc_2786f70e parse_shellbags 1ms 2026-09-19T21:43:24
tc_604aefeb submit_finding 16ms 2026-09-19T21:43:30
tc_4c19325f parse_lnk_files 1ms 2026-09-19T21:43:32
tc_85945c45 search 3ms 2026-09-19T21:43:33
tc_c9e13e97 parse_jump_lists 1ms 2026-09-19T21:43:36
tc_3e80ffa1 parse_shellbags 1ms 2026-09-19T21:43:41
tc_77c48f35 search 3ms 2026-09-19T21:43:43
tc_9942ceea parse_srum 1ms 2026-09-19T21:43:46
tc_1eed7b25 get_raw_output 63ms 2026-09-19T21:43:47
tc_040b565f get_raw_output 63ms 2026-09-19T21:43:50
tc_3474214c search 3ms 2026-09-19T21:43:50
tc_51b51e2d submit_finding 16ms 2026-09-19T21:43:54
tc_cb37bb0f parse_lnk_files 1ms 2026-09-19T21:43:56
tc_ecbd8dfb search 3ms 2026-09-19T21:43:56
tc_e033e8cb parse_jump_lists 1ms 2026-09-19T21:44:01
tc_1229967f submit_finding 17ms 2026-09-19T21:44:02
tc_e6f4aaa8 search 4ms 2026-09-19T21:44:06
tc_92d8a94f parse_shimcache 1ms 2026-09-19T21:44:11
tc_0035806b submit_finding 15ms 2026-09-19T21:44:12
tc_ca9c7666 get_raw_output 64ms 2026-09-19T21:44:18
tc_14fc9169 search 3ms 2026-09-19T21:44:22
tc_de3363ad submit_finding 0ms 2026-09-19T21:44:23
tc_4b77286d parse_srum 1ms 2026-09-19T21:44:24
tc_91475666 search 5ms 2026-09-19T21:44:25
tc_8867f6ee get_userassist 1ms 2026-09-19T21:44:31
tc_60115f79 get_raw_output 63ms 2026-09-19T21:44:31
tc_ffe61ccd search 4ms 2026-09-19T21:44:36
tc_43f7a0d5 submit_finding 0ms 2026-09-19T21:44:37
tc_5bbbbc5a search 3ms 2026-09-19T21:44:40
tc_7a91029f search 3ms 2026-09-19T21:44:41
tc_841c13f8 get_raw_output 64ms 2026-09-19T21:44:45
tc_eee89db9 get_raw_output 63ms 2026-09-19T21:44:48
tc_dd8a23ea submit_finding 14ms 2026-09-19T21:44:50
tc_a350f8fe search 3ms 2026-09-19T21:44:50
tc_3bddfaac get_raw_output 64ms 2026-09-19T21:44:55
tc_046074f5 submit_finding 14ms 2026-09-19T21:44:59
tc_cae7a6de submit_finding 15ms 2026-09-19T21:44:59
tc_2495fc9d search 3ms 2026-09-19T21:45:05
tc_9ae0f4bc search 4ms 2026-09-19T21:45:09
tc_7c57706f track_progress 13ms 2026-09-19T21:45:11
tc_5e099fc1 search 3ms 2026-09-19T21:45:13
tc_09365854 get_investigation_summary 6ms 2026-09-19T21:45:14
tc_41188942 get_raw_output 63ms 2026-09-19T21:45:19
tc_72fc4f0e get_investigation_summary 5ms 2026-09-19T21:45:20
tc_6063d65d search 3ms 2026-09-19T21:45:27
tc_7ef0b7b3 open_case 32ms 2026-09-19T21:45:32
tc_607ab94d get_investigation_summary 7ms 2026-09-19T21:45:33
tc_f7427fee get_findings 2ms 2026-09-19T21:45:34
tc_93f5a259 search 3ms 2026-09-19T21:45:36
tc_20904043 get_findings 2ms 2026-09-19T21:45:37
tc_940c8e51 get_findings 2ms 2026-09-19T21:45:38
tc_5061f981 get_findings 2ms 2026-09-19T21:45:39
tc_815bbef1 get_source_stats 65ms 2026-09-19T21:45:41
tc_19c8eacc list_sources 3ms 2026-09-19T21:45:43
tc_ad21380b search 6ms 2026-09-19T21:45:45
tc_d2cf255b parse_prefetch 2ms 2026-09-19T21:45:47
tc_2ee07e6f parse_prefetch_detailed 1ms 2026-09-19T21:45:49
tc_c3554952 search 3ms 2026-09-19T21:45:50
tc_7a687675 parse_amcache 1ms 2026-09-19T21:45:51
tc_af9b9766 get_amcache 9ms 2026-09-19T21:45:53
tc_7947b66b parse_shimcache 1ms 2026-09-19T21:45:55
tc_ae40bdba parse_lnk_files 1ms 2026-09-19T21:45:57
tc_52e1bc06 submit_finding 16ms 2026-09-19T21:45:59
tc_4f59f7e7 parse_jump_lists 1ms 2026-09-19T21:45:59
tc_a3e159c7 parse_shellbags 1ms 2026-09-19T21:46:02
tc_d6be6a06 parse_srum 1ms 2026-09-19T21:46:04
tc_539b49c9 get_userassist 1ms 2026-09-19T21:46:07
tc_45faa15a search 3ms 2026-09-19T21:46:18
tc_8400541d search 3ms 2026-09-19T21:46:19
tc_f42b53c2 get_raw_output 66ms 2026-09-19T21:46:24
tc_bc599670 search 5ms 2026-09-19T21:46:25
tc_1543a5ba get_raw_output 64ms 2026-09-19T21:46:29
tc_57074c5c get_deleted_files 178ms 2026-09-19T21:46:35
tc_f6b24a60 search 4ms 2026-09-19T21:46:35
tc_24faaba7 find_file_staging._search(tsk.filelist) 5ms 2026-09-19T21:46:38
tc_23a1017e find_file_staging._search(ez.mft) 4ms 2026-09-19T21:46:38
tc_ab04574a find_file_staging._query(tsk.filelist) 36ms 2026-09-19T21:46:38
tc_733ccaef find_file_staging._query(ez.mft) 202ms 2026-09-19T21:46:38
tc_c407fd00 find_file_staging._search(ez.mft) 16ms 2026-09-19T21:46:38
tc_5d4ca50f find_file_staging._search(ez.mft) 4ms 2026-09-19T21:46:38
tc_4dcc0e5b find_file_staging 617ms 2026-09-19T21:46:38
tc_3112cb1c detect_timestomping 281ms 2026-09-19T21:46:44
tc_9d1f745c search 3ms 2026-09-19T21:46:46
tc_90a0f60c get_raw_output 63ms 2026-09-19T21:46:46
tc_186ef61b parse_browser_history 6384ms 2026-09-19T21:46:56
tc_25723b78 open_case 30ms 2026-09-19T21:46:56
tc_d611599a get_investigation_summary 7ms 2026-09-19T21:46:57
tc_015b1206 get_findings 1ms 2026-09-19T21:46:57
tc_1ba634ae search 3ms 2026-09-19T21:47:01
tc_f4b43d27 get_findings 2ms 2026-09-19T21:47:02
tc_c9a5db7a search 4ms 2026-09-19T21:47:04
tc_3f1ea4e0 search 6ms 2026-09-19T21:47:07
tc_fe68f117 get_findings 2ms 2026-09-19T21:47:07
tc_5271334f get_source_stats 65ms 2026-09-19T21:47:07
tc_33da233c get_findings 2ms 2026-09-19T21:47:09
tc_273ba745 search 3ms 2026-09-19T21:47:10
tc_3e487343 get_findings 2ms 2026-09-19T21:47:10
tc_2f6cc62c search 5ms 2026-09-19T21:47:13
tc_8de4f881 detect_timestomping 321ms 2026-09-19T21:47:13
tc_6a1e7c5e get_raw_output 63ms 2026-09-19T21:47:13
tc_5ae5e33d get_raw_output 64ms 2026-09-19T21:47:15
tc_571e4938 find_file_staging._search(tsk.filelist) 4ms 2026-09-19T21:47:15
tc_6987085b find_file_staging._search(ez.mft) 4ms 2026-09-19T21:47:15
tc_5aab8c4a find_file_staging._query(tsk.filelist) 36ms 2026-09-19T21:47:15
tc_1c1aa4be find_file_staging._query(ez.mft) 199ms 2026-09-19T21:47:15
tc_01c3ae53 find_file_staging._search(ez.mft) 16ms 2026-09-19T21:47:15
tc_5084bc46 find_file_staging._search(ez.mft) 4ms 2026-09-19T21:47:15
tc_dfcd6c5e find_file_staging 613ms 2026-09-19T21:47:15
tc_11f0e25c search 10ms 2026-09-19T21:47:17
tc_b4e9b74f search 26ms 2026-09-19T21:47:18
tc_7f077b5f search 3ms 2026-09-19T21:47:18
tc_164e7dab get_timeline 10ms 2026-09-19T21:47:20
tc_8d011d13 get_raw_output 64ms 2026-09-19T21:47:20
tc_1a6c4fd3 search 3ms 2026-09-19T21:47:23
tc_56ce6045 search 4ms 2026-09-19T21:47:23
tc_6eb4e1e4 search 4ms 2026-09-19T21:47:26
tc_57d3da0d search 9ms 2026-09-19T21:47:26
tc_afe95eca get_timeline 1ms 2026-09-19T21:47:30
tc_d65420ed get_timeline 2ms 2026-09-19T21:47:34
tc_8f640153 get_timeline 3ms 2026-09-19T21:47:43
tc_dfd77151 search 3ms 2026-09-19T21:47:48
tc_41d676b0 get_raw_output 64ms 2026-09-19T21:47:59
tc_ad666f72 search 3ms 2026-09-19T21:48:07
tc_2128481b get_raw_output 64ms 2026-09-19T21:48:13
tc_1c2718a8 search 3ms 2026-09-19T21:48:17
tc_eff9b3a0 search 2ms 2026-09-19T21:48:17
tc_e588893e search 3ms 2026-09-19T21:48:22
tc_1c2bdac6 get_raw_output 64ms 2026-09-19T21:48:28
tc_32cf352f search 3ms 2026-09-19T21:48:33
tc_2628546e search 3ms 2026-09-19T21:48:41
tc_fc460a93 search 2ms 2026-09-19T21:48:41
tc_51d99423 search 4ms 2026-09-19T21:48:46
tc_5f4ae714 bookmark_window 11ms 2026-09-19T21:48:49
tc_eb448e37 search 3ms 2026-09-19T21:48:58
tc_a80493ea search 3ms 2026-09-19T21:49:03
tc_ef7c3127 search 2ms 2026-09-19T21:49:03
tc_b22ad637 get_raw_output 63ms 2026-09-19T21:49:13
tc_4baa57b7 search 5ms 2026-09-19T21:49:15
tc_14c7b186 search 3ms 2026-09-19T21:49:15
tc_6fb4551d parse_usn_journal 2ms 2026-09-19T21:49:28
tc_2407e6ff search 3ms 2026-09-19T21:49:30
tc_9a61ba01 search 3ms 2026-09-19T21:49:30
tc_b9b922a9 get_raw_output 65ms 2026-09-19T21:49:34
tc_5c54b9b0 search 3ms 2026-09-19T21:49:34
tc_1234797c parse_mft 31ms 2026-09-19T21:49:36
tc_909daaff search 3ms 2026-09-19T21:49:38
tc_077e8bc8 search 3ms 2026-09-19T21:49:38
tc_bbf3101c query_registry_value 0ms 2026-09-19T21:49:47
tc_4bc101cd search 3ms 2026-09-19T21:49:49
tc_a3158a67 list_partitions 1ms 2026-09-19T21:49:55
tc_c562526a search 3ms 2026-09-19T21:49:56
tc_d4cd97a5 search 5ms 2026-09-19T21:50:04
tc_442b956a get_investigation_summary 88ms 2026-09-19T21:50:05
tc_bc564276 search 3ms 2026-09-19T21:50:05
tc_2a207ce7 list_sources 3ms 2026-09-19T21:50:10
tc_02c164b4 search 10ms 2026-09-19T21:50:14
tc_f2d031d7 search 3ms 2026-09-19T21:50:14
tc_fd21e7e4 bookmark_window 12ms 2026-09-19T21:50:27
tc_56e8ea59 search 3ms 2026-09-19T21:50:31
tc_007bbf7c search 3ms 2026-09-19T21:50:31
tc_203b9ed4 search 3ms 2026-09-19T21:50:40
tc_da53b590 search 3ms 2026-09-19T21:50:40
tc_6d60aded search 3ms 2026-09-19T21:50:47
tc_32219860 search 3ms 2026-09-19T21:50:47
tc_1be3ab9d search 3ms 2026-09-19T21:50:51
tc_d32234b0 search 3ms 2026-09-19T21:50:51
tc_8eeead5c search 3ms 2026-09-19T21:50:55
tc_5bc76622 search 3ms 2026-09-19T21:50:55
tc_a68a99b1 search 3ms 2026-09-19T21:50:59
tc_37fc8bc9 search 3ms 2026-09-19T21:50:59
tc_6169dcc7 search 4ms 2026-09-19T21:51:04
tc_179e0dd3 search 3ms 2026-09-19T21:51:04
tc_b6ef3643 search 3ms 2026-09-19T21:51:08
tc_17c21f57 search 3ms 2026-09-19T21:51:08
tc_1f833871 search 3ms 2026-09-19T21:51:13
tc_a31df51b search 3ms 2026-09-19T21:51:13
tc_c8202e6a search 4ms 2026-09-19T21:51:20
tc_4bb26f9e search 3ms 2026-09-19T21:51:20
tc_2e89a266 search 3ms 2026-09-19T21:51:27
tc_4c89ee87 search 3ms 2026-09-19T21:51:27
tc_49e93fc7 search 3ms 2026-09-19T21:51:39
tc_2c878163 search 3ms 2026-09-19T21:51:39
tc_d7b5c6d0 search 3ms 2026-09-19T21:51:53
tc_28949c24 search 3ms 2026-09-19T21:51:53
tc_b6a2a212 search 3ms 2026-09-19T21:52:03
tc_0f99964d search 2ms 2026-09-19T21:52:03
tc_8f73e36f search 3ms 2026-09-19T21:52:11
tc_76d5dd9c search 3ms 2026-09-19T21:52:11
tc_2948dca5 search 3ms 2026-09-19T21:52:22
tc_df1649e9 search 2ms 2026-09-19T21:52:22
tc_f2bcfd14 search 3ms 2026-09-19T21:52:30
tc_c804003c search 2ms 2026-09-19T21:52:30
tc_f60ff751 search 3ms 2026-09-19T21:52:37
tc_9536a893 search 2ms 2026-09-19T21:52:37
tc_d3b6aac8 search 3ms 2026-09-19T21:52:51
tc_e530735b search 2ms 2026-09-19T21:52:51
tc_48195850 search 3ms 2026-09-19T21:53:00
tc_1537fce0 search 3ms 2026-09-19T21:53:00
tc_0740dcc8 search 3ms 2026-09-19T21:53:11
tc_16e425ae search 3ms 2026-09-19T21:53:11
tc_dc03a914 search 3ms 2026-09-19T21:53:20
tc_45b37c1d search 3ms 2026-09-19T21:53:20
tc_92805b18 search 3ms 2026-09-19T21:53:29
tc_973e0725 search 3ms 2026-09-19T21:53:29
tc_621b05ab search 3ms 2026-09-19T21:53:39
tc_c6495915 search 3ms 2026-09-19T21:53:39
tc_cb1e9b89 search 3ms 2026-09-19T21:53:50
tc_355b60f3 search 3ms 2026-09-19T21:53:50
tc_075d7543 search 3ms 2026-09-19T21:54:06
tc_2874f9be search 2ms 2026-09-19T21:54:06
tc_f1651e0d get_investigation_summary 6ms 2026-09-19T21:54:07
tc_66e6ebf5 open_case 32ms 2026-09-19T21:54:09
tc_825d45c3 get_investigation_summary 7ms 2026-09-19T21:54:10
tc_95f9f98c get_findings 1ms 2026-09-19T21:54:10
tc_8d1ddc59 get_findings 2ms 2026-09-19T21:54:12
tc_7390cae7 get_source_stats 65ms 2026-09-19T21:54:12
tc_a70c4c67 get_findings 2ms 2026-09-19T21:54:15
tc_9c037749 get_bookmarks 2ms 2026-09-19T21:54:15
tc_38e4748a get_timeline 21ms 2026-09-19T21:54:16
tc_9658f34f list_sources 3ms 2026-09-19T21:54:21
tc_4ca85b3f open_case 33ms 2026-09-19T21:54:44
tc_03cfbdd3 reconstruct_execution_chains._query(volatility.pstree) 104ms 2026-09-19T21:54:46
tc_feecf90e reconstruct_execution_chains._query(volatility.cmdline) 13ms 2026-09-19T21:54:46
tc_b319772b find_file_staging._search(tsk.filelist) 15ms 2026-09-19T21:54:46
tc_7f04ba5a find_execution_evidence._query(ez.shimcache) 14ms 2026-09-19T21:54:46
tc_4c825180 find_execution_evidence 132ms 2026-09-19T21:54:46
tc_9d57a7d7 find_persistence_mechanisms._query(registry.system) 140ms 2026-09-19T21:54:46
tc_66aa2529 reconstruct_execution_chains._query(volatility.netscan) 15ms 2026-09-19T21:54:46
tc_79b5f492 find_file_staging._search(ez.mft) 12ms 2026-09-19T21:54:46
tc_974a3db8 find_defense_evasion._search(all) 168ms 2026-09-19T21:54:46
tc_39bed77d find_lateral_movement_indicators._search(all) 53ms 2026-09-19T21:54:46
tc_47b4b522 find_persistence_mechanisms._query(registry.software) 15ms 2026-09-19T21:54:46
tc_b9e33fd0 reconstruct_execution_chains._query(volatility.malfind) 8ms 2026-09-19T21:54:46
tc_698c3af9 find_defense_evasion._search(ez.mft) 8ms 2026-09-19T21:54:46
tc_52234a59 find_lateral_movement_indicators._search(all) 8ms 2026-09-19T21:54:46
tc_3cbc95ab reconstruct_execution_chains 194ms 2026-09-19T21:54:46
tc_2bf3335e find_persistence_mechanisms._query(volatility.svcscan) 8ms 2026-09-19T21:54:46
tc_a9a64a6d enrich_iocs 344ms 2026-09-19T21:54:46
tc_bcd3db4e find_defense_evasion._search(all) 115ms 2026-09-19T21:54:46
tc_e9a0f3ca find_suspicious_processes._query(volatility.malfind) 120ms 2026-09-19T21:54:46
tc_921bf013 find_suspicious_processes._query(volatility.cmdline) 14ms 2026-09-19T21:54:46
tc_f73ff190 find_defense_evasion._search(all) 24ms 2026-09-19T21:54:46
tc_e2320f74 find_persistence_mechanisms._search(all) 133ms 2026-09-19T21:54:46
tc_0496660f find_lateral_movement_indicators._search(all) 149ms 2026-09-19T21:54:46
tc_46e4d36a find_suspicious_processes._query(volatility.netscan) 10ms 2026-09-19T21:54:46
tc_effef866 find_defense_evasion._search(all) 11ms 2026-09-19T21:54:46
tc_bb43ad7c find_persistence_mechanisms._search(all) 10ms 2026-09-19T21:54:46
tc_c56e2efd find_lateral_movement_indicators._query(volatility.netscan) 8ms 2026-09-19T21:54:46
tc_3967fb1b find_defense_evasion 364ms 2026-09-19T21:54:46
tc_f77bc40c find_suspicious_processes._query(volatility.pstree) 9ms 2026-09-19T21:54:46
tc_8eed18dc find_persistence_mechanisms._query(ez.shimcache) 11ms 2026-09-19T21:54:46
tc_5b726fe8 find_suspicious_processes 191ms 2026-09-19T21:54:46
tc_a05eec0c find_lateral_movement_indicators._search(all) 12ms 2026-09-19T21:54:46
tc_4b94c570 find_persistence_mechanisms._search(all) 15ms 2026-09-19T21:54:46
tc_aa847178 find_lateral_movement_indicators._search(all) 7ms 2026-09-19T21:54:46
tc_ecba36b0 find_lateral_movement_indicators._search(all) 77ms 2026-09-19T21:54:46
tc_87ba2d81 find_lateral_movement_indicators 500ms 2026-09-19T21:54:46
tc_ad8218a2 find_file_staging._query(tsk.filelist) 586ms 2026-09-19T21:54:47
tc_918e74b5 assess_recovery._query(tsk.filelist) 653ms 2026-09-19T21:54:47
tc_23dffeb2 assess_recovery._query(ez.shimcache) 9ms 2026-09-19T21:54:47
tc_413f5ce0 assess_recovery 678ms 2026-09-19T21:54:47
tc_1bf52135 find_persistence_mechanisms._query(tsk.filelist) 501ms 2026-09-19T21:54:47
tc_e5780832 find_persistence_mechanisms 1000ms 2026-09-19T21:54:47
tc_ec6a7cc1 detect_timestomping 1445ms 2026-09-19T21:54:47
tc_1bfd5b35 find_file_staging._query(ez.mft) 670ms 2026-09-19T21:54:48
tc_9fdcbf5f find_file_staging._search(ez.mft) 17ms 2026-09-19T21:54:48
tc_7f07d4b6 find_file_staging._search(ez.mft) 4ms 2026-09-19T21:54:48
tc_dd061887 find_file_staging 1861ms 2026-09-19T21:54:48
tc_f9d95bd9 find_data_exfiltration_indicators._query(bulk.url) 1990ms 2026-09-19T21:54:48
tc_3b1cbb34 find_data_exfiltration_indicators._query(bulk.email) 10ms 2026-09-19T21:54:49
tc_9c2f7c51 find_data_exfiltration_indicators._query(bulk.domain) 83ms 2026-09-19T21:54:49
tc_145d53fc find_data_exfiltration_indicators._search(all) 25ms 2026-09-19T21:54:49
tc_79405887 find_data_exfiltration_indicators 3067ms 2026-09-19T21:54:49
tc_9729a5ae get_eventlog_anomalies 2ms 2026-09-19T21:54:52
tc_b0ed4ae6 analyze_execution_timeline._query(ez.shimcache) 9ms 2026-09-19T21:54:52
tc_f43a59bf analyze_execution_timeline 19ms 2026-09-19T21:54:52
tc_c90b7c6d correlate_across_sources 47ms 2026-09-19T21:54:52
tc_8cd50971 open_case 33ms 2026-09-19T21:55:03
tc_5d9c02c2 get_investigation_summary 7ms 2026-09-19T21:55:04
tc_10adcbc2 get_findings 2ms 2026-09-19T21:55:05
tc_cd587ff4 get_ioc_summary 533ms 2026-09-19T21:55:05
tc_0af51e65 get_raw_output 64ms 2026-09-19T21:55:07
tc_ab79129a get_raw_output 64ms 2026-09-19T21:55:07
tc_c7933651 get_raw_output 63ms 2026-09-19T21:55:08
tc_4dbfc4e1 get_raw_output 64ms 2026-09-19T21:55:10
tc_140d6293 get_raw_output 64ms 2026-09-19T21:55:10
tc_af118935 get_raw_output 64ms 2026-09-19T21:55:10
tc_01c63c10 get_raw_output 64ms 2026-09-19T21:55:12
tc_7593e367 get_raw_output 63ms 2026-09-19T21:55:13
tc_61649c1e get_raw_output 63ms 2026-09-19T21:55:13
tc_248b56b9 get_raw_output 63ms 2026-09-19T21:55:16
tc_7ccc8125 get_raw_output 63ms 2026-09-19T21:55:16
tc_6640c84f get_findings 2ms 2026-09-19T21:55:24
tc_d3a0bdf0 search 5ms 2026-09-19T21:55:34
tc_f0adf890 search 5ms 2026-09-19T21:55:34
tc_b70c1013 search 7ms 2026-09-19T21:55:34
tc_3c67cb16 search 6ms 2026-09-19T21:55:44
tc_ff13610e search 5ms 2026-09-19T21:55:44
tc_c808696d search 4ms 2026-09-19T21:55:44
tc_792dddd9 search 8ms 2026-09-19T21:55:51
tc_765cab7a search 4ms 2026-09-19T21:55:51
tc_050e7bb1 search 4ms 2026-09-19T21:55:51
tc_2f30d0d6 search 9ms 2026-09-19T21:56:02
tc_aa6036f3 search 4ms 2026-09-19T21:56:02
tc_5ac89e56 search 5ms 2026-09-19T21:56:02
tc_bf701527 get_raw_output 64ms 2026-09-19T21:56:16
tc_6a7ba516 get_raw_output 63ms 2026-09-19T21:56:16
tc_779f9069 get_raw_output 64ms 2026-09-19T21:56:27
tc_9719b5b2 get_raw_output 64ms 2026-09-19T21:56:27
tc_1e1c79ab get_findings 2ms 2026-09-19T21:56:42
tc_ee1db11f get_raw_output 64ms 2026-09-19T21:56:52
tc_88e1a276 search 4ms 2026-09-19T21:56:58
tc_0f6abcca search 5ms 2026-09-19T21:56:58
tc_b5ad908d search 4ms 2026-09-19T21:56:58
tc_d6dcb2c5 search 4ms 2026-09-19T21:57:05
tc_bc2a2a67 search 3ms 2026-09-19T21:57:05
tc_30971e17 search 53ms 2026-09-19T21:57:06
tc_3fd34e6a get_raw_output 63ms 2026-09-19T21:57:16
tc_45232d2e search 5ms 2026-09-19T21:57:16
tc_9bbd22bf get_findings 2ms 2026-09-19T21:57:29
tc_4ba58788 get_raw_output 64ms 2026-09-19T21:57:44
tc_d0cef62e search 4ms 2026-09-19T21:58:00
tc_722480c3 search 5ms 2026-09-19T21:58:00
tc_2c9f6733 search 4ms 2026-09-19T21:58:00
tc_08bad53a get_findings 1ms 2026-09-19T21:58:21
tc_3486f0b4 get_raw_output 63ms 2026-09-19T21:58:33
tc_e727ee71 search 5ms 2026-09-19T21:58:40
tc_1e4f83c3 search 5ms 2026-09-19T21:58:40
tc_69389711 search 4ms 2026-09-19T21:58:40
tc_91490c8c lookup_attack_technique 513ms 2026-09-19T21:58:55
tc_b2ea7fc6 lookup_attack_technique 0ms 2026-09-19T21:58:55
tc_397a9077 lookup_attack_technique 0ms 2026-09-19T21:58:55
tc_dc7d10eb lookup_attack_technique 0ms 2026-09-19T21:59:16
tc_92fca288 lookup_attack_technique 0ms 2026-09-19T21:59:16
tc_cd98a525 lookup_attack_technique 0ms 2026-09-19T21:59:16
tc_1b8e6c44 submit_finding 17ms 2026-09-19T21:59:31
tc_33ebcc77 submit_finding 15ms 2026-09-19T21:59:50
tc_adae1dff submit_finding 17ms 2026-09-19T22:00:01
tc_3c5aaa6f submit_finding 13ms 2026-09-19T22:00:15
tc_63b2a888 submit_finding 16ms 2026-09-19T22:00:28
tc_f8c1fff0 submit_finding 17ms 2026-09-19T22:00:38
tc_cfb8c077 track_progress 12ms 2026-09-19T22:00:48
tc_dc0367b3 get_investigation_summary 5ms 2026-09-19T22:00:54
tc_f424b597 get_source_stats 65ms 2026-09-19T22:01:00
tc_378bb9d7 search 4ms 2026-09-19T22:01:08
tc_caad7d6e search 5ms 2026-09-19T22:01:08
tc_fc0c1214 search 4ms 2026-09-19T22:01:22
tc_54c2cdc5 search 3ms 2026-09-19T22:01:22
tc_73369c93 search 4ms 2026-09-19T22:01:31
tc_0390cfeb search 10ms 2026-09-19T22:01:31
tc_86519fb9 search 6ms 2026-09-19T22:01:43
tc_624bcf64 search 8ms 2026-09-19T22:01:43
tc_159a8d92 submit_finding 0ms 2026-09-19T22:01:54
tc_6b052e1a search 6ms 2026-09-19T22:02:12
tc_a54a39c9 search 4ms 2026-09-19T22:02:21
tc_fdd44a8a submit_finding 16ms 2026-09-19T22:02:30
tc_e8be07ea submit_finding 15ms 2026-09-19T22:02:43
tc_4336106a submit_finding 16ms 2026-09-19T22:03:14
tc_12324089 get_investigation_summary 6ms 2026-09-19T22:03:26
tc_96fb315e get_findings 2ms 2026-09-19T22:03:40
tc_14b8ba38 get_findings 2ms 2026-09-19T22:04:03
tc_787bd59a get_findings 2ms 2026-09-19T22:04:11
tc_dc18f0da open_case 34ms 2026-09-19T22:04:18
tc_4194c940 get_investigation_summary 7ms 2026-09-19T22:04:18
tc_47e5376e get_findings 1ms 2026-09-19T22:04:18
tc_546d0eb3 get_source_stats 66ms 2026-09-19T22:04:20
tc_db6d439a get_bookmarks 3ms 2026-09-19T22:04:20
tc_c3973101 get_findings 2ms 2026-09-19T22:04:21
tc_9cf847eb search 4ms 2026-09-19T22:04:22
tc_28f349ce get_findings 2ms 2026-09-19T22:04:23
tc_cd8ebcf4 get_findings 2ms 2026-09-19T22:04:25
tc_8dd30e1f get_findings 1ms 2026-09-19T22:04:25
tc_c9c3bf82 get_findings 1ms 2026-09-19T22:04:25
tc_2cf2060b get_findings 1ms 2026-09-19T22:04:25
tc_c3b3cbe2 get_source_stats 65ms 2026-09-19T22:04:27
tc_63d33209 get_ioc_summary 538ms 2026-09-19T22:04:30
tc_85499871 search 3ms 2026-09-19T22:04:34
tc_86602a85 search 2ms 2026-09-19T22:04:34
tc_95be56d7 search 3ms 2026-09-19T22:04:41
tc_e842b44b search 3ms 2026-09-19T22:04:41
tc_b8b1bc74 search 4ms 2026-09-19T22:04:45
tc_a7937bc2 search 2ms 2026-09-19T22:04:45
tc_4b8a0a6f search 3ms 2026-09-19T22:04:48
tc_ce474306 search 2ms 2026-09-19T22:04:48
tc_a7db3e95 parse_prefetch 1ms 2026-09-19T22:04:54
tc_8afe8de8 get_userassist 1ms 2026-09-19T22:04:54
tc_9c0aded3 get_amcache 7ms 2026-09-19T22:05:00
tc_82e68ddc parse_browser_history 6310ms 2026-09-19T22:05:06
tc_09f35dda search 3ms 2026-09-19T22:05:13
tc_bf76e2c3 get_findings 2ms 2026-09-19T22:05:19
tc_e00a3fa2 get_investigation_summary 5ms 2026-09-19T22:05:22
tc_57192c0e search 4ms 2026-09-19T22:05:30
tc_c293e30c update_finding 3ms 2026-09-19T22:05:42
tc_3330201d search 3ms 2026-09-19T22:05:55
tc_6ca93074 update_finding 2ms 2026-09-19T22:06:04
tc_fc6a5a81 update_finding 2ms 2026-09-19T22:06:19
tc_0c3245e5 search 3ms 2026-09-19T22:06:23
tc_93d3bde2 search 3ms 2026-09-19T22:06:29
tc_bdc2142a search 4ms 2026-09-19T22:06:33
tc_0752845f search 3ms 2026-09-19T22:06:37
tc_8d3786ca get_deleted_files 205ms 2026-09-19T22:06:44
tc_c26a22cc search 3ms 2026-09-19T22:06:48
tc_510c1c4a get_raw_output 63ms 2026-09-19T22:06:53
tc_949faa5f search 3ms 2026-09-19T22:06:58
tc_ce24349a search 3ms 2026-09-19T22:07:03
tc_a712ee26 search 3ms 2026-09-19T22:07:08
tc_b0fa2794 submit_finding 16ms 2026-09-19T22:07:15
tc_2bc82306 search 3ms 2026-09-19T22:07:22
tc_8164071b search 3ms 2026-09-19T22:07:29
tc_954a3a90 search 3ms 2026-09-19T22:07:34
tc_39d8933c search 3ms 2026-09-19T22:07:40
tc_bff79ca9 search 3ms 2026-09-19T22:07:47
tc_200367a0 search 3ms 2026-09-19T22:07:59
tc_9b1fcfef search 4ms 2026-09-19T22:08:06
tc_c12ea667 submit_finding 15ms 2026-09-19T22:08:13
tc_48863c82 search 3ms 2026-09-19T22:08:21
tc_9f8986b6 submit_finding 16ms 2026-09-19T22:08:39
tc_7a414bab search 3ms 2026-09-19T22:08:46
tc_f666e4be search 5ms 2026-09-19T22:08:59
tc_66e6f917 search 3ms 2026-09-19T22:09:10
tc_6bdc8cfc open_case 33ms 2026-09-19T22:09:17
tc_079629e7 get_investigation_summary 7ms 2026-09-19T22:09:18
tc_914eb02b get_findings 1ms 2026-09-19T22:09:18
tc_def93f32 get_findings 2ms 2026-09-19T22:09:19
tc_ce8b82af get_findings 2ms 2026-09-19T22:09:20
tc_b497d15a get_ioc_summary 509ms 2026-09-19T22:09:22
tc_9ee7c124 get_source_stats 65ms 2026-09-19T22:09:22
tc_e3a4121d get_findings 2ms 2026-09-19T22:09:24
tc_8e9e9ac3 search 4ms 2026-09-19T22:09:26
tc_a7ab4442 get_bookmarks 2ms 2026-09-19T22:09:27
tc_f362019e get_deleted_files 197ms 2026-09-19T22:09:28
tc_b3615dc1 get_source_stats 65ms 2026-09-19T22:09:30
tc_b5259dca list_sources 3ms 2026-09-19T22:09:32
tc_3ceeb42f search 7ms 2026-09-19T22:09:34
tc_f11c66d4 get_raw_output 64ms 2026-09-19T22:09:39
tc_75611d6a get_raw_output 63ms 2026-09-19T22:09:39
tc_f9797a53 search 8ms 2026-09-19T22:09:42
tc_1ecfde81 search 6ms 2026-09-19T22:09:45
tc_cf505b0e search 2ms 2026-09-19T22:09:45
tc_3e3d54a6 search 3ms 2026-09-19T22:09:50
tc_6291ff16 search 2ms 2026-09-19T22:09:50
tc_1d351535 get_raw_output 63ms 2026-09-19T22:10:02
tc_03f82fa4 get_raw_output 62ms 2026-09-19T22:10:02
tc_3759d08a get_raw_output 63ms 2026-09-19T22:10:11
tc_dd17aefd get_raw_output 61ms 2026-09-19T22:10:11
tc_14b168f2 get_raw_output 63ms 2026-09-19T22:10:24
tc_6eec02cb get_raw_output 62ms 2026-09-19T22:10:24
tc_fa288f70 search 4ms 2026-09-19T22:10:27
tc_d34728d9 search 3ms 2026-09-19T22:10:27
tc_17e8c9f5 get_raw_output 63ms 2026-09-19T22:10:34
tc_aabe2629 get_raw_output 63ms 2026-09-19T22:10:34
tc_618d2238 get_raw_output 63ms 2026-09-19T22:10:40
tc_64326f96 get_raw_output 62ms 2026-09-19T22:10:40
tc_a5c7507a get_raw_output 63ms 2026-09-19T22:10:44
tc_9edc7247 get_raw_output 62ms 2026-09-19T22:10:44
tc_db226c47 get_raw_output 64ms 2026-09-19T22:10:47
tc_1016831a search 3ms 2026-09-19T22:10:51
tc_abbbbe12 search 3ms 2026-09-19T22:10:51
tc_339f76d5 search 3ms 2026-09-19T22:10:55
tc_101e492b search 4ms 2026-09-19T22:10:55
tc_43bb01fa parse_browser_history 6245ms 2026-09-19T22:11:10
tc_3a050215 parse_prefetch 1ms 2026-09-19T22:11:10
tc_4316cd2c get_amcache 8ms 2026-09-19T22:11:14
tc_c2cb3449 get_userassist 1ms 2026-09-19T22:11:14
tc_324a12fa get_raw_output 63ms 2026-09-19T22:11:21
tc_47ae279e get_raw_output 63ms 2026-09-19T22:11:26
tc_df7d6c2d search 3ms 2026-09-19T22:11:30
tc_e740dd6b search 5ms 2026-09-19T22:11:35
tc_b2809f80 search 3ms 2026-09-19T22:11:41
tc_a794d9bd get_findings 2ms 2026-09-19T22:11:46
tc_6c9fb061 search 7ms 2026-09-19T22:11:51
tc_118ab7d4 get_findings 2ms 2026-09-19T22:11:56
tc_e4128b79 get_findings 2ms 2026-09-19T22:12:01
tc_55406229 get_findings 2ms 2026-09-19T22:12:06
tc_f31c3b8f get_findings 2ms 2026-09-19T22:12:11
tc_4df0d117 get_findings 2ms 2026-09-19T22:12:16
tc_0d5ff540 get_findings 2ms 2026-09-19T22:12:22
tc_8fffae3a get_findings 2ms 2026-09-19T22:12:29
tc_4fbb283f get_findings 2ms 2026-09-19T22:12:40
tc_6cbf4487 get_findings 2ms 2026-09-19T22:12:49
tc_f05fb3cc get_findings 2ms 2026-09-19T22:12:54
tc_72b1d87c get_findings 2ms 2026-09-19T22:13:06
tc_6a5abaae get_findings 2ms 2026-09-19T22:13:13
tc_20df6f0b open_case 34ms 2026-09-19T22:13:21
tc_07408b4f get_investigation_summary 8ms 2026-09-19T22:13:22
tc_34f11d78 get_findings 2ms 2026-09-19T22:13:22
tc_b9680033 get_findings 2ms 2026-09-19T22:13:23
tc_d2bff024 get_raw_output 65ms 2026-09-19T22:13:25
tc_4752a972 get_findings 2ms 2026-09-19T22:13:26
tc_5d15bf03 get_findings 2ms 2026-09-19T22:13:28
tc_52830658 get_findings 2ms 2026-09-19T22:13:30
tc_71928b26 get_source_stats 65ms 2026-09-19T22:13:32
tc_1b7dd46b get_bookmarks 2ms 2026-09-19T22:13:32
tc_0e145002 get_ioc_summary 534ms 2026-09-19T22:13:37
tc_aa6a7dc3 get_findings 2ms 2026-09-19T22:13:42
tc_ab281f40 search 5ms 2026-09-19T22:13:49
tc_62b3ec5a search 4ms 2026-09-19T22:13:49
tc_42248282 get_raw_output 63ms 2026-09-19T22:13:56
tc_4193dfdf search 3ms 2026-09-19T22:13:59
tc_513dec52 get_raw_output 63ms 2026-09-19T22:14:02
tc_ecef10c5 search 4ms 2026-09-19T22:14:06
tc_45c58511 search 3ms 2026-09-19T22:14:12
tc_f5ac9359 search 5ms 2026-09-19T22:14:17
tc_8056568d search 3ms 2026-09-19T22:14:17
tc_a3ca8fc8 search 4ms 2026-09-19T22:14:17
tc_2a672c80 get_raw_output 64ms 2026-09-19T22:14:22
tc_15a4a662 get_raw_output 63ms 2026-09-19T22:14:23
tc_4e16a16b get_raw_output 63ms 2026-09-19T22:14:26
tc_9933f20a get_raw_output 64ms 2026-09-19T22:14:26
tc_cac3cbea update_finding 3ms 2026-09-19T22:14:31
tc_f82eed2b search 4ms 2026-09-19T22:14:37
tc_f03dca9b search 4ms 2026-09-19T22:14:45
tc_09d28945 get_raw_output 64ms 2026-09-19T22:14:55
tc_85aa2ac8 get_raw_output 64ms 2026-09-19T22:15:11
tc_312e4f63 get_deleted_files 227ms 2026-09-19T22:15:19
tc_034139c4 get_amcache 7ms 2026-09-19T22:15:23
tc_b414e2cc get_userassist 1ms 2026-09-19T22:15:23
tc_850f1d13 parse_browser_history 6192ms 2026-09-19T22:15:34
tc_4a8a109a parse_prefetch 2ms 2026-09-19T22:15:37
tc_4247740c search 4ms 2026-09-19T22:15:43
tc_f8086fbd get_raw_output 66ms 2026-09-19T22:15:48
tc_5fa5d6ed search 3ms 2026-09-19T22:15:54
tc_c804c326 get_raw_output 63ms 2026-09-19T22:16:07
tc_95a2f5ca search 4ms 2026-09-19T22:16:11
tc_1d1a385e get_raw_output 52ms 2026-09-19T22:16:15
tc_dd745209 get_findings 2ms 2026-09-19T22:16:27
tc_81eed50a update_finding 2ms 2026-09-19T22:16:34
tc_71623427 search 4ms 2026-09-19T22:16:42
tc_a787feb5 get_raw_output 23ms 2026-09-19T22:17:00
tc_7b0f380b search 4ms 2026-09-19T22:17:14
tc_d987d178 get_raw_output 64ms 2026-09-19T22:17:33
tc_4f25693f search 3ms 2026-09-19T22:17:43
tc_0ec9a458 get_raw_output 64ms 2026-09-19T22:17:47
tc_a8b69bbf get_raw_output 64ms 2026-09-19T22:17:52
tc_76bfc6fb get_raw_output 64ms 2026-09-19T22:17:58
tc_58b87548 get_raw_output 64ms 2026-09-19T22:18:03
tc_2f28f51e get_raw_output 65ms 2026-09-19T22:18:10
tc_81db3785 search 3ms 2026-09-19T22:18:17
tc_511c5fec get_investigation_summary 6ms 2026-09-19T22:18:17
tc_3eee32c5 open_case 35ms 2026-09-19T22:18:20
tc_b34e4eb1 get_findings 3ms 2026-09-19T22:18:21
tc_0c31efa6 get_investigation_summary 6ms 2026-09-19T22:18:21
tc_fb1c44f4 get_findings 2ms 2026-09-19T22:18:23
tc_fb71a6de list_sources 3ms 2026-09-19T22:18:23
tc_478c4784 get_findings 2ms 2026-09-19T22:18:25
tc_6d0a9049 get_timeline 21ms 2026-09-19T22:18:25
tc_a0935015 get_timeline 1ms 2026-09-19T22:18:34
tc_c506b440 get_timeline 2ms 2026-09-19T22:18:44
tc_e7d56fa2 get_timeline 3ms 2026-09-19T22:18:50
tc_eb165f48 open_case 34ms 2026-09-19T22:19:16
tc_c537ffc9 deduplicate_findings 65ms 2026-09-19T22:19:17
tc_4cc2ca89 deduplicate_findings 225ms 2026-09-19T22:19:21
tc_6d5a05a7 search 19ms 2026-09-19T22:19:23
tc_f4299bff search 11ms 2026-09-19T22:19:23
tc_5ed1dfa6 search 16ms 2026-09-19T22:19:23
tc_0b5b0a6f search 20ms 2026-09-19T22:19:23
tc_6cf198ae search 17ms 2026-09-19T22:19:23
tc_217fa2cd search 22ms 2026-09-19T22:19:23
tc_0f37f94a search 16ms 2026-09-19T22:19:25
tc_959e1acc search 23ms 2026-09-19T22:19:25
tc_72f18760 search 19ms 2026-09-19T22:19:25
tc_971ae2f7 search 22ms 2026-09-19T22:19:25
tc_bc3f4e7a search 23ms 2026-09-19T22:19:25
tc_09269f39 search 3ms 2026-09-19T22:19:30
tc_3a49a31c find_file_staging._search(tsk.filelist) 7ms 2026-09-19T22:19:32
tc_d0e93b6f find_file_staging._search(ez.mft) 5ms 2026-09-19T22:19:32
tc_b9b2ba1b get_raw_output 72ms 2026-09-19T22:19:32
tc_0d0c1e3c get_source_stats 97ms 2026-09-19T22:19:32
tc_9173726a find_file_staging._query(tsk.filelist) 102ms 2026-09-19T22:19:32
tc_21d0fdef detect_timestomping 527ms 2026-09-19T22:19:33
tc_28d16bf4 find_file_staging._query(ez.mft) 386ms 2026-09-19T22:19:33
tc_08e573fd find_file_staging._search(ez.mft) 16ms 2026-09-19T22:19:33
tc_719b67dd find_file_staging._search(ez.mft) 4ms 2026-09-19T22:19:33
tc_5fd71fa1 find_file_staging 885ms 2026-09-19T22:19:33
tc_61f2650d correlate_across_sources 128ms 2026-09-19T22:19:36
tc_f44771b1 correlate_across_sources 142ms 2026-09-19T22:19:36
tc_9b686730 open_case 35ms 2026-09-19T22:19:48
tc_ac7fb8b1 get_findings 2ms 2026-09-19T22:19:48
tc_136fa16d get_investigation_summary 6ms 2026-09-19T22:19:50
tc_46b0c6f3 get_findings 2ms 2026-09-19T22:19:51
tc_491f8a62 get_findings 2ms 2026-09-19T22:19:52
tc_8f342cca get_findings 2ms 2026-09-19T22:19:53
tc_f3445916 search 5ms 2026-09-19T22:19:56
tc_e5867992 search 4ms 2026-09-19T22:19:56
tc_9b480295 search 2ms 2026-09-19T22:19:56
tc_2d56add1 search 3ms 2026-09-19T22:20:00
tc_043a421b search 3ms 2026-09-19T22:20:00
tc_711df95c search 6ms 2026-09-19T22:20:00
tc_6c391d84 search 4ms 2026-09-19T22:20:04
tc_6b9f84c6 search 4ms 2026-09-19T22:20:04
tc_662f3585 search 4ms 2026-09-19T22:20:09
tc_0ebabb1d search 3ms 2026-09-19T22:20:09
tc_61668d5e search 5ms 2026-09-19T22:20:16
tc_3745221c search 2ms 2026-09-19T22:20:16
tc_af6e59b0 get_raw_output 64ms 2026-09-19T22:20:21
tc_3b83ff83 search 3ms 2026-09-19T22:20:25
tc_89b307f8 search 2ms 2026-09-19T22:20:25
tc_0ef29d1f search 3ms 2026-09-19T22:20:29
tc_0759194b search 4ms 2026-09-19T22:20:29
tc_9db144a4 get_raw_output 64ms 2026-09-19T22:20:40
tc_874f06f0 get_raw_output 63ms 2026-09-19T22:20:40
tc_987f8fb9 audit_evidence_coverage 445ms 2026-09-19T22:20:49
tc_742a8b76 audit_tool_coverage 2ms 2026-09-19T22:20:49
tc_9e8b6339 deduplicate_findings 52ms 2026-09-19T22:21:01
tc_d2c9c305 search 4ms 2026-09-19T22:21:13
tc_1a5cf4a3 search 3ms 2026-09-19T22:21:13
tc_f294fd1e get_raw_output 63ms 2026-09-19T22:21:24
tc_740e6981 check_finalize_readiness 5ms 2026-09-19T22:21:30
tc_16380b40 update_finding 16ms 2026-09-19T22:21:42
tc_4c8321c8 update_finding 3ms 2026-09-19T22:21:56
tc_99affb86 search 4ms 2026-09-19T22:22:03
tc_411c5ee3 search 4ms 2026-09-19T22:22:10
tc_3cc9cd5f search 3ms 2026-09-19T22:22:23
tc_7d42c68c search 3ms 2026-09-19T22:22:31
tc_7a8f4db0 get_raw_output 63ms 2026-09-19T22:22:36
tc_f6ab390f get_raw_output 63ms 2026-09-19T22:22:44
tc_5789c705 update_finding 14ms 2026-09-19T22:22:58
tc_859c7345 update_finding 13ms 2026-09-19T22:23:05
tc_3b3321ed track_progress 14ms 2026-09-19T22:23:17
tc_dfeb0a32 check_finalize_readiness 5ms 2026-09-19T22:23:23
tc_210a566f get_investigation_summary 6ms 2026-09-19T22:23:34
tc_bf833ef1 check_finalize_readiness 6ms 2026-09-19T22:23:34
tc_6b923ce8 open_case 14ms 2026-09-19T22:23:38
tc_a4a0ff45 get_findings 3ms 2026-09-19T22:23:39
tc_57adf069 get_investigation_summary 6ms 2026-09-19T22:23:39
tc_f1b38967 get_ioc_summary 612ms 2026-09-19T22:23:40
tc_71e10c38 get_bookmarks 2ms 2026-09-19T22:23:40
tc_1748e166 get_source_stats 65ms 2026-09-19T22:23:40
tc_d58e83c2 get_findings 2ms 2026-09-19T22:23:42
tc_2556be7b get_findings 2ms 2026-09-19T22:23:43
tc_773d29b8 get_findings 2ms 2026-09-19T22:23:48
tc_9fd7d463 get_findings 2ms 2026-09-19T22:23:52
tc_17705f59 check_finalize_readiness 5ms 2026-09-19T22:23:52
tc_ee9607a0 get_findings 2ms 2026-09-19T22:23:55
tc_a28cdba8 get_findings 2ms 2026-09-19T22:24:01
tc_a8267be6 audit_evidence_coverage 387ms 2026-09-19T22:24:07
tc_387ffef3 audit_tool_coverage 2ms 2026-09-19T22:24:07
tc_82a3543d submit_narrative 13ms 2026-09-19T22:24:45
tc_f037a4b1 check_finalize_readiness 5ms 2026-09-19T22:24:48

Each finding traces back to the specific tool calls that produced the supporting evidence.

Sensitive "Secret Project" data copied to removable USB media (RM#1) 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_6f08c30a
66ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_168fd4d4
64ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Secret Project Data", "regex": false, "sourc...
tc_7474aab9
5ms
4
list_partitions
tc_0525c3c4
1ms
Carved IOCs Reveal Personal Gmail Account and Cloud Storage as Exfiltration Destination 5 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "iaman.informant.personal", "regex": false, "...
tc_27f7fa15
4ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "iaman", "regex": false, "source": "bulk.url"...
tc_85461772
4ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "iaman.informant", "regex": false, "source": ...
tc_a43f4b87
4ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_b24fc511
64ms
5
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "iaman.informant.personal", "regex": false, "...
tc_d4d7ee85
3ms
Multi-session CD-R (RM#3) "IAMAN CD" contains Secret Project Data burned across 9 sessions with file deletion between sessions 7 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_2b7fa20b
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_374aea29
65ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_3bddfaac
64ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "IAMAN CD", "regex": false, "source": null, "...
tc_8279b429
3ms
5
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_841c13f8
64ms
6
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "cd burning", "regex": false, "source": null,...
tc_c3554952
3ms
7
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_eee89db9
63ms
Cross-System Confirmation: 17 Masqueraded Secret Project Files Identical Across RM#2 USB, RM#3 Optical Disc, and PC Staging Areas 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_779f9069
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
4
search
{ "exclude_sources": null, "max_results": 30, "queries": [ "masquerade", "winter_storm", "my_favorite", "super_bowl",...
tc_d3a0bdf0
5ms
Additional Accounts Created by Informant: admin11, ITechTeam, temporary (Insider-Created, Not External Backdoors) 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_bf701527
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
Anti-forensic tools (Eraser, CCleaner) installed and executed to destroy evidence 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_1047dd83
63ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "CCleaner", "regex": false, "source": null, "...
tc_d68dcab6
4ms
3
get_timeline
{ "limit": 50, "t_end": "2015-03-25T16:00:00", "t_start": "2015-03-25T14:00:00" }
tc_1a5ed6b8
3ms
Network share access to secured_drive containing Secret Project Data 1 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_168fd4d4
64ms
17 Deleted Files with Masqueraded Extensions Concealing Office Documents on Removable Media RM2 9 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_09675af9
63ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "a_gift_from_you", "regex": false, "source": ...
tc_1f40e615
3ms
3
get_raw_output
{ "after_id": 17638, "limit": 5, "source_name": "tsk.timeline" }
tc_4d9146b0
48ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "IAMAN", "regex": false, "source": null, "t_e...
tc_5c930e3e
4ms
5
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_6f08c30a
66ms
6
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "winter_storm", "regex": false, "source": "ts...
tc_a14fcba2
3ms
7
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "$OrphanFiles", "regex": false, "source": "ts...
tc_aac2ecfc
3ms
8
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_b28d4ee0
53ms
9
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "TECHNI", "regex": false, "source": "tsk.file...
tc_d1f7799a
2ms
Secret Project Data files on RM#1 USB drive with original filenames 3 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "RM#1", "regex": false, "source": "tsk.timeli...
tc_93744d44
4ms
2
get_raw_output
{ "after_id": 3, "limit": 5, "source_name": "tsk.timeline" }
tc_06a69604
9ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "secret_project", "regex": false, "source": "...
tc_09c0e8f0
3ms
Web browsing activity related to cloud storage and anti-forensic research 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_1047dd83
63ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": [ "dropbox", "googledrive", "drive.google", "mega.nz", "wetr...
tc_20cf5945
5ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Google Drive", "regex": false, "source": nul...
tc_381045b3
5ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "CCleaner", "regex": false, "source": null, "...
tc_d68dcab6
4ms
Windows Event Logs reveal account creation and privilege escalation during data leakage 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_b8900834
64ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "evtx", "regex": false, "source": null, "t_en...
tc_c1de7c30
3ms
Anti-forensic research and tool acquisition intent 2 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "anti-forensic", "regex": false, "source": nu...
tc_7384cf6b
4ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "how to leak a secret", "regex": false, "sour...
tc_e7d906c5
4ms
RM#3 optical disc files use extension masquerading identical to RM#2 USB drive 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_374aea29
65ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "winter_storm", "regex": false, "source": nul...
tc_6241434f
3ms
Google Drive Sync Client Installed and Configured - Exfiltration to iaman.informant.personal@gmail.com (Circumstantial) 4 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "googledrivesync.exe", "Google Drive sync", "snapshot.db",...
tc_88e1a276
4ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "snapshot.db", "sync_config.db", "user_default" ], "query"...
tc_d6dcb2c5
4ms
3
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "iaman.informant.personal@gmail.com" ], "query": "", "rege...
tc_bc2a2a67
3ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
Anti-Forensic Cleanup: Eraser and CCleaner Used to Destroy Evidence 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "composite.recovery" }
tc_61649c1e
63ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "4624", "4625", "logon", "logoff" ], "query": "", "regex":...
tc_69389711
4ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_779f9069
64ms
D: Drive (BD-RE Optical) Staging Area Used as Intermediate Step Before CD Burn 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
3
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "10.11.11.128", "secured_drive", "network share" ], "query...
tc_5ac89e56
5ms
RM#1 'Authorized USB' Drive Used for Both Legitimate and Exfiltration Purposes 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_779f9069
64ms
Network Share Access Corroborated by Multiple Evidence Sources 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "10.11.11.128", "secured_drive", "network share" ], "query...
tc_5ac89e56
5ms
Files deleted to Recycle Bin and beyond on 2015-03-24 3 refs
1
get_timeline
{ "limit": 50, "t_end": "2015-03-24T21:30:00", "t_start": "2015-03-24T13:00:00" }
tc_be50d804
2ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_6f08c30a
66ms
3
get_deleted_files
tc_31f1a5cc
238ms
User account "informant" was the primary active account during data leakage 3 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "Google Drive", "regex": false, "source": nul...
tc_381045b3
5ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_b8900834
64ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_1047dd83
63ms
Document Metadata and File Attribution - NIST Informant Source System 4 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "exiftool.metadata" }
tc_8ddabb81
65ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.fsstat" }
tc_8ca52543
54ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "iaman", "regex": false, "source": "bulk.emai...
tc_0d049f99
4ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_b28d4ee0
53ms
IOCs carved from RM#3 optical disc reveal document metadata and email addresses 6 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3", "regex": false, "source": null, "t_end...
tc_0ec0902e
4ms
2
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3_type3", "regex": false, "source": "bulk....
tc_d989d590
4ms
3
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3_type3", "regex": false, "source": "bulk....
tc_f1947365
3ms
4
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3_type3", "regex": false, "source": "bulk....
tc_2b35012e
3ms
5
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3_type3", "regex": false, "source": "bulk....
tc_0cdff4d3
3ms
6
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "rm3_type3", "regex": false, "source": "bulk....
tc_cc9a6481
3ms
RM#3 optical disc volume label "IAMAN CD" links to informant identity and burn timeline 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_374aea29
65ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_09675af9
63ms
CD Burning Software: Windows Built-in IMAPI Used for Multi-Session RM#3 Disc 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": [ "Burn", "admin11\\AppData\\Local\\Microsoft\\Windows\\Burn...
tc_a54a39c9
4ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
Additional NIST Email Persona: spy.conspirator@nist.gov Found in Bulk Extractor Output 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "spy.conspirator", "regex": false, "source": ...
tc_ce24349a
3ms
Outlook Offline Storage Table (OST) File Contains NIST Email Account Data 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "iaman.informant@nist.gov.ost", "regex": fals...
tc_9b1fcfef
4ms
Additional NIST Contacts Found in Email Metadata: 645mtgs@xchange.nist.gov and wei.yu@nist.gov 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "645mtgs@xchange.nist.gov", "regex": false, "...
tc_48863c82
3ms
Timeline of data leakage events (2015-03-22 to 2015-03-25) 6 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_09675af9
63ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_168fd4d4
64ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_1047dd83
63ms
4
get_timeline
{ "limit": 50, "t_end": "2015-03-24T21:30:00", "t_start": "2015-03-24T13:00:00" }
tc_be50d804
2ms
5
get_timeline
{ "limit": 50, "t_end": "2015-03-25T16:00:00", "t_start": "2015-03-25T14:00:00" }
tc_1a5ed6b8
3ms
6
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_b8900834
64ms
No steganography detected in image files 1 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "stegdetect" }
tc_d52039bf
63ms
RM#2 volume label IAMAN $_@ links device to informant identity 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.fsstat" }
tc_e793e9ff
63ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_09675af9
63ms
Complete Chronological Sequence of Events: Network Share Access Through Anti-Forensic Cleanup 6 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.sam" }
tc_bf701527
64ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_9719b5b2
64ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_6a7ba516
63ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "tsk.masquerade" }
tc_779f9069
64ms
5
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "googledrivesync.exe", "Google Drive sync", "snapshot.db",...
tc_88e1a276
4ms
6
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "composite.recovery" }
tc_61649c1e
63ms

Tool Call Details

Copied to clipboard