Investigation Dashboard
The attack timeline spans 2015-02-15 to 2015-03-25. The earliest activity was Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2) (2015-02-15). The investigation subsequently uncovered Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3); Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft. The most recent activity was Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Executed After Exfiltration (2015-03-25).
- Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)
- Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft
- Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)
-
Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)
2015-02-15T16:51:38 — 2015-03-24T10:00:18
-
Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft
2015-03-22T14:33:13 — 2015-03-25T15:29:08
-
Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)
2015-02-15T16:51:38 — 2015-03-24T20:57:03
| Case ID | ndlc |
| Evidence Root | /evidence |
| Report Generated | 2026-09-19T21:01:34 |
| Investigation Start | 2026-09-19T19:55:01 |
| Investigation End | 2026-09-19T21:01:30 |
| Total Processing | 2926.1s |
| Audit Log | /home/mulder/.mulder/cases/ndlc.audit.jsonl |
Evidence Hashes
sha256sum <file>| File | SHA-256 | Size |
|---|---|---|
| cfreds_2015_data_leakage_pc.E01 | e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 | 2.0 GB |
| cfreds_2015_data_leakage_rm1.E01 | a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 | 74.6 MB |
| cfreds_2015_data_leakage_rm2.E01 | 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 | 243.2 MB |
| cfreds_2015_data_leakage_rm3_type3.E01 | 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b | 90.2 MB |
Investigation Report
Insider Threat Data Exfiltration Investigation — CFREDS 2015 Data Leakage Case
Background
This investigation was initiated to examine a suspected insider threat data exfiltration incident involving a departing employee at a government organization. The subject, identified through converging forensic evidence as "Iaman Informant" (username: informant, email: iaman.informant@nist.gov), is alleged to have systematically copied classified "Secret Project Data" from a secured network file share to multiple removable media devices and potentially to cloud storage, employing a variety of anti-forensic techniques to conceal the theft.
The forensic examination encompassed four disk images: the subject's workstation (cfreds_2015_data_leakage_pc.E01, hostname "informant-PC," running Windows 7 64-bit in the Eastern Standard Time zone), and three removable media devices — RM1 (cfreds_2015_data_leakage_rm1.E01, a 4GB USB device with dual partitions), RM2 (cfreds_2015_data_leakage_rm2.E01, a FAT32 USB device), and RM3 (cfreds_2015_data_leakage_rm3_type3.E01, a CD-R disc). Analysis drew upon 25 indexed evidence sources spanning 16 distinct artifact types including filesystem analysis (Sleuthkit), registry examination (RegRipper, python-registry), event log analysis (Chainsaw, Hayabusa), MFT parsing (EZTools), bulk content extraction (bulk_extractor), string analysis, EXIF metadata extraction, optical media session reconstruction, and file masquerade detection.
The source PC was connected to an internal network on subnet 10.11.11.0/24, where the subject accessed a secured network share at \\10.11.11.128\secured_drive. The PC's own DHCP-assigned address was 10.11.11.129. The investigation identified the "informant" user account (RID 1000, login count 10, created 2015-03-22 at 14:33:54 UTC) as the sole actor in the exfiltration campaign. Three additional local accounts — admin11 (RID 1001), ITechTeam (RID 1002), and temporary (RID 1003) — were created by the informant account within a two-minute window on the same day, but none of these accounts accessed the Secret Project Data or performed any substantive activity relevant to the data theft.
Incident Timeline
The exfiltration campaign unfolded over approximately five weeks, from February 15 through March 25, 2015, and can be divided into five distinct operational phases.
Phase 1 — Initial Data Copy (February 15, 2015). The earliest evidence of exfiltration dates to Sunday, February 15, 2015. At 16:51:38 UTC, the Secret Project Data directory structure was created on RM1's exFAT partition (volume label "Authorized USB," volume serial 5c75-4d3e). Between 16:52:08 and 16:52:20 UTC, five classified Office documents were copied to this partition with their original filenames intact: [secret_project]_design_concept.ppt, [secret_project]_detailed_design.pptx, [secret_project]_revised_points.ppt, [secret_project]_detailed_proposal.docx, and [secret_project]_proposal.docx. These files had modification dates ranging from December 4, 2014 to January 23, 2015, consistent with active project documents. Twelve days later, on February 27, 2015, at 17:20:18 UTC, the root "Secret Project Data" directory on this partition was deleted, though the files themselves remained accessible in subdirectories.
Phase 2 — Workstation Setup and Network Reconnaissance (March 22, 2015). On Sunday, March 22, the subject logged into the PC for the first time at 14:33:13 UTC and began setting up the environment. Internet Explorer 11 was installed at 15:12:32 UTC, and Chrome was configured. At 14:52:22 UTC, shellbag artifacts record the first access to the \\10.11.11.128\secured_drive network share, where the subject navigated through the complete directory tree including Secret Project Data, Common Data, and Past Projects subdirectories. Between 15:51:54 and 15:53:01 UTC, the subject created three additional local accounts (admin11, ITechTeam, temporary) and added admin11 and ITechTeam to the local Administrators group. Security event logs (Event ID 4720/4732, confirmed via Chainsaw and Hayabusa) definitively attribute these creations to the informant account's SID (S-1-5-21-2425377081-3129163575-2985601102-1000).
Phase 3 — Document Access, Research, and Staging (March 23, 2015). The subject's activity intensified on Monday, March 23. Cover image files (24 photographs including amalfi.bmp, barn.gif, boudicca.bmp, cactus.png, and others) were created on RM2's FAT32 partition between 16:55:17 and 16:55:37 UTC, establishing an innocuous appearance for the media. Chrome was launched at 17:26:50 UTC, followed by browsing to Bing and Google. The subject searched for "secret" using Windows Explorer's search bar at 18:40:17 UTC (recorded in the WordWheelQuery registry key). Secret project files were opened using their respective Office applications — Excel opened (secret_project)_pricing_decision.xlsx at 20:26:50 UTC, and PowerPoint opened [secret_project]_final_meeting.pptx at 20:27:33 UTC. Google Drive was installed at approximately 20:01:53 UTC, with ShimCache confirming googledrivesync.exe was executed. Critically, the subject conducted extensive browser research during this period into topics including "anti-forensic+tools" (85 search instances), "ccleaner" (65 instances), "eraser" (51 instances), "external+device+and+forensics" (65 instances), "cd+burning+method" (64 instances), "information+leakage+cases" (47 instances), and "DLP DRM" (90 instances). This research directly preceded and informed every subsequent anti-forensic action.
Phase 4 — Multi-Media Exfiltration and CD-R Burning (March 24, 2015). On Tuesday, March 24, the subject executed the primary exfiltration operation. Between 09:59:26 and 10:00:18 UTC, seventeen masqueraded copies of the Secret Project Data documents were created on both RM1's FAT32 partition and RM2, organized into five directories mirroring the corporate share structure (design, pricing decision, progress, proposal, technical review). Every document was renamed with a false file extension to disguise its Office format — for example, [secret_project]detailed_proposal.docx became "a_gift_from_you.gif" (35,226,880 bytes), and [secret_project]_detailed_design.pptx became "winter_whether_advisory.zip" (16,381,123 bytes). The USBSTOR driver was last written at 13:37:59 UTC, and shellbag evidence records the subject browsing E:\RM#1\Secret Project Data at 13:38:31 UTC and the D: drive directories (de, tr, pd, prop, prog) between 19:47:48 and 20:44:18 UTC. The subject saved Resignation_Letter(Iaman_Informant).docx at 18:48:40 UTC.
Between 20:54:16 and 20:57:03 UTC, the subject burned data to the CD-R (RM3, volume label "IAMAN CD") in nine UDF VAT sessions. The disc preserves evidence of iterative concealment refinement: sessions -7 through -3 used full directory names matching the corporate share structure; session -1 used abbreviated names (de, pd, prog, prop, tr); and the final session (0) deleted all data directories, leaving only three stock Windows 7 sample photographs (Koala.jpg, Penguins.jpg, Tulips.jpg) as cover content. All seventeen masqueraded documents were subsequently deleted from RM1's FAT32 partition and RM2, leaving only orphaned file system entries.
Phase 5 — Anti-Forensic Cleanup and Departure (March 25, 2015). On Wednesday, March 25, the subject executed the final phase of the operation. Outlook was used at 14:41:03 UTC for email activity. At 14:50:14 UTC, the Eraser 6.2.0.2962 installer was run from the Desktop\Download directory, followed by the CCleaner v5.04 installer (ccsetup504.exe) at 14:57:56 UTC. Eraser was executed at 15:12:28 UTC for secure file deletion, and CCleaner64.exe was executed at 15:15:50 UTC for system trace cleaning. Google Drive sync was then launched at 15:21:30 UTC — notably after the anti-forensic cleanup, raising the possibility that the subject cleaned traces first and then synced remaining data to the cloud. WINWORD.EXE was used at 15:24:48 UTC (the subject's fourth run) to finalize the resignation letter, which was converted to XPS format at 15:28:47 UTC. The last RecentDocs registry write occurred at 15:29:08 UTC, marking the final recorded activity on the system. Google Drive's sync_config.db, cacerts, and snapshot.db files were all found deleted, consistent with Eraser's secure deletion capability having been used to destroy cloud synchronization evidence.
Key Findings
The investigation produced 23 findings, of which 3 are critical severity, 9 are high severity, 5 are medium severity, and the remainder are informational. The findings are organized below by operational category.
Data Collection and Exfiltration. The core of the incident is the confirmed exfiltration of 17 classified Office documents — collectively titled "Secret Project Data" — from the network share at \\10.11.11.128\secured_drive to three separate removable media devices. The documents encompassed design specifications (PPT, PPTX), proposals (DOCX), pricing decisions (XLSX), progress reports (DOCX), and technical reviews (DOCX, PPTX, OLE). RM1's exFAT partition contained original-name copies dating to February 15, 2015. RM1's FAT32 partition, RM2, and RM3 all contained byte-identical masqueraded copies created on March 24, 2015. Cross-media verification confirmed that file sizes matched exactly across all three media — for example, a_gift_from_you.gif was consistently 35,226,880 bytes (the true [secret_project]_detailed_proposal.docx), and winter_whether_advisory.zip was consistently 16,381,123 bytes (the true [secret_project]_detailed_design.pptx). The same three email addresses embedded within the document content — Eric_P._Lauer@omb.eop.gov, wayne.longman@att.net, and mmun@loc.gov — appeared at proportional disc offsets on both RM2 and RM3, providing independent confirmation of byte-identical content across media.
File Extension Masquerading. All 17 exfiltrated documents were systematically renamed with false file extensions across all three media devices. OLE-format documents (PPT, XLS) were given extensions such as .amr, .db, .avi, and .svg, while OOXML-format documents (DOCX, PPTX, XLSX) were given extensions including .zip, .7z, .jpg, .png, .one, .gif, and .txt. The filenames themselves were changed to innocuous personal-sounding names (winter_storm, my_favorite_cars, diary_#1d, landscape, a_gift_from_you). Sleuthkit masquerade detection confirmed the mismatch between file signatures and extensions. This technique maps to MITRE ATT&CK T1036.008 (Masquerading: Match Legitimate Name or Location).
Multi-Layered Anti-Forensic Concealment. The subject employed at least five distinct anti-forensic techniques. First, file extension masquerading as described above. Second, systematic deletion of all exfiltrated documents from all removable media after copying. Third, multi-session CD-R burning exploiting UDF VAT to progressively obscure and ultimately "delete" data on write-once media — though the subject apparently did not understand that UDF's Virtual Allocation Table preserves all previous generations on write-once discs. Fourth, placement of cover content (personal photographs on RM1/RM2 and stock Windows 7 sample photos on RM3) to make media appear innocuous upon casual inspection. Fifth, execution of dedicated anti-forensic tools — Eraser for secure file deletion and CCleaner for system trace cleaning — on the final day of activity.
Dual-Partition USB Structure. RM1 was configured with two distinct partitions to enable plausible deniability. The first partition (exFAT, labeled "Authorized USB") contained Secret Project Data files with their original names, appearing as a legitimate work device. The second partition (FAT32, labeled "IAMAN $_@") contained the masqueraded copies in a directory structure mirroring the corporate share, all of which were subsequently deleted. If the USB device was inspected casually, only the first "Authorized USB" partition would be readily visible.
Potential Cloud Exfiltration. Google Drive was installed on March 23 and last launched at 15:21:30 UTC on March 25 — six minutes after CCleaner was executed. The timing sequence (anti-forensic cleanup followed by cloud sync) suggests the subject may have synced documents to Google Drive as a supplementary exfiltration vector. However, the destruction of all Google Drive configuration files (sync_config.db, cacerts, snapshot.db) by Eraser means the investigation cannot definitively confirm what, if any, data was uploaded. Apple iCloud was also installed (icloudsetup.exe appeared in UserAssist), though no definitive evidence of iCloud data synchronization was found. These findings are assessed at medium severity with inference-level confidence.
Potential Co-Conspirator Contact. Bulk extractor recovered an Outlook contact entry for "spy" with email address spy.conspirator@nist.gov from the PC's disk image. The provocative naming convention mirrors the subject's own email naming pattern. However, this finding is assessed at inference confidence: only one evidence source supports it, no email message content between the two addresses was recovered, and no evidence indicates Secret Project Data was transmitted via email. The exfiltration pathway appears to have been exclusively through removable media and potentially cloud storage.
Negative Finding: No Encryption or Steganography. Analysis across all three removable media devices found no evidence of encrypted containers (TrueCrypt, VeraCrypt, BitLocker) or steganographic tools or content. Cover images contained genuine, unmodified EXIF metadata. The subject's anti-forensic techniques were limited to the five categories described above.
Threat Intelligence and Attribution
This incident presents a textbook insider threat profile: a privileged user with legitimate access to sensitive data who exploits that access for unauthorized data exfiltration prior to departure. The attribution to the "informant" user account is confirmed with high confidence based on multiple independent evidence streams. The user's account (RID 1000, login count 10) was the only account that accessed the Secret Project Data via the network share, the only account whose shellbag artifacts reference the removable media devices, and the only account under which the anti-forensic tools were installed and executed. The password hint "IAMAN" directly ties the user account to the volume labels on RM2 ("IAMAN $_@") and RM3 ("IAMAN CD").
The subject's premeditation is extensively documented through browser search history recovered by bulk_extractor. The subject researched "information+leakage+cases," "how+to+leak+a+secret," "intellectual+property+theft," and "data+leakage+methods" before executing the campaign. The subject then researched the specific tools and techniques subsequently employed: anti-forensic tools, CCleaner, Eraser, CD burning methods, cloud storage options, and data recovery counter-measures. The subject also demonstrated forensic investigation awareness, researching "e-mail+investigation," "Forensic+Email+Investigation," "what+is+windows+system+artifacts," "windows+event+logs," and "external+device+and+forensics" — indicating a deliberate attempt to understand and evade forensic investigation. Each search topic maps directly to an action taken during the campaign.
No evidence links this incident to external threat actors or organized campaigns. The tradecraft — while showing deliberate effort — contains fundamental operational security failures, most notably the use of UDF write-once media for concealment (which preserves rather than destroys data), the failure to thoroughly clean registry shellbag artifacts, and the retention of browser search history in unallocated disk space despite running CCleaner. The operational pattern is consistent with a motivated but technically unsophisticated insider acting independently, with the possible involvement of the spy.conspirator@nist.gov contact whose role, if any, remains undetermined.
Impact Assessment
The scope of this incident is significant. Seventeen classified Office documents collectively comprising the organization's "Secret Project Data" portfolio — including design specifications, detailed proposals, pricing decisions, progress reports, and technical review materials — were exfiltrated to three separate physical media devices and potentially to cloud storage. The total volume of exfiltrated data across the 17 documents exceeds 135 megabytes, with individual files ranging from 27,414 bytes to 35,226,880 bytes. The documents contain content referencing government entities including the Office of Management and Budget (Eric_P._Lauer@omb.eop.gov), the Library of Congress (mmun@loc.gov), and external contacts (wayne.longman@att.net), indicating sensitive inter-agency or partner content.
The creation of redundant copies across three physically separate media — two USB devices and one CD-R — represents a deliberate strategy to ensure the data survived confiscation of any single device. The potential cloud exfiltration via Google Drive introduces the possibility that the data exists in an additional, uncontrolled location. The subject's destruction of Google Drive synchronization evidence means the full scope of cloud-based data exposure cannot be determined from available evidence.
Only one system — the subject's workstation informant-PC — was directly compromised. However, the compromised data originated from the network share at \\10.11.11.128\secured_drive, meaning the exposure extends to all Secret Project Data stored on that share. The subject's legitimate credentials (iaman@nist.gov, iaman.informant@nist.gov) were used throughout; no credential theft or privilege escalation beyond the subject's existing access was necessary or observed. The three additional accounts created by the subject (admin11, ITechTeam, temporary) did not access any sensitive data and appear to have been diversionary or experimental in nature.
The creation and saving of Resignation_Letter_(Iaman_Informant).docx and its XPS conversion on the final day of activity, combined with the anti-forensic cleanup sequence, strongly indicate the subject intended this to be their last day at the organization. The business impact extends beyond data loss to potential competitive harm, intellectual property theft, and regulatory compliance violations, depending on the classification and contractual protections governing the Secret Project Data.
Immediate Tactical Containment
- Disable the "informant" user account (iaman.informant@nist.gov, iaman@nist.gov, RID 1000) across all organizational systems including Active Directory, email, VPN, and remote access services immediately.
- Disable the three accounts created by the subject — admin11 (RID 1001), ITechTeam (RID 1002), and temporary (RID 1003) — on informant-PC and verify they do not exist on any domain controllers.
- Isolate the workstation informant-PC (IP 10.11.11.129) from the network pending full forensic preservation.
- Revoke all access to the network share \\10.11.11.128\secured_drive for the informant account and audit current access control lists to identify any other accounts with access that may be associated with the subject.
- Seize and forensically preserve all three removable media devices: RM1 (USB, volume labels "Authorized USB" and "IAMAN $@"), RM2 (USB, volume label "IAMAN $@", Volume ID 0xb4d85399), and RM3 (CD-R, volume label "IAMAN CD"). Maintain chain of custody.
- Initiate a Google Workspace administrative hold on the Google Drive account associated with iaman.informant.personal@gmail.com and request preservation of all synced content and access logs.
- Block the email address spy.conspirator@nist.gov and place the associated account under monitoring pending determination of their involvement.
- Issue credential reset for all accounts that had access to \\10.11.11.128\secured_drive\Secret Project Data to prevent potential credential sharing.
- Preserve all event logs on the file server at 10.11.11.128, particularly SMB access logs covering the period February 15 through March 25, 2015.
Strategic Remediation
The subject accessed the full Secret Project Data directory tree on the network share at \\10.11.11.128\secured_drive without triggering any data loss prevention alert, despite the data's classified status. This indicates the absence or misconfiguration of Data Loss Prevention (DLP) controls on the file server. The subject's own research into "DLP DRM" (90 search instances) suggests awareness that such controls might exist and a desire to understand them. Implementing content-aware DLP monitoring on the secured_drive share — with rules that detect bulk file access, file copying to removable media, and access from accounts with pending departures — would have generated an alert during the initial February 15 exfiltration or during the systematic March 24 copy operation.
The subject downloaded, installed, and executed two anti-forensic tools (Eraser 6.2.0.2962 and CCleaner v5.04) from the Desktop\Download directory without any application whitelisting or endpoint detection response. No alerts were generated when the subject installed Eraser (which requires .NET 4.0 installation), CCleaner, or Google Drive on a workstation that presumably should have had controlled software installation policies. Implementing application whitelisting or endpoint detection and response (EDR) with rules to flag known anti-forensic and data wiping tools — specifically including Eraser.exe, CCleaner64.exe, and ccsetup504.exe — would have detected the cleanup phase of this operation in real time.
The subject copied approximately 135 megabytes of classified data to two USB devices and one CD-R over a period of five weeks without any removable media access controls intervening. The USBSTOR driver loaded successfully at 13:37:59 UTC on March 24, and the CD-R was burned with nine sessions between 20:54 and 20:57 UTC the same day. Implementing a removable media policy that requires encryption, logging, and administrative approval for USB and optical media write operations — or disabling USB mass storage and CD/DVD burning entirely for users without a documented business need — would have blocked the primary exfiltration vector (T1052.001).
The subject's browser search history reveals extensive research into "how+to+leak+a+secret," "anti-forensic+tools," "data+leakage+methods," and "intellectual+property+theft" totaling hundreds of search instances, none of which generated any user behavior analytics alert. Deploying a User and Entity Behavior Analytics (UEBA) solution with rules that flag searches for data exfiltration methods, anti-forensic tools, and intellectual property theft — particularly when correlated with HR data indicating pending departure — would have identified the subject's intent well before the exfiltration was executed.
The subject maintained unmonitored access to a Google Drive personal account (iaman.informant.personal@gmail.com) and Apple iCloud, installing synchronization clients on the workstation. The post-cleanup timing of the Google Drive sync launch at 15:21:30 UTC suggests potential cloud exfiltration, yet no cloud access security broker (CASB) or web filtering system flagged the personal cloud storage usage. Restricting personal cloud storage synchronization clients on corporate endpoints and monitoring for their installation via endpoint management would have addressed the potential cloud exfiltration vector (T1567.002).
Conclusion
This investigation conclusively establishes that user "Iaman Informant" (iaman.informant@nist.gov) conducted a premeditated, multi-stage data exfiltration campaign targeting classified Secret Project Data from the organization's secured network file share. The following conclusions address each investigation question:
Q1. What systems were compromised? One workstation was directly involved: informant-PC (Windows 7 64-bit, IP 10.11.11.129). The data originated from the network file share at \\10.11.11.128\secured_drive. No evidence of compromise to other systems was identified.
Q2. How did the attacker gain initial access? This was an insider threat scenario. The subject used legitimate credentials (iaman.informant@nist.gov, account RID 1000) with authorized access to the network share. No external intrusion, credential theft, or privilege escalation was required or observed.
Q3. What lateral movement occurred? N/A. The subject operated from a single workstation and accessed the network share using authorized SMB connectivity. No lateral movement to additional systems was detected. The three accounts created by the subject (admin11, ITechTeam, temporary) were not used for lateral movement.
Q4. What persistence mechanisms were installed? N/A in the traditional malware sense. However, the subject created three local accounts on informant-PC (admin11, ITechTeam, temporary), two of which were added to the Administrators group. These accounts could have served as persistence mechanisms for continued access, though none were used for data access.
Q5. Was data exfiltrated, and if so, what and how much? Yes. Seventeen classified Office documents from the Secret Project Data portfolio were exfiltrated to three separate removable media devices (two USB drives and one CD-R), totaling over 135 megabytes across five content categories: design, pricing decision, progress, proposal, and technical review. Potential additional exfiltration via Google Drive cloud storage is suspected but cannot be confirmed due to anti-forensic destruction of synchronization evidence.
Q6. What is the full timeline of the incident? The incident spanned February 15 to March 25, 2015. Phase 1 (Feb 15): Initial data copy to RM1 exFAT. Phase 2 (Mar 22): PC setup, network share access, account creation. Phase 3 (Mar 23): Document access, anti-forensic research, cloud tool installation. Phase 4 (Mar 24): Multi-media masqueraded exfiltration to RM1 FAT32, RM2, and RM3 CD-R; resignation letter drafted. Phase 5 (Mar 25): Anti-forensic tool execution (Eraser, CCleaner), Google Drive sync, resignation letter finalized.
Q7. What is the total scope and business impact? The entire Secret Project Data portfolio was exfiltrated, including documents containing references to government officials (OMB, Library of Congress) and external contacts. Three physically separate copies ensure data survival even if one or two devices are recovered. The potential cloud exfiltration via Google Drive means the data may exist in additional uncontrolled locations. The business impact includes potential loss of competitive advantage, intellectual property theft, regulatory compliance violations, and reputational harm.
Q8. What are the recommended remediation actions? The five strategic recommendations above address the specific root causes identified in this investigation: absence of DLP controls on the file share, lack of application whitelisting or EDR to detect anti-forensic tools, unrestricted removable media access, absence of user behavior analytics to detect pre-exfiltration research patterns, and unmonitored personal cloud storage access from corporate endpoints. Immediate tactical containment requires disabling all associated accounts, isolating the workstation, seizing removable media, and preserving Google Drive and file server logs.
Attack Timeline
Findings
Corporate "Secret Project Data" was exfiltrated from the network share \10.11.11.128\secured_drive to multiple removable media devices by user "informant" (Iaman Informant, iaman.informant@nist.gov):
RM1 (Authorized USB, exFAT, Volume Serial: 5c75-4d3e):
Contains complete Secret Project Data with original filenames in two copies:
- Secret Project Data/Secret Project Data/design/ (3 PPT/PPTX files)
- Secret Project Data/Secret Project Data/proposal/ (2 DOCX files + deleted temp ~$ecret_project]_proposal.docx)
- RM#1/ mirror with same files
Timeline: Files accessed on 2015-02-15 16:52 UTC (access/birth timestamps), modified dates range from 2014-12-04 to 2015-01-23.
RM2 (IAMAN $_@, FAT32, Volume ID: 0xb4d85399):
Contains same data but deliberately disguised with false filenames and extensions (see masquerading finding). All 17 files are deleted orphans, created 2015-03-24 09:59-10:00 UTC. Additional ~24 deleted image files (amalfi.bmp, barn.gif, cactus.png, etc.) created 2015-03-23 16:55 UTC appear to be cover images.
The RM2 folder structure (design, PRICIN~1, progress, proposal, TECHNI~1) maps directly to the network share categories: design, pricing decision, progress, proposal, technical review. File sizes prove byte-for-byte copies:
- winter_storm.amr (14,547,968) = [secret_project]_revised_points.ppt (14,547,968)
- winter_whether_advisory.zip (16,381,123) = [secret_project]_detailed_design.pptx (16,381,123)
- a_gift_from_you.gif (35,226,880) = [secret_project]_detailed_proposal.docx (35,226,880)
- landscape.png (6,484,502) = [secret_project]_proposal.docx (6,484,502)
Evidence Chain
The user responsible for the data exfiltration has been identified as "Iaman Informant" based on converging evidence:
User identity:
- PC username: "informant" (Users/informant profile)
- Email: iaman.informant@nist.gov (from Outlook OST file references on PC)
- Also: iaman@nist.gov (BASIC authentication references)
- USB volume label: "IAMAN $_@" (FAT32 volume on RM2)
- CD volume label: "IAMAN CD" (optical media RM3)
Resignation letter:
- RecentDocs shows "Resignation_Letter_(Iaman_Informant).docx" as the most recently accessed document (MRU position 8)
- Also converted to XPS: "Resignation_Letter_(Iaman_Informant).xps" (MRU position 14)
- OpenSavePidlMRU confirms both files were saved: Resignation_Letter_(Iaman_Informant).docx (2015-03-24 18:48:40) and .xps (2015-03-25 15:28:33)
- WINWORD.EXE (4 runs) and XPS viewer (1 run) execution confirms document editing
Embedded email addresses in documents on RM2/RM3:
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget)
- wayne.longman@att.net (personal contact embedded in documents)
- mmun@loc.gov (Library of Congress)
Search activity:
- WordWheelQuery shows the user searched for "secret" on the PC (2015-03-23 18:40:17)
The combination of a resignation letter, systematic access to sensitive corporate data via network share, deliberate file disguising, exfiltration to multiple removable media, and subsequent anti-forensic cleanup constitutes a classic insider threat data theft scenario by a departing employee.
Evidence Chain
File size analysis, masquerade detection, and document metadata confirm that the SAME 17 Office documents containing Secret Project Data were exfiltrated to three separate removable media devices, creating redundant copies for distribution or safekeeping.
Cross-Media File Size Verification (5 sources independently confirm):
Four files can be traced from the original network share (\\10.11.11.128\secured_drive) through all three media:
| Original Document | Size | RM1 exFAT | RM1 FAT32 | RM2 | RM3 |
|---|---|---|---|---|---|
| [secret_project]_detailed_proposal.docx | 35,226,880 | ✓ original | a_gift_from_you.gif | a_gift_from_you.gif | /prop/a_gift_from_you.gif |
| [secret_project]_proposal.docx | 6,484,502 | ✓ original | landscape.png | landscape.png | /prop/landscape.png |
| [secret_project]_detailed_design.pptx | 16,381,123 | ✓ original | winter_whether_advisory.zip | winter_whether_advisory.zip | /de/winter_whether_advisory.zip |
| [secret_project]_revised_points.ppt | 14,547,968 | ✓ original | winter_storm.amr | winter_storm.amr | /de/winter_storm.amr |
All 17 masqueraded files have byte-identical sizes across RM1 (FAT32 partition), RM2, and RM3.
Email Address Convergence Across Media:
The same three embedded email addresses appear in documents on RM2 AND RM3, confirming identical document content:
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget)
- wayne.longman@att.net (personal contact)
- mmun@loc.gov (Library of Congress)
Volume Label Attribution:
- RM1 FAT32 partition: "IAMAN $@"
- RM2: "IAMAN $@" (same label as RM1 FAT32)
- RM3: "IAMAN CD"
- PC user password hint: "IAMAN"
Directory Structure Evolution Across Media (anti-forensic refinement):
- RM1 exFAT: Original names (design/, proposal/)
- RM1 FAT32: Full category names (design/, PRICIN~1/, progress/, proposal/, TECHNI~1/)
- RM2: Identical to RM1 FAT32
- RM3 sessions -7 to -3: Full names (design/, pricing decision/, progress/, proposal/, technical review/)
- RM3 session -1: Abbreviated (de/, pd/, prog/, prop/, tr/)
- RM3 session 0: All deleted, replaced with stock photos
This progressive directory name obfuscation reveals the suspect iteratively refining their concealment strategy across media.
Timeline of Multi-Media Exfiltration:
1. 2015-02-15: First copy to RM1 exFAT (original filenames)
2. 2015-03-24 09:59-10:00: Masqueraded copies to RM1 FAT32 and RM2 (deleted after)
3. 2015-03-24 20:54-20:57: Burned to RM3 CD-R with 9 session iterations
Evidence Chain
The SAME 17 Office documents containing Secret Project Data were disguised with false file extensions on all three removable media devices (RM1 FAT32 partition, RM2, and RM3 CD-R). This was a systematic anti-forensic technique applied consistently across all exfiltration media.
Masquerade Scheme (identical across RM1 FAT32, RM2, RM3):
design/ directory:
- winter_storm.amr → Actually OLE (14,547,968 bytes) = [secret_project]_revised_points.ppt
- winter_whether_advisory.zip → Actually PPTX (16,381,123 bytes) = [secret_project]_detailed_design.pptx
PRICIN~1/ (pricing decision) directory:
- my_favorite_cars.db → Actually OLE (1,260,544 bytes)
- my_favorite_movies.7z → Actually XLSX (100,078 bytes)
- new_years_day.jpg → Actually XLSX (10,237,535 bytes)
- super_bowl.avi → Actually OLE (10,289,152 bytes)
progress/ directory:
- my_friends.svg → Actually OLE (58,368 bytes)
- my_smartphone.png → Actually DOCX (4,440,235 bytes)
- new_year_calendar.one → Actually DOCX (27,414 bytes)
proposal/ directory:
- a_gift_from_you.gif → Actually DOCX (35,226,880 bytes) = [secret_project]_detailed_proposal.docx
- landscape.png → Actually DOCX (6,484,502 bytes) = [secret_project]_proposal.docx
TECHNI~1/ (technical review) directory:
- diary_#1d.txt → DOCX; diary_#1p.txt → PPTX; diary_#2d.txt → DOCX; diary_#2p.txt → OLE; diary_#3d.txt → OLE; diary_#3p.txt → OLE
Cross-media confirmation: File sizes are byte-identical across all three media. The same false filenames and extensions were used consistently. On RM3 CD-R, the multiple VAT sessions show the user first used full directory names (design, pricing decision, etc.) then abbreviated (de, pd, etc.).
Evidence Chain
All 17 masqueraded Office documents were deleted on EVERY removable media device after being copied, demonstrating systematic anti-forensic cleanup across the entire exfiltration campaign:
RM1 FAT32 partition: All 17 masqueraded documents are now orphaned entries (under $OrphanFiles). 22 cover image files also deleted. The exFAT partition's root "Secret Project Data" directory was also deleted (mtime: 2015-02-27).
RM2 (FAT32): All 17 masqueraded documents are deleted orphan files. 24 cover image files (amalfi.bmp, barn.gif, boudicca.bmp, cactus.png, etc.) also deleted. Timeline shows cover images existed first → deleted → disguised project files copied → project files deleted — at least two rounds of intentional staging and cleanup.
RM3 CD-R: All document directories marked as deleted in the final UDF VAT session. Only 3 stock Windows 7 sample photos (Koala.jpg, Penguins.jpg, Tulips.jpg) remain active. However, the write-once nature of UDF means deleted data remains physically on the disc.
Deletion timeline:
1. 2015-02-27: Root "Secret Project Data" directory on RM1 exFAT deleted
2. 2015-03-23 ~16:55: Cover images placed on RM2
3. 2015-03-24 09:59-10:00: Masqueraded files created on RM1 FAT32 and RM2
4. After creation: All files deleted from RM1 FAT32 and RM2
5. 2015-03-24 20:54-20:57: Files burned to RM3 in multiple sessions, then deleted in final session
6. 2015-03-25 15:12-15:16: Eraser and CCleaner executed on PC to destroy remaining traces
Evidence Chain
The "informant" user account on the source PC (cfreds_2015_data_leakage_pc.E01) has extensive shellbag evidence tying this user to browsing the USB device contents and the source network share:
Network Share Access (data source):
- \10.11.11.128\secured_drive\Secret Project Data — accessed 2015-03-22 14:52:22, with subdirectories for design, final, pricing decision, proposal, progress, technical review, Common Data, Past Projects
- File V:\Secret Project Data also accessed (alternate drive letter)
USB Device Access (exfiltration destination):
- E:\RM#1\Secret Project Data — accessed 2015-03-24 13:38:31
- E:\RM#1\Secret Project Data\design — accessed 2015-03-24 13:38:52
- E:\Secret Project Data (including all subdirectories: design, pricing decision, progress, proposal, technical review) — accessed 2015-03-24 13:57-14:01
- E:\Secret Project Data\design\winter_whether_advisory.zip [16381123] — the user specifically opened the masqueraded file and explored its ppt\ subdirectory, confirming awareness of the file's true PPTX content
Second Partition Access:
- D:\de, D:\tr, D:\pd, D:\prop, D:\prog — accessed 2015-03-24 19:47-20:41 (abbreviated versions of the FAT32 partition directories)
- D:\de\winter_whether_advisory.zip [16381123] — same file size as the masqueraded PPTX
USBSTOR driver loaded: 2015-03-24 13:37:59 UTC
User Identity:
- Email: iaman.informant@nist.gov (found in Outlook profile data on PC)
- The FAT32 partition volume label "IAMAN $_@" contains the user's "IAMAN" identifier
Evidence Chain
User "informant" accessed a secured network share at \10.11.11.128\secured_drive containing the Secret Project Data. Evidence from multiple sources:
Shellbags (registry.usrclass.informant):
Browsed the complete directory tree of the network share starting 2015-03-22 14:52:22 UTC:
- \10.11.11.128\secured_drive\Common Data
- \10.11.11.128\secured_drive\Past Projects (MRU: 2015-03-24 13:47:54)
- \10.11.11.128\secured_drive\Secret Project Data (with subdirs: design, pricing decision, final, technical review, proposal, progress)
The share was also mapped as V: drive, with shellbags showing:
- V:\Secret Project Data (MRU: 2015-03-23 20:27:24)
- V:\Secret Project Data\final (MRU: 2015-03-23 20:27:29)
Registry (system):
Network configuration shows DHCP IP address 10.11.11.x on the same subnet as the share server. USBSTOR driver last write: 2015-03-24 13:37:59Z confirms USB storage access during the same timeframe.
Bulk extractor domains (PC):
Multiple references to \10.11.11.128\secured_drive and \10.11.11.128\SECURED_DRIVE found in unallocated space.
Recent Documents:
The informant's RecentDocs key (last written 2015-03-25 15:29:08Z) includes: [secret_project]_proposal.docx, [secret_project]_design_concept.ppt, (secret_project)_pricing_decision.xlsx, [secret_project]_final_meeting.pptx, and winter_whether_advisory.zip — confirming these project files were opened on the PC.
Evidence Chain
User "informant" downloaded, installed, and executed two anti-forensic/data wiping tools on 2015-03-25, the day AFTER the data exfiltration to removable media. Cross-system evidence confirms these tools were the culmination of deliberate research.
Execution Timeline (UserAssist, ShimCache, MFT):
- 14:50:14Z: Eraser 6.2.0.2962.exe installer run (from Desktop\Download)
- 14:57:56Z: ccsetup504.exe (CCleaner v5.04) installer run
- 15:12:28Z: Eraser.exe executed (secure file deletion, 1 run)
- 15:15:50Z: CCleaner64.exe executed (system trace cleaning, 1 run)
- 15:18:36Z: Software...\Run key emptied (by CCleaner removing startup entries)
- 15:21:30Z: Google Drive sync launched (cloud exfiltration)
- 15:24:48Z: WINWORD.EXE (resignation letter)
- 15:28:47Z: XPS viewer (resignation letter conversion)
ShimCache Confirmation: C:\Program Files\Eraser\Eraser.exe — Executed=Yes
MFT Confirmation: C:\Program Files\CCleaner\ files created 2015-03-25 14:58:35Z
Cross-System Correlation with Search History:
- User searched "ccleaner" (n=65 URL search instances) before downloading
- User searched "eraser" (n=51 instances) before downloading
- User searched "anti-forensic+tools" (n=85), "system+cleaner" (n=6), "how+to+delete+data" (n=5)
- Download URL carved: http://iweb.dl.sourceforge.net/project/eraser/Eraser%206/6.2/Eraser%206.2.0.2962.exe
Impact Assessment:
- Browser history: 0 windows recovered (consistent with CCleaner clearing browser data)
- Google Drive sync_config.db and related files: ALL DELETED (anti-forensic cleanup)
- RM2 USB files: All 17 masqueraded documents deleted (orphan entries only)
- Startup entries: Run key emptied
Eraser .NET dependency: dotNetFx40_Full_setup.exe was run from Eraser's temp directory, confirming the installation required and installed .NET 4.0.
Evidence Chain
Synthesizing all evidence sources across PC, RM1 (USB), RM2 (USB), and RM3 (CD-R), the following complete exfiltration timeline is reconstructed:
2015-02-15 (Sunday) — Initial Data Copy:
- 16:51:38 UTC: RM#1 directory modified on RM1 exFAT
- 16:52:08-20 UTC: Five secret project files copied to RM1 exFAT (design_concept.ppt, detailed_design.pptx, revised_points.ppt, detailed_proposal.docx, proposal.docx)
2015-02-27 — Cleanup:
- 17:20:18 UTC: "Secret Project Data" root directory deleted on RM1 exFAT
2015-03-22 (Sunday) — PC Setup and Network Access:
- 14:33:13Z: First login as "informant" (account created 14:33:54Z, login count=10)
- 14:52:22Z: First access to \\10.11.11.128\secured_drive via shellbags
- 15:11-15:17Z: Chrome, IE11 installed; Google Update running
- 15:51-15:53Z: Created admin11, ITechTeam, temporary accounts
2015-03-23 (Monday) — Document Work and Research:
- 16:55:17-37Z: Cover image files born on RM2 FAT32 (24 images)
- 17:26-17:28Z: Chrome launched, Bing/Google searched
- 18:37-18:40Z: Secret project files opened (LNK files created)
- 18:40:17Z: WordWheelQuery search for "secret"
- 20:02Z: Google Drive installed (clickonce_bootstrap.exe)
- 20:10Z: cmd.exe run (4x) — command-line operations
- 20:23-20:28Z: V: drive (network share) browsed, Excel/PowerPoint used
2015-03-24 (Tuesday) — Multi-Media Exfiltration:
- 09:59:26-10:00:18Z: 17 masqueraded files created on RM1 FAT32 and RM2 in 5 directories
- 13:37:59Z: USBSTOR driver last written (USB device connected)
- 13:38:31-14:01:29Z: E:\RM#1\Secret Project Data browsed on PC (shellbags)
- 18:48:40Z: Resignation_Letter_(Iaman_Informant).docx saved
- 19:47:48-20:44:18Z: D:\de, D:\tr, D:\pd, D:\prop, D:\prog browsed (CD-R/RM3 directories)
- 20:54:16-20:57:03Z: CD-R burned with 9 VAT sessions (17 documents + 3 cover photos)
2015-03-25 (Wednesday) — Anti-Forensics and Departure:
- 14:41:03Z: Outlook (5x total) — final email activity
- 14:50:14Z: Eraser installer run from Desktop\Download
- 14:57:56Z: CCleaner installer run from Desktop\Download
- 15:12:28Z: Eraser executed — secure file deletion
- 15:15:50Z: CCleaner64 executed — system trace cleaning
- 15:21:30Z: Google Drive sync launched — potential cloud exfiltration
- 15:24:48Z: WINWORD.EXE — resignation letter (4 total runs)
- 15:28:47Z: XPS viewer — resignation letter converted to XPS
- 15:29:08Z: Last RecentDocs write (final system activity)
Evidence Chain
The CD-R disc image (rm3_type3.E01, volume label "IAMAN CD") contains a UDF write-once filesystem with 9 VAT (Virtual Allocation Table) generations, indicating the disc was burned in multiple sessions. The same set of 17 masqueraded secret project documents found on RM1's FAT32 partition and RM2 were also burned to this CD-R, using the SAME disguised filename scheme (.amr, .zip, .db, .7z, .jpg, .avi, .svg, .png, .one, .gif, .txt extensions).
Session Progression (9 VAT generations) — Directory Naming Evolution:
The CD-R preserves evidence of the user iteratively refining their concealment strategy across multiple burn sessions:
- Sessions -7 to -3: Files first burned using FULL directory names matching the corporate network share structure:
- /design/ (session -7): winter_storm.amr (14,547,968 bytes), winter_whether_advisory.zip (16,381,123 bytes)
- /pricing decision/ (session -6): my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi
- /progress/ (session -5): my_friends.svg, my_smartphone.png, new_year_calendar.one
- /proposal/ (session -4): a_gift_from_you.gif (35,226,880 bytes), landscape.png (6,484,502 bytes)
-
/technical review/ (session -3): diary_#1d.txt through diary_#3p.txt (6 files)
-
Session -1: Files re-burned with ABBREVIATED directory names to obscure the connection to project categories:
-
/de/, /pd/, /prog/, /prop/, /tr/ — same 17 files, same sizes
-
Session 0 (final/active): All data directories deleted; only 3 stock Windows 7 photos remain:
- Koala.jpg (780,831 bytes, created 2015-03-24T20:57:00Z)
- Penguins.jpg (777,835 bytes, created 2015-03-24T20:57:00Z)
- Tulips.jpg (620,888 bytes, created 2015-03-24T20:57:03Z)
Anti-forensic Deletion Pattern:
Files burned in earlier sessions were "deleted" in subsequent sessions (marked as deleted in UDF allocation). The write-once nature of UDF with VAT means deleted data remains physically on the disc despite being marked as removed in the active allocation table.
Shellbags confirm CD-R access: "BD-RE Drive (D:) IAMAN CD" with directories D:\de, D:\tr, D:\pd, D:\prop, D:\prog browsed 2015-03-24 19:47-20:44 UTC.
Evidence Chain
The CD-R demonstrates a sophisticated multi-stage anti-forensic approach exploiting the user's misunderstanding of UDF write-once media behavior. The 9 VAT generations reveal the suspect's iterative attempt to conceal the exfiltrated data.
Anti-forensic technique #1 — File extension masquerading:
All 17 exfiltrated Office documents were renamed with false extensions to disguise their content:
- OLE documents (.ppt, .xls) given extensions: .amr, .db, .avi, .svg
- OOXML documents (.docx, .pptx, .xlsx) given extensions: .zip, .7z, .jpg, .png, .one, .gif, .txt
The filenames themselves were changed to innocuous personal-sounding names (winter_storm, my_favorite_cars, diary_#1d, etc.)
Anti-forensic technique #2 — Directory name obfuscation across sessions:
The disc preserves evidence of the user progressively obscuring the connection between directory names and the corporate project structure:
- Earlier sessions (-7 to -3): Full names "design", "pricing decision", "progress", "proposal", "technical review" — directly mapping to \\10.11.11.128\secured_drive\Secret Project Data subdirectories
- Later session (-1): Abbreviated to "de", "pd", "prog", "prop", "tr" — reducing the forensic connection
- Final session (0): All directories marked as deleted (both full and abbreviated names appear as empty deleted directories)
Anti-forensic technique #3 — Data overwriting with cover content:
After deleting all exfiltrated documents, the user burned 3 stock Windows 7 sample photos (Koala.jpg, Penguins.jpg, Tulips.jpg) to the active session. This would make the disc appear to contain only innocent sample photos if casually examined.
Anti-forensic failure — UDF VAT preservation:
The user likely did not understand that UDF's Virtual Allocation Table on write-once media preserves all previous generations. Each "deletion" only updated the VAT to mark files as removed, while the actual data remained physically intact on the disc. All 9 generations are recoverable through forensic analysis, exposing the complete history of the user's concealment attempts.
Session 0 final state shows both sets of deleted directory names:
The final session's deleted directory listing reveals BOTH the original full names AND the abbreviated names as empty deleted directories, providing direct evidence that the user created both naming schemes during the disc's lifecycle.
Evidence Chain
Browser search history from the PC (bulk.url_searches) reveals the user "informant" conducted extensive research into data leakage techniques, anti-forensic tools, and digital forensics BEFORE executing the exfiltration campaign. This demonstrates premeditation and a deliberate attempt to understand — and evade — forensic investigation.
Anti-Forensic Tool Research (directly leading to tool downloads):
- "anti-forensic+tools" (n=85 search instances)
- "anti-forensics" (multiple direct searches)
- "ccleaner" (n=65) → Led to download of ccsetup504.exe, executed 2015-03-25 14:57:56Z
- "eraser" (n=51) → Led to download of Eraser 6.2.0.2962.exe, executed 2015-03-25 14:50:14Z
- "system+cleaner" (n=5+1)
- "how+to+delete+data" (n=5)
Data Leakage Planning Research:
- "information+leakage+cases" (n=47)
- "how+to+leak+a+secret" (n=6)
- "intellectual+property+theft" (n=6)
- "leaking+confidential+information" (n=2)
- "data+leakage+methods" (n=1)
Forensic Investigation Awareness (counter-forensics):
- "e-mail+investigation" (n=88)
- "Forensic+Email+Investigation" (n=78)
- "what+is+windows+system+artifacts" (n=79)
- "windows+event+logs" (n=61)
- "investigation+on+windows+machine" (n=64)
- "external+device+and+forensics" (n=65)
- "digital+forensics" (multiple)
Exfiltration Vector Research:
- "cloud+storage" (n=6) → Led to Google Drive and iCloud installation
- "google+drive" (n=10) → googledrivesync.exe downloaded and executed
- "apple+icloud" (n=1) → icloudsetup.exe installed
- "cd+burning+method" (n=64) → CD-R burning with masqueraded files
- "cd+burning+method+in+windows" (n=53)
- "security+checkpoint+cd-r" (n=1) — researched security controls for CD media
Data Protection/DLP Awareness:
- "DLP%20DRM" (n=90) — researched Data Loss Prevention and Digital Rights Management
- "file+sharing+and+tethering" (n=491)
Data Recovery Counter-Research:
- "data+recovery+tools" (multiple) — researched what tools could recover deleted data
- "how+to+recover+data" (multiple) — understood what investigators could find
Wired Article on Data Theft:
- Visited: http://www.wired.com/2015/03/stealing-data-computers-using-heat/ — article about "stealing data from computers using heat"
CONVERGENCE ACROSS EVIDENCE SOURCES:
This research activity (from bulk_extractor URL search histograms on the PC disk) directly correlates with actions documented in registry artifacts (UserAssist, ShimCache), removable media filesystems (masqueraded files, CD-R burns), and event logs (account creation). Each searched topic maps to a specific action taken:
1. Searched "ccleaner"/"eraser" → Downloaded and executed both tools
2. Searched "cloud+storage"/"google+drive" → Installed and ran googledrivesync.exe
3. Searched "cd+burning+method" → Burned data to CD-R with 9 VAT sessions
4. Searched "anti-forensic+tools" → Implemented file masquerading, deletion, and wiping
5. Searched "data+leakage+methods" → Executed multi-media exfiltration campaign
Evidence Chain
RM1 is a 4GB USB device containing two distinct partitions configured for apparent plausible deniability:
Partition 1 (exFAT):
- Volume Label: "Authorized USB"
- Volume Serial: 5c75-4d3e
- Contains active Secret Project Data files openly (in design/ and proposal/ subdirectories)
- Appears as an "authorized" work USB
Partition 2 (FAT32):
- Volume Label: "IAMAN $_@" — notably contains the user identifier "IAMAN" matching email addresses iaman@nist.gov and iaman.informant@nist.gov found on the source PC
- Volume ID: 0xb4d85399
- Originally contained 17 masqueraded copies of secret project documents (all deleted)
- Originally contained 22 cover image files (all deleted)
- Directory structure (design, pricing decision, progress, proposal, technical review) mirrors the network share at \10.11.11.128\secured_drive\Secret Project Data
The use of two partitions — one "clean" and one for covert storage — along with the false file extensions and subsequent deletion of all files on the second partition, demonstrates a deliberate multi-layered concealment strategy. If the USB was inspected casually, only the first "Authorized USB" partition would be visible, appearing to contain legitimate project files.
Evidence Chain
Bulk extractor analysis across all removable media carved identical document metadata, confirming the same documents are present on all three devices and providing attribution information.
Embedded email addresses (found on all three media):
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget, Executive Office of the President) — found in document content embedded at consistent offsets across RM2 and RM3
- wayne.longman@att.net — found as mailto: hyperlinks within document content, multiple occurrences
- mmun@loc.gov (Library of Congress) — found in context "(email address: mmun@loc.gov)" preceding a "PREFACE" section
Government/institutional domain references (from bulk.domain):
- www.iec.ch (International Electrotechnical Commission) — extensive references
- www.whitehouse.gov/omb — government OMB policy documents
- lcweb.loc.gov (Library of Congress)
- desert-estates.info — hyperlink in document content
- digitalcorpora.org/corpora/govdocs — GovDocs corpus references
EXIF metadata from document-embedded images:
- Kodak DC260 camera images (2003): Technical photographs
- Adobe Photoshop CS Macintosh processed images (2006): Document illustrations
- Cover images on RM1/RM2: Genuine personal photos from various sources (2004-2013 era)
- Cover images on RM3: Unmodified Windows 7 sample photos (Corbis/Microsoft, 2008-2009)
User identity confirmed across sources:
- iaman.informant@nist.gov (Outlook OST on PC)
- iaman.informant.personal@gmail.com (personal email in registry)
- Password hint "IAMAN" matches volume labels "IAMAN $_@" and "IAMAN CD"
Cross-media email convergence: The same three embedded email addresses appear at proportional disc offsets on RM2 and RM3, confirming byte-identical document content across media.
Evidence Chain
The user installed cloud storage applications representing additional exfiltration vectors. Anti-forensic cleanup destroyed evidence of what was synced.
Google Drive (confirmed execution):
- googledrivesync.exe installed: C:\Program Files (x86)\Google\Drive\ (MFT shows 27+ language files created 2015-03-23 20:02:43Z)
- ShimCache: googledrivesync.exe modified 2015-02-19 18:24:23, Executed=Yes
- UserAssist: Last executed 2015-03-25 15:21:30Z (1 GUI run)
- Shellbags: "Users\Google Drive" directory browsed (MRU 2015-03-25 15:20:59Z)
- CRITICAL: Google Drive launched AFTER Eraser (15:12Z) and CCleaner (15:15Z) — suggesting the user cleaned up first, then synced remaining data to cloud
- User searched "google+drive" (n=10) and "cloud+storage" (n=6) in browser
Google Drive Sync Evidence Destroyed:
- sync_config.db-shm (deleted, inode 73728)
- cacerts (deleted, inode 75037)
- snapshot.db (deleted, inode 75039)
- sync_config.db (deleted, inode 75040)
These deletions are consistent with Eraser's secure file deletion capability.
Apple iCloud (installed but uncertain usage):
- icloudsetup.exe in UserAssist (executed at some point)
- Bonjour Service installed: 2015-03-23 20:00:56Z (Apple dependency)
- User searched "apple+icloud" (n=1) in browser
- No definitive evidence of iCloud data sync
Significance:
The sequence (anti-forensic cleanup → Google Drive sync → resignation letter) suggests the user synced documents to Google Drive as a cloud exfiltration method complementing physical media. However, the destruction of sync configuration files means we cannot definitively confirm what was uploaded.
Evidence Chain
On 2015-03-22, the "informant" user created three additional accounts within 2 minutes during initial PC setup. Chainsaw/Hayabusa security event analysis confirms the creation events, and registry analysis shows minimal activity on these accounts, suggesting they may have been diversionary.
Account Creation Events (from chainsaw.hunt and hayabusa.alerts):
- 2015-03-22 15:51:54Z: "admin11" created (Local User Creation + Added to Administrators group)
- 2015-03-22 15:52:30Z: "ITechTeam" created (Local User Creation + Added to Administrators group)
- 2015-03-22 15:53:01Z: "temporary" created (Local User Creation, NOT added to Administrators)
Hayabusa Alert: "User Added To Local Admin Grp" (high severity) at 2015-03-22 15:51:54Z — SrcSID matches informant's SID (S-1-5-21-2425377081-3129163575-2985601102-1001)
Account Activity Assessment (from per-user NTUSER.DAT and UsrClass.dat):
- admin11 (RID 1001): Login count=2, last login 2015-03-22 15:57:02Z. UserAssist shows only standard Windows exploration (Welcome Center, Control Panel). Shellbags show only Libraries/Desktop browsing. NO access to Secret Project Data, network shares, or removable media.
- ITechTeam (RID 1002): Never logged in (login count=0). No UserAssist or shellbag data.
- temporary (RID 1003): Login count=1. UserAssist shows only Welcome Center exploration (2015-03-22 15:56:13Z). Shellbags show only Libraries browsing. NO Secret Project Data access.
Correlation with Forensic Research:
The user's search history includes "investigation+on+windows+machine" (n=64), "what+is+windows+system+artifacts" (n=79), and "windows+event+logs" (n=61). Creating multiple accounts with varying privilege levels may have been an attempt to:
1. Create confusion about which account performed the data theft
2. Test whether account creation would be logged
3. Establish plausible deniability ("maybe admin11 did it")
Counter-analysis note (confidence downgrade from "confirmed" to "inference"):
The existence and creation of these accounts is confirmed. However, characterizing them as "diversionary" is an inference. Alternative explanations include: (1) testing account creation as part of learning Windows administration, (2) standard lab/test environment setup, or (3) creating accounts for other users who never used them. The diversionary interpretation is supported by the convergent forensic research evidence, but cannot be confirmed without direct evidence of intent. The accounts' creation is consistent with the broader attack chain pattern but does not independently prove anti-forensic motivation.
Significance: None of the three created accounts accessed the Secret Project Data. ALL exfiltration activity was performed under the "informant" account.
Evidence Chain
The informant's Outlook OST data store on the PC contains an email contact entry for "spy" with email address spy.conspirator@nist.gov. Bulk extractor recovered this from two locations in the disk image:
- Offset 15509094608: Raw email address
spy.conspirator@nist.govin UTF-16 encoding within Outlook data structures - Offset 15509095786: Formatted display name entry
spy <spy.conspirator@nist.gov>— indicating this was stored as a contact or autocomplete entry in the Outlook cache
The deliberately provocative naming convention (display name "spy", email "spy.conspirator") mirrors the informant's own email naming pattern (iaman.informant@nist.gov) and suggests this may be a co-conspirator in the data exfiltration scheme. The contact resided within the cached offline store (.ost) for iaman.informant@nist.gov.
Counter-analysis note (confidence downgrade from "confirmed" to "inference"):
- Only one evidence source (bulk.email from PC disk image) — no corroboration from a second independent source
- No actual email message content between the informant and this contact was recovered
- The provocative naming matches the synthetic naming convention used throughout this NIST CFREDS 2015 scenario (iaman.informant, spy.conspirator)
- The presence of a contact entry proves only that the address existed in Outlook autocomplete/contacts, not that conspiratorial communication occurred
- No evidence of secret project data being transmitted via email to any address
The exfiltration pathway appears to have been exclusively through removable media (RM1, RM2, RM3) and potentially cloud storage (Google Drive), not email.
Evidence Chain
Analysis across all three removable media devices found no evidence of encrypted containers (TrueCrypt, VeraCrypt, BitLocker) or steganographic tools/content.
RM1 (USB): String analysis and YARA scanning produced no hits for encryption or steganography signatures. Cover images on the FAT32 partition contain genuine EXIF data from Kodak DC260 cameras and Adobe Photoshop CS.
RM3 (CD-R): steg.detection returned no results. YARA scan: no matches. The three active cover images (Koala.jpg, Penguins.jpg, Tulips.jpg) are unmodified Windows 7 sample photos from C:\Users\Public\Pictures\Sample Pictures\ — confirmed by exact file size matching against MFT entries on the PC. No size modification indicating appended steganographic data.
Anti-forensic techniques used were limited to:
1. File extension masquerading (false extensions on Office documents)
2. File deletion (all exfiltrated documents deleted after copying)
3. Multi-session CD burning with deletion (exploiting UDF VAT)
4. Cover content placement (stock/personal photos)
5. Anti-forensic tool execution (Eraser, CCleaner)
Evidence Chain
System: informant-PC (Windows 7, 64-bit)
Timezone: Eastern Standard Time (UTC-5 standard / UTC-4 during EDT). Registry key ControlSet001\Control\TimeZoneInformation: Bias=300, ActiveTimeBias=240, TimeZoneKeyName=Eastern Standard Time. Last written: 2015-03-25T10:34:25Z.
User Accounts (from SAM hive):
- informant (RID 1000) - Primary active user
- Created: 2015-03-22 14:33:54Z
- Last Login: 2015-03-25 14:45:59Z
- Login Count: 10
- Password Hint: "IAMAN" (matches volume labels "IAMAN $_@" and "IAMAN CD")
- Account Type: Admin
-
This user created all other accounts and is the primary actor
-
admin11 (RID 1001) - Admin
- Created: 2015-03-22 15:51:54Z (created BY informant per Security event logs)
- Last Login: 2015-03-22 15:57:02Z
-
Login Count: 2
-
ITechTeam (RID 1002) - Admin
- Created: 2015-03-22 15:52:30Z (created BY informant)
-
Never logged in
-
temporary (RID 1003) - Limited user
- Created: 2015-03-22 15:53:01Z (created BY informant)
-
Login Count: 1
-
Administrator (RID 500) - Disabled
- Guest (RID 501) - Disabled
Security Event Log confirms: The informant user (S-1-5-21-...1000) created admin11, ITechTeam, and temporary accounts and added admin11 and ITechTeam to Administrators group on 2015-03-22. Password hint "IAMAN" directly links the user to the removable media labels.
Evidence Chain
UserAssist, ShimCache, and RecentDocs artifacts reconstruct the complete application execution timeline on the informant-PC, revealing a methodical data access, exfiltration, and cover-up workflow.
Application Execution Chronology (UserAssist timestamps, UTC):
Day 1 - 2015-03-22 (System Setup):
- 14:33:13Z: First login, standard Windows apps explored
- 15:12:32Z: IE11 installer downloaded and run (C:\Users\informant\Desktop\Download\IE11-Windows6.1-x64-en-us.exe)
- 15:24:47Z: System licensing (slui.exe, 3x)
- 15:51-15:53Z: Created admin11, ITechTeam, temporary accounts
Day 2 - 2015-03-23 (Document Work Begins):
- 17:26:50Z: Chrome launched
- 17:28:18Z: TypedURLs → bing.com, google.com
- 20:10:19Z: cmd.exe (4x) — command-line operations
- 20:23:28Z: First access to \10.11.11.128\secured_drive (shellbags)
- 20:26:50Z: Excel (1x) — (secret_project)_pricing_decision.xlsx
- 20:27:33Z: PowerPoint (2x) — [secret_project]_final_meeting.pptx
Day 3 - 2015-03-24 (Data Access and CD-R Burning):
- 13:37:59Z: USBSTOR driver last written (USB device connected)
- 13:38:31Z: E:\RM#1\Secret Project Data browsed (shellbags)
- 13:47:54Z-13:48:00Z: V:\Secret Project Data subdirectories accessed
- 14:16:37Z: rundll32.exe (1x)
- 18:31:55Z: Sticky Notes (13x total)
- 20:44:18Z: winter_whether_advisory.zip accessed (RecentDocs)
- 20:57:00Z: CD-R stock photos created (Koala.jpg, Penguins.jpg, Tulips.jpg)
- 21:01:14Z: Stock photos on CD-R viewed (RecentDocs .jpg)
- 21:05:38Z: Chrome (7x total)
Day 4 - 2015-03-25 (Final Day — Anti-Forensics and Departure):
- 14:41:03Z: Outlook (5x total) — email activity
- 14:42:47Z: Windows Media Player (1x)
- 14:46:05Z: Internet Explorer (5x total)
- 14:50:14Z: Eraser installer run from Desktop\Download
- 14:57:56Z: CCleaner installer run from Desktop\Download
- 15:12:28Z: Eraser executed — secure file deletion
- 15:15:50Z: CCleaner executed — system trace cleaning
- 15:21:30Z: Google Drive sync launched — cloud exfiltration
- 15:24:48Z: WINWORD.EXE (4x total) — resignation letter
- 15:28:47Z: XPS viewer — resignation letter conversion
- 15:29:08Z: Last RecentDocs write (Resignation_Letter_.docx)
Key ShimCache Entries (additional execution evidence):
- C:\Program Files\Eraser\Eraser.exe (modified 2015-01-12, Executed=Yes)
- C:\Program Files (x86)\Google\Drive\googledrivesync.exe (modified 2015-02-19, Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\WINWORD.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\POWERPNT.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\EXCEL.EXE (Executed=Yes)
Evidence Chain
Multiple registry artifacts from the informant user's NTUSER.DAT hive document the systematic pattern of accessing and handling secret project documents.
WordWheelQuery (Windows Explorer Search):
- LastWrite: 2015-03-23 18:40:17Z
- Search term: "secret"
- This search was used to locate secret project documents on the network share or local system
RecentDocs (MRU Order, LastWrite 2015-03-25 15:29:08Z):
Most recently accessed first:
1. Resignation_Letter_(Iaman_Informant).docx
2. Resignation_Letter_(Iaman_Informant).xps
3. BD-RE Drive (D:) IAMAN CD
4. Tulips.jpg → 5. Koala.jpg → 6. Penguins.jpg (stock photos on CD-R)
7. BD-RE Drive (D:)
8. winter_whether_advisory.zip
9. final (folder)
10. [secret_project]_final_meeting.pptx
11. pricing decision (folder)
12. (secret_project)_pricing_decision.xlsx
13. secret (folder)
14. [secret_project]_design_concept.ppt
15. [secret_project]_proposal.docx
RecentDocs by Extension:
- .docx: [secret_project]proposal.docx, Resignation_Letter(Iaman_Informant).docx
- .ppt: [secret_project]design_concept.ppt (LastWrite 2015-03-23 18:38:21Z)
- .pptx: [secret_project]_final_meeting.pptx (LastWrite 2015-03-23 20:27:33Z)
- .xlsx: (secret_project)_pricing_decision.xlsx (LastWrite 2015-03-23 20:26:53Z)
- .xps: Resignation_Letter(Iaman_Informant).xps (LastWrite 2015-03-25 15:28:33Z)
- .zip: winter_whether_advisory.zip (LastWrite 2015-03-24 20:44:18Z)
- .jpg: Tulips.jpg, Koala.jpg, Penguins.jpg (LastWrite 2015-03-24 21:01:14Z)
- Folders: BD-RE Drive IAMAN CD, BD-RE Drive, final, pricing decision, secret
OpenSavePidlMRU (File Open/Save Dialog History):
- LastWrite 2015-03-25 15:28:33Z
- Files accessed via open/save dialogs (MRU order):
1. Resignation_Letter_(Iaman_Informant).xps
2. Download\ccsetup504.exe
3. Download\Eraser 6.2.0.2962.exe
4. Resignation_Letter_(Iaman_Informant).docx
5. Download\IE11-Windows6.1-x64-en-us.exe
- .docx type: Resignation_Letter saved on 2015-03-24 18:48:40Z
- .exe type: ccsetup504.exe, Eraser installer, IE11 installer (LastWrite 2015-03-25 14:48:28Z)
- .xps type: Resignation Letter saved as XPS on 2015-03-25 15:28:33Z
TypedURLs (Internet Explorer):
- LastWrite 2015-03-23 17:28:18Z
- url1: http://www.bing.com/
- url2: http://google.com/
- url3: http://go.microsoft.com/fwlink/?LinkId=69157
These artifacts collectively demonstrate the user: (1) searched for "secret" documents, (2) accessed all secret project files in their original formats, (3) accessed the CD-R drive contents, (4) downloaded anti-forensic tools, and (5) created and saved a resignation letter.
Evidence Chain
EXIF analysis of image data on the CD-R reveals two distinct classes of images:
1. Active Cover Images (3 files in final session):
The three remaining active files are stock Windows 7 sample photographs:
- Koala.jpg (780,831 bytes): Artist="Corbis", DateTimeOriginal=2008-02-11 11:32:43, modified 2009-03-12 13:48:28. SHA1: 8ed079594882a366e55d2435a8ef465e273a41ac
- Penguins.jpg (777,835 bytes): Artist="Corbis", DateTimeOriginal=2008-02-18 05:07:31, modified 2009-03-12 13:48:35. SHA1: 5db7f51e7ec17bd17335c85b069025072ba6614c
- Tulips.jpg (620,888 bytes): Copyright="Microsoft Corporation", DateTimeOriginal=2008-02-07 11:33:11, modified 2009-03-12 13:48:39. SHA1: 80824aa4a492d18585c4659632069dc9cc79fd47
These are standard Windows 7 sample photos (C:\Users\Public\Pictures\Sample Pictures) used as cover content to make the CD appear innocuous. Their modified dates (2009-07-14 05:32:31, the Windows 7 RTM date) and Corbis/Microsoft attribution confirm they are unmodified system files. They were burned to the CD on 2015-03-24 at 20:57:00-20:57:03 UTC, after all exfiltrated documents were deleted from the active filesystem.
2. Document-Embedded Image EXIF (from deleted sessions):
The masqueraded Office documents contain embedded images with EXIF data from two distinct sources:
a) Kodak DC260 photographs (2003 era):
- Camera: "Eastman Kodak Company" / "KODAK DIGITAL SCIENCE DC260 (V01.00)"
- DateTimeOriginal: 2003-09-24 15:33:42 and 2003-12-10 17:27:44
- Resolution: 1536×1024 pixels
- No GPS data present
- Found at offsets 1310146 and 9203260 in the CD-R image
b) Adobe Photoshop CS Macintosh processed images (2006 era):
- Software: "Adobe Photoshop CS Macintosh"
- DateTime stamps: 2006-03-21, between 11:19:46 and 13:39:22 (same day processing batch)
- Various dimensions (157×207 to 539×273 pixels) — small images typical of document illustrations
- Multiple distinct SHA1 hashes confirm these are unique images
- Found at 9 offsets between 95018581 and 99647667 in the CD-R image
No GPS coordinates were found in any images on the CD-R. The EXIF data does not contain steganographic indicators. The document-embedded images suggest the exfiltrated documents contain technical illustrations that were originally photographed with a Kodak DC260 camera in 2003 and processed in Adobe Photoshop CS on a Mac in March 2006.
Evidence Chain
Investigation question: "Is there any evidence in the PCAP data of SMB file transfers between the PC and 10.11.11.128?"
Answer: No valid PCAP network capture files exist in the disk image. The only .cap files found were ATI GPU driver files (atiumd6a.cap, atiumdva.cap) located in the Windows driver store at C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_*. TShark confirmed these are not valid packet capture files.
Despite the absence of PCAP evidence, the SMB connection to \10.11.11.128\secured_drive is confirmed through multiple other artifacts:
- Shellbag entries showing navigation to the network share path
- File metadata timestamps on USB documents matching the source on the secured drive
- The PC's own IP was 10.11.11.129 (DHCP, same /24 subnet as the file server at 10.11.11.128)
Evidence Chain
MITRE ATT&CK Coverage
Indicators of Compromise
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
| Internal IP | 10.11.11.128 |
Dual-Partition USB Device Structure Enables Plausible Deniability | VT |
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
| Path | C:\Program |
Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Execute |
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
iaman@nist.gov |
Dual-Partition USB Device Structure Enables Plausible Deniability | |||
iaman.informant@nist.gov |
Dual-Partition USB Device Structure Enables Plausible Deniability | |||
eric_p._lauer@omb.eop.gov |
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across | |||
wayne.longman@att.net |
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across | |||
mmun@loc.gov |
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across | |||
iaman.informant.personal@gmail.com |
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across | |||
spy.conspirator@nist.gov |
Potential Co-Conspirator Contact Entry — spy.conspirator@nist.gov in Outlook Dat |
Evidence Browser
Evidence Sources
| Source Name | Extractor | Lines | Hash | Referenced By |
|---|---|---|---|---|
| tsk.partitions | sleuthkit | 8 | blake2b:3eed10c8... |
— |
| tsk.fsstat | sleuthkit | 37 | blake2b:2d2079ee... |
3 findings |
| tsk.partitions | sleuthkit | 9 | blake2b:83c0b87c... |
— |
| tsk.filelist | sleuthkit | 27 | blake2b:ae86d6dd... |
6 findings |
| hashdeep.hashes | hashdeep | 6 | blake2b:c270e797... |
— |
| tsk.fsstat | sleuthkit | 40 | blake2b:9e253812... |
3 findings |
| tsk.filelist | sleuthkit | 51 | blake2b:55fc9962... |
6 findings |
| tsk.partitions | sleuthkit | 8 | blake2b:3eed10c8... |
— |
| tsk.partitions | sleuthkit | 9 | blake2b:83c0b87c... |
— |
| tsk.partitions | sleuthkit | 10 | blake2b:67b9085f... |
— |
| optical.listing | mulder-optical | 58 | blake2b:65ca19c0... |
7 findings |
| ez.mft | eztools | 98918 | blake2b:6381ab0d... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:3da38cb8... |
— |
| bulk.domain | bulk_extractor | 237 | blake2b:29444e46... |
2 findings |
| bulk.email | bulk_extractor | 12 | blake2b:26c081a6... |
4 findings |
| bulk.exif | bulk_extractor | 21 | blake2b:c2dd544d... |
2 findings |
| bulk.rfc822 | bulk_extractor | 41 | blake2b:e3da4d10... |
— |
| bulk.url | bulk_extractor | 300 | blake2b:28d82359... |
1 finding |
| bulk.url_services | bulk_extractor | 21 | blake2b:6224c8f2... |
1 finding |
| tsk.filelist | sleuthkit | 104709 | blake2b:171e0914... |
6 findings |
| tsk.filelist.p1 | sleuthkit | 93 | blake2b:5bdfadd3... |
6 findings |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:c2a52474... |
— |
| bulk.domain | bulk_extractor | 264 | blake2b:c8b97b94... |
2 findings |
| bulk.duplicates | bulk_extractor | 9 | blake2b:9ba9de0c... |
— |
| bulk.email | bulk_extractor | 43 | blake2b:eb085c00... |
4 findings |
| bulk.exif | bulk_extractor | 27 | blake2b:eaa48964... |
2 findings |
| bulk.rfc822 | bulk_extractor | 41 | blake2b:283d0ef9... |
— |
| bulk.url | bulk_extractor | 288 | blake2b:d727c498... |
1 finding |
| bulk.url_services | bulk_extractor | 19 | blake2b:01e609ea... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:54705fdb... |
— |
| bulk.domain | bulk_extractor | 189 | blake2b:ae916b75... |
2 findings |
| bulk.duplicates | bulk_extractor | 9 | blake2b:bb406faf... |
— |
| bulk.exif | bulk_extractor | 20 | blake2b:d7c9e32a... |
2 findings |
| bulk.url | bulk_extractor | 207 | blake2b:039de0b6... |
1 finding |
| bulk.url_services | bulk_extractor | 14 | blake2b:2eac1377... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:cd0c5cdc... |
— |
| bulk.domain | bulk_extractor | 366963 | blake2b:fc1062a8... |
2 findings |
| bulk.duplicates | bulk_extractor | 12 | blake2b:f8b9f6c0... |
— |
| bulk.email | bulk_extractor | 6851 | blake2b:1790b6a7... |
4 findings |
| bulk.ether | bulk_extractor | 6 | blake2b:0825117f... |
— |
| bulk.exif | bulk_extractor | 793 | blake2b:2158d20a... |
2 findings |
| bulk.rfc822 | bulk_extractor | 7326 | blake2b:cfe35c27... |
— |
| bulk.url | bulk_extractor | 421750 | blake2b:c2ca3420... |
1 finding |
| bulk.url_facebook-address | bulk_extractor | 19 | blake2b:7fe55073... |
1 finding |
| bulk.url_searches | bulk_extractor | 155 | blake2b:b928562c... |
2 findings |
| bulk.url_services | bulk_extractor | 3637 | blake2b:c01e89c3... |
1 finding |
| bulk.winpe | bulk_extractor | 29138 | blake2b:16029dc9... |
— |
| bulk.winpe_carved | bulk_extractor | 29130 | blake2b:8048b50e... |
— |
| registry.system | regripper | 186 | blake2b:5cd5d58a... |
5 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
5 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
5 findings |
| registry.system | regripper | 69 | blake2b:6b7bf22c... |
5 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
5 findings |
| pcap.disk.atiumd6a | tshark | 8 | blake2b:e0cc3007... |
1 finding |
| tsk.masquerade | sleuthkit | 0 | blake2b:empty... |
6 findings |
| registry.system | regripper | 33492 | blake2b:9ef84a11... |
5 findings |
| pcap.disk.atiumdva | tshark | 8 | blake2b:717532ef... |
1 finding |
| evtx.manifest | evtx-extract | 54 | blake2b:62bd3681... |
— |
| tsk.masquerade | sleuthkit | 17 | blake2b:97440a18... |
6 findings |
| registry.system | regripper | 283 | blake2b:fc484f66... |
5 findings |
| ez.shimcache | eztools | 307 | blake2b:a4845f8d... |
2 findings |
| registry.system | regripper | 283 | blake2b:3a9de3b9... |
5 findings |
| pcap.disk.atiumd6a | tshark | 8 | blake2b:e0cc3007... |
1 finding |
| registry.query.software | python-registry | 1 | blake2b:5779bd0c... |
— |
| registry.system | regripper | 5209 | blake2b:271fd1be... |
5 findings |
| registry.system | regripper | 199 | blake2b:35341c41... |
5 findings |
| pcap.disk.atiumdva | tshark | 8 | blake2b:717532ef... |
1 finding |
| registry.system | regripper | 199 | blake2b:2be4a97a... |
5 findings |
| pcap.disk.atiumd6a | tshark | 8 | blake2b:e0cc3007... |
1 finding |
| hayabusa.alerts | hayabusa | 35 | blake2b:8f8ce27e... |
2 findings |
| pcap.disk.atiumdva | tshark | 8 | blake2b:717532ef... |
1 finding |
| registry.query.system | python-registry | 1 | blake2b:2ae2eb16... |
1 finding |
| registry.query.system | python-registry | 1 | blake2b:8639046c... |
1 finding |
| registry.query.system | python-registry | 1 | blake2b:106b833a... |
1 finding |
| tsk.timeline | sleuthkit | 344089 | blake2b:4cc4645b... |
5 findings |
| registry.system | regripper | 381 | blake2b:070a4d56... |
5 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
5 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
5 findings |
| registry.usrclass.admin11 | regripper | 11 | blake2b:26a43778... |
1 finding |
| registry.ntuser.admin11 | regripper | 133 | blake2b:bf617a09... |
1 finding |
| registry.ntuser.default | regripper | 74 | blake2b:8518dc3f... |
— |
| registry.usrclass.informant | regripper | 102 | blake2b:9f1344c3... |
8 findings |
| registry.ntuser.informant | regripper | 306 | blake2b:597d71cd... |
9 findings |
| registry.usrclass.temporary | regripper | 15 | blake2b:3ef5eb22... |
1 finding |
| registry.ntuser.temporary | regripper | 118 | blake2b:800424ee... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:7d6368ee... |
— |
| bulk.domain | bulk_extractor | 5206 | blake2b:1f177d2c... |
2 findings |
| bulk.duplicates | bulk_extractor | 1298 | blake2b:a115e731... |
— |
| bulk.email | bulk_extractor | 15 | blake2b:23d970cf... |
4 findings |
| bulk.exif | bulk_extractor | 20 | blake2b:d7c9e32a... |
2 findings |
| bulk.url | bulk_extractor | 5226 | blake2b:db311642... |
1 finding |
| bulk.url_services | bulk_extractor | 25 | blake2b:d5889ea9... |
1 finding |
| bulk.zip_carved | bulk_extractor | 3851 | blake2b:34af67f4... |
— |
| exiftool.metadata | exiftool | 9 | blake2b:f2d57075... |
— |
| hashdeep.hashes | hashdeep | 6 | blake2b:0e07b059... |
— |
| tsk.timeline | sleuthkit | 67 | blake2b:822b5179... |
5 findings |
| strings.output | strings | 22065 | blake2b:9705a003... |
1 finding |
| bulk.bulk_extractor | bulk_extractor | 1 | blake2b:b880e20a... |
— |
| bulk.domain | bulk_extractor | 7330 | blake2b:c953e364... |
2 findings |
| bulk.duplicates | bulk_extractor | 1742 | blake2b:f0cc1b26... |
— |
| bulk.email | bulk_extractor | 61 | blake2b:85d5f607... |
4 findings |
| bulk.exif | bulk_extractor | 27 | blake2b:eaa48964... |
2 findings |
| bulk.rfc822 | bulk_extractor | 41 | blake2b:283d0ef9... |
— |
| bulk.url | bulk_extractor | 7192 | blake2b:e1252d17... |
1 finding |
| bulk.url_services | bulk_extractor | 58 | blake2b:033e5d0e... |
1 finding |
| bulk.zip_carved | bulk_extractor | 5221 | blake2b:75538583... |
— |
| tsk.timeline | sleuthkit | 187 | blake2b:da03c607... |
5 findings |
| exiftool.metadata | exiftool | 9 | blake2b:e7b52a8d... |
— |
| strings.output | strings | 165747 | blake2b:2b7a943c... |
1 finding |
| tsk.masquerade | sleuthkit | 3 | blake2b:42bb5e7d... |
6 findings |
| chainsaw.hunt | chainsaw | 99 | blake2b:d992d688... |
1 finding |
| registry.query.system | python-registry | 1 | blake2b:106b833a... |
1 finding |
| exiftool.metadata | exiftool | 9 | blake2b:bb09ed66... |
— |
| hashdeep.hashes | hashdeep | 6 | blake2b:28ba0ef4... |
— |
| strings.output | strings | 34815 | blake2b:89a5dd6d... |
1 finding |
| composite.timeline | composite | 172 | blake2b:1204d042... |
— |
| composite.execution | composite | 122 | blake2b:06171204... |
— |
| composite.defense_evasion | composite | 216 | blake2b:243251bc... |
— |
| composite.correlation | composite | 1 | blake2b:3b4df503... |
— |
| composite.correlation | composite | 1 | blake2b:b900b4f1... |
— |
| composite.correlation | composite | 1 | blake2b:bebebfd1... |
— |
| composite.correlation | composite | 1 | blake2b:7d8d456d... |
— |
| composite.correlation | composite | 1 | blake2b:d3b22136... |
— |
| composite.correlation | composite | 1 | blake2b:454d74b0... |
— |
| composite.file_staging | composite | 578 | blake2b:06da57a3... |
— |
| composite.exfil | composite | 2494 | blake2b:fc05150a... |
— |
| enrichment.iocs | enrichment | 59 | blake2b:d99d9021... |
— |
| forensic.timestomping | timestomp_detector | 1 | blake2b:a8aad413... |
— |
| composite.file_staging | composite | 578 | blake2b:06da57a3... |
— |
| composite.correlation | composite | 1 | blake2b:69e54f70... |
— |
| forensic.timestomping | timestomp_detector | 1 | blake2b:a8aad413... |
— |
| composite.file_staging | composite | 578 | blake2b:06da57a3... |
— |
| composite.correlation | composite | 1 | blake2b:69e54f70... |
— |
Investigation Performance
| Input Tokens | 36,946 |
| Output Tokens | 229,734 |
| Total Tokens | 266,680 |
| Per-Model Breakdown | |
| claude-opus-4-6 | 266,680 |
Audit Trail
| ID | Tool | Duration | Timestamp | Actions |
|---|---|---|---|---|
| tc_bee59d22 | scan_evidence | 2103ms | 2026-09-19T19:55:01 | |
| tc_1fba11a8 | list_directory | 2ms | 2026-09-19T19:55:06 | |
| tc_01a72692 | list_sources | 2ms | 2026-09-19T19:55:06 | |
| tc_f4deafe2 | get_source_stats | 2ms | 2026-09-19T19:55:06 | |
| tc_4d0f2fba | open_case | 29ms | 2026-09-19T19:55:42 | |
| tc_67cc39a0 | list_directory | 2ms | 2026-09-19T19:55:42 | |
| tc_cfbf6412 | open_case | 30ms | 2026-09-19T19:55:43 | |
| tc_8f805a0b | open_case | 30ms | 2026-09-19T19:55:43 | |
| tc_70e7bba8 | list_directory | 2ms | 2026-09-19T19:55:43 | |
| tc_3c2c10cf | list_directory | 2ms | 2026-09-19T19:55:43 | |
| tc_87c1d7d2 | list_sources | 2ms | 2026-09-19T19:55:56 | |
| tc_2de15df9 | list_sources | 2ms | 2026-09-19T19:55:58 | |
| tc_13c71e56 | open_case | 29ms | 2026-09-19T19:56:32 | |
| tc_a5145cbc | run_mmls | 36ms | 2026-09-19T19:56:43 | |
| tc_5507e8cf | run_fsstat | 57ms | 2026-09-19T19:56:43 | |
| tc_b9d2a50d | open_case | 30ms | 2026-09-19T19:56:45 | |
| tc_54ffed04 | start_extraction_batch | 5ms | 2026-09-19T19:56:48 | |
| tc_070272f9 | run_mmls | 75ms | 2026-09-19T19:56:51 | |
| tc_7c98d92a | run_fls | 3638ms | 2026-09-19T19:56:51 | |
| tc_e3412c14 | run_hashdeep | 1507ms | 2026-09-19T19:56:52 | |
| tc_13f8e27f | run_fsstat | 59ms | 2026-09-19T19:56:56 | |
| tc_5d4dee95 | start_extraction_batch | 5ms | 2026-09-19T19:56:56 | |
| tc_9dee8d78 | run_photorec | 4ms | 2026-09-19T19:56:56 | |
| tc_b8375fca | run_fls | 1097ms | 2026-09-19T19:56:57 | |
| tc_b5265e6e | open_case | 34ms | 2026-09-19T20:00:44 | |
| tc_92a19233 | run_mmls | 35ms | 2026-09-19T20:00:48 | |
| tc_23b0d6e3 | run_mmls | 62ms | 2026-09-19T20:00:48 | |
| tc_f80f3cff | run_mmls | 77ms | 2026-09-19T20:00:48 | |
| tc_11254085 | start_extraction_batch | 16ms | 2026-09-19T20:00:55 | |
| tc_b7a115d4 | run_optical_listing | 96ms | 2026-09-19T20:00:55 | |
| tc_c5591884 | run_mft_parser | 8312ms | 2026-09-19T20:01:03 | |
| tc_677fa84a | run_bulk_extractor | 9384ms | 2026-09-19T20:01:04 | |
| tc_7643f576 | run_fls | 17856ms | 2026-09-19T20:01:12 | |
| tc_8809a1ab | run_bulk_extractor | 107053ms | 2026-09-19T20:02:42 | |
| tc_97db2ec7 | run_bulk_extractor | 109406ms | 2026-09-19T20:02:44 | |
| tc_96e4a04b | run_bulk_extractor | 343098ms | 2026-09-19T20:06:38 | |
| tc_2f02ff8f | get_completed_results | 0ms | 2026-09-19T20:06:40 | |
| tc_b41c0821 | start_extraction_batch | 9ms | 2026-09-19T20:06:48 | |
| tc_570cb1da | run_amcache_parser | 0ms | 2026-09-19T20:07:02 | |
| tc_9eb3e729 | detect_masquerading | 6100ms | 2026-09-19T20:07:08 | |
| tc_4e8e7d7e | run_evtx_parser | 19201ms | 2026-09-19T20:07:13 | |
| tc_af92ace0 | detect_masquerading | 4909ms | 2026-09-19T20:07:13 | |
| tc_1cd93a63 | detect_masquerading | 0ms | 2026-09-19T20:07:13 | |
| tc_4d185fe0 | run_shimcache_parser | 21072ms | 2026-09-19T20:07:14 | |
| tc_2914cb8d | query_registry_value | 19657ms | 2026-09-19T20:07:15 | |
| tc_6a24bf13 | parse_browser_history | 23751ms | 2026-09-19T20:07:19 | |
| tc_0c767bd7 | run_hayabusa | 28707ms | 2026-09-19T20:07:22 | |
| tc_a9928c82 | query_registry_value | 27633ms | 2026-09-19T20:07:23 | |
| tc_52e81cfe | query_registry_value | 27706ms | 2026-09-19T20:07:23 | |
| tc_f771dca9 | analyze_disk_pcaps | 28636ms | 2026-09-19T20:07:24 | |
| tc_83c7c047 | query_registry_value | 29038ms | 2026-09-19T20:07:24 | |
| tc_7d7f8be9 | run_prefetch_parser | 34281ms | 2026-09-19T20:07:28 | |
| tc_509498f3 | run_mactime | 39074ms | 2026-09-19T20:07:32 | |
| tc_87da887d | run_registry_parser | 52894ms | 2026-09-19T20:07:41 | |
| tc_df928ac0 | run_bulk_extractor | 711588ms | 2026-09-19T20:08:39 | |
| tc_792f16d8 | get_completed_results | 0ms | 2026-09-19T20:08:41 | |
| tc_a1a0e4ab | start_extraction_batch | 4ms | 2026-09-19T20:09:06 | |
| tc_1b335a94 | run_photorec | 4ms | 2026-09-19T20:09:06 | |
| tc_513d4a13 | run_mft_parser | 26ms | 2026-09-19T20:09:06 | |
| tc_e261c801 | detect_masquerading | 0ms | 2026-09-19T20:09:08 | |
| tc_c80813e8 | run_exiftool | 88ms | 2026-09-19T20:09:08 | |
| tc_4ffb4939 | run_hashdeep | 424ms | 2026-09-19T20:09:08 | |
| tc_d6ef4645 | run_mactime | 3611ms | 2026-09-19T20:09:10 | |
| tc_539b5057 | run_strings | 671ms | 2026-09-19T20:09:14 | |
| tc_b21d3456 | yara_scan_files | 6701ms | 2026-09-19T20:09:15 | |
| tc_527c518b | get_completed_results | 0ms | 2026-09-19T20:09:23 | |
| tc_38245ae9 | open_case | 31ms | 2026-09-19T20:09:38 | |
| tc_ea58f110 | get_investigation_summary | 5ms | 2026-09-19T20:09:42 | |
| tc_b7e12a25 | list_sources | 2ms | 2026-09-19T20:09:42 | |
| tc_12f14b79 | get_raw_output | 118ms | 2026-09-19T20:09:49 | |
| tc_f88b7a7a | get_raw_output | 102ms | 2026-09-19T20:09:51 | |
| tc_d67ae8aa | get_raw_output | 21ms | 2026-09-19T20:09:51 | |
| tc_62987b1e | get_raw_output | 104ms | 2026-09-19T20:10:18 | |
| tc_d1bbd94c | get_raw_output | 103ms | 2026-09-19T20:10:18 | |
| tc_895e4b1b | get_raw_output | 99ms | 2026-09-19T20:10:19 | |
| tc_6d9c776c | get_raw_output | 84ms | 2026-09-19T20:10:35 | |
| tc_532a7d97 | search | 7ms | 2026-09-19T20:10:36 | |
| tc_a4b039b1 | get_raw_output | 24ms | 2026-09-19T20:10:36 | |
| tc_67c35a0e | search | 4ms | 2026-09-19T20:10:45 | |
| tc_b88e2a9b | search | 3ms | 2026-09-19T20:10:45 | |
| tc_46ac5417 | search | 5ms | 2026-09-19T20:10:46 | |
| tc_393cf1ce | search | 4ms | 2026-09-19T20:10:56 | |
| tc_f0925a2e | search | 3ms | 2026-09-19T20:10:57 | |
| tc_f6ac5d20 | search | 5ms | 2026-09-19T20:10:58 | |
| tc_3e22222d | search | 3ms | 2026-09-19T20:11:04 | |
| tc_82e1e3e4 | get_deleted_files | 150ms | 2026-09-19T20:11:04 | |
| tc_1f6ef439 | search | 3ms | 2026-09-19T20:11:05 | |
| tc_0d2e8d40 | run_bulk_extractor | 854434ms | 2026-09-19T20:11:10 | |
| tc_b7d88ffd | search | 9ms | 2026-09-19T20:11:13 | |
| tc_4d5d332a | get_raw_output | 29ms | 2026-09-19T20:11:14 | |
| tc_c9e19e77 | search | 3ms | 2026-09-19T20:11:14 | |
| tc_90be43e2 | get_completed_results | 0ms | 2026-09-19T20:11:15 | |
| tc_f26ac21a | get_raw_output | 113ms | 2026-09-19T20:11:20 | |
| tc_71789dbd | search | 3ms | 2026-09-19T20:11:20 | |
| tc_46252f53 | search | 3ms | 2026-09-19T20:11:21 | |
| tc_f268e215 | start_extraction_batch | 4ms | 2026-09-19T20:11:40 | |
| tc_73c115e3 | detect_masquerading | 0ms | 2026-09-19T20:11:40 | |
| tc_cc93cbdc | run_mft_parser | 40ms | 2026-09-19T20:11:40 | |
| tc_cbe4a670 | run_mactime | 1006ms | 2026-09-19T20:11:41 | |
| tc_79ec605a | run_exiftool | 85ms | 2026-09-19T20:11:41 | |
| tc_a7a2af9c | run_strings | 2558ms | 2026-09-19T20:11:43 | |
| tc_6f8e6e9c | yara_scan_files | 8316ms | 2026-09-19T20:11:49 | |
| tc_97df813f | search | 11ms | 2026-09-19T20:11:53 | |
| tc_de89001e | detect_masquerading | 300015ms | 2026-09-19T20:11:53 | |
| tc_4f50aa15 | search | 3ms | 2026-09-19T20:11:53 | |
| tc_facbb9dd | get_completed_results | 0ms | 2026-09-19T20:11:57 | |
| tc_ce5da528 | search | 3ms | 2026-09-19T20:11:57 | |
| tc_b61a548a | get_raw_output | 11ms | 2026-09-19T20:11:58 | |
| tc_8527a47d | get_completed_results | 0ms | 2026-09-19T20:11:58 | |
| tc_4f23b9af | run_chainsaw | 1426ms | 2026-09-19T20:12:07 | |
| tc_7526da95 | open_case | 31ms | 2026-09-19T20:12:26 | |
| tc_01de4c73 | yara_scan_files | 20685ms | 2026-09-19T20:12:26 | |
| tc_c3bca976 | get_investigation_summary | 5ms | 2026-09-19T20:12:30 | |
| tc_781c5a00 | list_sources | 2ms | 2026-09-19T20:12:30 | |
| tc_5d633d74 | list_partitions | 2ms | 2026-09-19T20:12:30 | |
| tc_27bf2a30 | get_raw_output | 22ms | 2026-09-19T20:12:38 | |
| tc_ec173722 | get_raw_output | 99ms | 2026-09-19T20:12:39 | |
| tc_65432829 | get_raw_output | 101ms | 2026-09-19T20:12:40 | |
| tc_3c7ae72c | submit_finding | 74ms | 2026-09-19T20:12:47 | |
| tc_d42d6199 | open_case | 31ms | 2026-09-19T20:13:01 | |
| tc_4743f57a | search | 5ms | 2026-09-19T20:13:02 | |
| tc_5f00137e | get_raw_output | 100ms | 2026-09-19T20:13:03 | |
| tc_43799fbc | wait_all | 0ms | 2026-09-19T20:13:03 | |
| tc_a3f0d0c1 | get_raw_output | 99ms | 2026-09-19T20:13:04 | |
| tc_336f9f8f | submit_finding | 8ms | 2026-09-19T20:13:06 | |
| tc_a41d526e | open_case | 31ms | 2026-09-19T20:13:14 | |
| tc_9640a91c | search | 4ms | 2026-09-19T20:13:15 | |
| tc_7e1c1241 | get_raw_output | 11ms | 2026-09-19T20:13:16 | |
| tc_6ad4d887 | get_raw_output | 30ms | 2026-09-19T20:13:16 | |
| tc_d000ecc6 | get_investigation_summary | 5ms | 2026-09-19T20:13:17 | |
| tc_223ab028 | list_sources | 2ms | 2026-09-19T20:13:17 | |
| tc_38170e9e | submit_finding | 10ms | 2026-09-19T20:13:20 | |
| tc_8bbde21a | get_findings | 1ms | 2026-09-19T20:13:25 | |
| tc_decdaf2e | get_raw_output | 102ms | 2026-09-19T20:13:26 | |
| tc_af2aabc4 | search | 5ms | 2026-09-19T20:13:26 | |
| tc_0ad0039a | search | 4ms | 2026-09-19T20:13:27 | |
| tc_7f5abba9 | get_raw_output | 99ms | 2026-09-19T20:13:28 | |
| tc_5176505e | search | 3ms | 2026-09-19T20:13:29 | |
| tc_9373d670 | search | 11ms | 2026-09-19T20:13:30 | |
| tc_e61bdc86 | submit_finding | 10ms | 2026-09-19T20:13:34 | |
| tc_8478da81 | get_raw_output | 101ms | 2026-09-19T20:13:36 | |
| tc_44f9e584 | search | 5ms | 2026-09-19T20:13:37 | |
| tc_2beaa53c | get_raw_output | 100ms | 2026-09-19T20:13:38 | |
| tc_9e1064ac | query_registry_value | 4814ms | 2026-09-19T20:13:39 | |
| tc_ca7900d6 | search | 5ms | 2026-09-19T20:13:39 | |
| tc_247a599e | get_raw_output | 20ms | 2026-09-19T20:13:39 | |
| tc_9e2a03d3 | get_raw_output | 98ms | 2026-09-19T20:13:39 | |
| tc_97bd88d5 | get_raw_output | 9ms | 2026-09-19T20:13:49 | |
| tc_bfaf8fda | get_raw_output | 97ms | 2026-09-19T20:13:50 | |
| tc_f1c8214a | search | 5ms | 2026-09-19T20:13:51 | |
| tc_a0f52611 | search | 8ms | 2026-09-19T20:13:51 | |
| tc_e6f39a77 | submit_finding | 17ms | 2026-09-19T20:13:52 | |
| tc_1236077e | get_raw_output | 10ms | 2026-09-19T20:13:59 | |
| tc_9e99e9af | search | 4ms | 2026-09-19T20:14:01 | |
| tc_628b2522 | get_raw_output | 100ms | 2026-09-19T20:14:01 | |
| tc_2f1a7111 | get_raw_output | 99ms | 2026-09-19T20:14:02 | |
| tc_fe3dc26b | submit_finding | 15ms | 2026-09-19T20:14:07 | |
| tc_24cae0ce | search | 8ms | 2026-09-19T20:14:11 | |
| tc_82b27a64 | search | 3ms | 2026-09-19T20:14:12 | |
| tc_0c33ddac | bookmark_window | 11ms | 2026-09-19T20:14:16 | |
| tc_4dd992d9 | bookmark_window | 11ms | 2026-09-19T20:14:18 | |
| tc_19589fad | search | 3ms | 2026-09-19T20:14:22 | |
| tc_9c417cac | get_raw_output | 30ms | 2026-09-19T20:14:23 | |
| tc_2cd31b75 | search | 3ms | 2026-09-19T20:14:24 | |
| tc_46f8345c | search | 3ms | 2026-09-19T20:14:32 | |
| tc_67ae5f95 | search | 4ms | 2026-09-19T20:14:34 | |
| tc_293e882d | get_raw_output | 99ms | 2026-09-19T20:14:35 | |
| tc_eb524e79 | search | 5ms | 2026-09-19T20:14:35 | |
| tc_02869b8d | submit_finding | 15ms | 2026-09-19T20:14:38 | |
| tc_b7dbfc57 | list_files | 216ms | 2026-09-19T20:14:41 | |
| tc_59fae84e | search | 4ms | 2026-09-19T20:14:41 | |
| tc_0a00bd6e | search | 3ms | 2026-09-19T20:14:42 | |
| tc_64af1c79 | search | 7ms | 2026-09-19T20:14:43 | |
| tc_eb98478b | submit_finding | 17ms | 2026-09-19T20:14:49 | |
| tc_bb05b01c | search | 4ms | 2026-09-19T20:14:50 | |
| tc_ca2004a9 | get_raw_output | 99ms | 2026-09-19T20:14:50 | |
| tc_2ab5967b | search | 8ms | 2026-09-19T20:14:52 | |
| tc_9129ac52 | search | 6ms | 2026-09-19T20:14:53 | |
| tc_914bc2ec | submit_finding | 17ms | 2026-09-19T20:14:55 | |
| tc_6164f7f6 | search | 3ms | 2026-09-19T20:14:59 | |
| tc_b52193cf | search | 3ms | 2026-09-19T20:14:59 | |
| tc_614ce225 | search | 3ms | 2026-09-19T20:15:05 | |
| tc_2491e9ca | search | 3ms | 2026-09-19T20:15:05 | |
| tc_45ac10ec | submit_finding | 16ms | 2026-09-19T20:15:06 | |
| tc_4febb050 | search | 5ms | 2026-09-19T20:15:06 | |
| tc_37df8f97 | submit_finding | 16ms | 2026-09-19T20:15:17 | |
| tc_fe7d1774 | bookmark_window | 12ms | 2026-09-19T20:15:21 | |
| tc_88406e78 | bookmark_window | 11ms | 2026-09-19T20:15:24 | |
| tc_cd3dce9a | submit_finding | 17ms | 2026-09-19T20:15:25 | |
| tc_0b0112c3 | bookmark_window | 11ms | 2026-09-19T20:15:26 | |
| tc_1c96587a | search | 4ms | 2026-09-19T20:15:28 | |
| tc_49bb0cdc | get_raw_output | 100ms | 2026-09-19T20:15:28 | |
| tc_f1270fed | search | 12ms | 2026-09-19T20:15:29 | |
| tc_fced7036 | search | 4ms | 2026-09-19T20:15:29 | |
| tc_24dd2874 | search | 4ms | 2026-09-19T20:15:37 | |
| tc_8f6e736e | search | 3ms | 2026-09-19T20:15:38 | |
| tc_7f65e9f2 | search | 6ms | 2026-09-19T20:15:39 | |
| tc_06c1de6a | submit_finding | 16ms | 2026-09-19T20:15:42 | |
| tc_27c06c83 | track_progress | 13ms | 2026-09-19T20:15:45 | |
| tc_c1fe3c55 | submit_finding | 16ms | 2026-09-19T20:15:56 | |
| tc_2fa622d5 | search | 6ms | 2026-09-19T20:16:00 | |
| tc_92db7fe9 | search | 4ms | 2026-09-19T20:16:01 | |
| tc_ca5339c7 | get_raw_output | 82ms | 2026-09-19T20:16:02 | |
| tc_150847e3 | get_raw_output | 98ms | 2026-09-19T20:16:02 | |
| tc_4f1fe60d | search | 3ms | 2026-09-19T20:16:03 | |
| tc_531559d2 | search | 5ms | 2026-09-19T20:16:04 | |
| tc_7dcfeb90 | get_investigation_summary | 6ms | 2026-09-19T20:16:04 | |
| tc_5c3514df | update_finding | 14ms | 2026-09-19T20:16:07 | |
| tc_359827b4 | open_case | 31ms | 2026-09-19T20:16:10 | |
| tc_0d4ec4c1 | list_directory | 2ms | 2026-09-19T20:16:10 | |
| tc_a1c8e852 | list_sources | 3ms | 2026-09-19T20:16:19 | |
| tc_ed187b9e | submit_finding | 15ms | 2026-09-19T20:16:25 | |
| tc_802e994f | submit_finding | 17ms | 2026-09-19T20:16:31 | |
| tc_05d77868 | submit_finding | 15ms | 2026-09-19T20:16:44 | |
| tc_71ef37d8 | submit_finding | 16ms | 2026-09-19T20:17:02 | |
| tc_a1c06eb2 | submit_finding | 15ms | 2026-09-19T20:17:23 | |
| tc_46cce383 | search | 3ms | 2026-09-19T20:17:27 | |
| tc_54511de3 | search | 6ms | 2026-09-19T20:17:28 | |
| tc_a110b292 | get_raw_output | 99ms | 2026-09-19T20:17:29 | |
| tc_06ad3173 | search | 5ms | 2026-09-19T20:17:40 | |
| tc_75c1e5d9 | search | 3ms | 2026-09-19T20:17:41 | |
| tc_e8401491 | get_raw_output | 10ms | 2026-09-19T20:17:49 | |
| tc_eb7fef9f | submit_finding | 16ms | 2026-09-19T20:18:09 | |
| tc_73e4c505 | get_findings | 2ms | 2026-09-19T20:18:11 | |
| tc_ca370897 | submit_finding | 16ms | 2026-09-19T20:18:53 | |
| tc_62dfd609 | submit_finding | 17ms | 2026-09-19T20:19:09 | |
| tc_535a275e | open_case | 33ms | 2026-09-19T20:19:15 | |
| tc_f87e949a | search | 4ms | 2026-09-19T20:19:15 | |
| tc_013d88d0 | search | 4ms | 2026-09-19T20:19:16 | |
| tc_28fce04e | search | 4ms | 2026-09-19T20:19:17 | |
| tc_c902226c | run_exiftool | 95ms | 2026-09-19T20:19:21 | |
| tc_29415098 | run_hashdeep | 486ms | 2026-09-19T20:19:22 | |
| tc_8c87095d | run_strings | 871ms | 2026-09-19T20:19:22 | |
| tc_405f9edc | search | 3ms | 2026-09-19T20:19:26 | |
| tc_b6b7e690 | search | 5ms | 2026-09-19T20:19:27 | |
| tc_2b98671d | yara_scan_files | 6610ms | 2026-09-19T20:19:28 | |
| tc_eacc58a8 | extract_optical_file | 0ms | 2026-09-19T20:19:35 | |
| tc_331ce70d | search | 4ms | 2026-09-19T20:19:36 | |
| tc_53423a28 | search | 3ms | 2026-09-19T20:19:36 | |
| tc_8774bdf4 | search | 3ms | 2026-09-19T20:19:42 | |
| tc_5b7bbc9b | search | 3ms | 2026-09-19T20:19:44 | |
| tc_1170fb64 | search | 5ms | 2026-09-19T20:19:47 | |
| tc_a7f5c3e0 | search | 5ms | 2026-09-19T20:19:48 | |
| tc_2bc81e0d | update_finding | 13ms | 2026-09-19T20:19:58 | |
| tc_551daa12 | search | 3ms | 2026-09-19T20:20:02 | |
| tc_482fac80 | search | 5ms | 2026-09-19T20:20:03 | |
| tc_434e6b5f | extract_optical_file | 83ms | 2026-09-19T20:20:05 | |
| tc_19745a47 | extract_optical_file | 86ms | 2026-09-19T20:20:05 | |
| tc_65d1ad2c | extract_optical_file | 100ms | 2026-09-19T20:20:05 | |
| tc_b32788d6 | extract_optical_file | 101ms | 2026-09-19T20:20:05 | |
| tc_f885c13c | extract_optical_file | 134ms | 2026-09-19T20:20:05 | |
| tc_aa5059bb | extract_optical_file | 142ms | 2026-09-19T20:20:05 | |
| tc_24f3365d | extract_optical_file | 143ms | 2026-09-19T20:20:05 | |
| tc_9fedbbfb | extract_optical_file | 146ms | 2026-09-19T20:20:05 | |
| tc_cc274e2d | extract_optical_file | 64ms | 2026-09-19T20:20:05 | |
| tc_59767766 | extract_optical_file | 63ms | 2026-09-19T20:20:05 | |
| tc_c36bebe1 | extract_optical_file | 82ms | 2026-09-19T20:20:05 | |
| tc_034105a7 | extract_optical_file | 54ms | 2026-09-19T20:20:05 | |
| tc_b73035f9 | extract_optical_file | 114ms | 2026-09-19T20:20:05 | |
| tc_3331dbed | extract_optical_file | 76ms | 2026-09-19T20:20:05 | |
| tc_ae4ca1ed | extract_optical_file | 85ms | 2026-09-19T20:20:05 | |
| tc_f7884609 | extract_optical_file | 70ms | 2026-09-19T20:20:05 | |
| tc_34306b05 | extract_optical_file | 87ms | 2026-09-19T20:20:05 | |
| tc_b031dc9a | extract_optical_file | 70ms | 2026-09-19T20:20:05 | |
| tc_24965fd9 | extract_optical_file | 106ms | 2026-09-19T20:20:05 | |
| tc_419499ae | extract_optical_file | 70ms | 2026-09-19T20:20:05 | |
| tc_5112a25c | extract_optical_file | 53ms | 2026-09-19T20:20:05 | |
| tc_07948a6b | extract_optical_file | 90ms | 2026-09-19T20:20:05 | |
| tc_1c57b628 | extract_optical_file | 85ms | 2026-09-19T20:20:05 | |
| tc_f5115e23 | extract_optical_file | 89ms | 2026-09-19T20:20:05 | |
| tc_9ea8cf94 | extract_optical_file | 102ms | 2026-09-19T20:20:05 | |
| tc_7fae75a5 | extract_optical_file | 87ms | 2026-09-19T20:20:05 | |
| tc_1459941e | extract_optical_file | 85ms | 2026-09-19T20:20:05 | |
| tc_55606732 | extract_optical_file | 158ms | 2026-09-19T20:20:05 | |
| tc_2181caa1 | extract_optical_file | 156ms | 2026-09-19T20:20:05 | |
| tc_c3b76c3a | extract_optical_file | 70ms | 2026-09-19T20:20:05 | |
| tc_a385242d | extract_optical_file | 78ms | 2026-09-19T20:20:05 | |
| tc_21f4ff65 | extract_optical_file | 80ms | 2026-09-19T20:20:05 | |
| tc_908ce257 | extract_optical_file | 80ms | 2026-09-19T20:20:05 | |
| tc_91082f8e | extract_optical_file | 81ms | 2026-09-19T20:20:05 | |
| tc_b7164f8d | extract_optical_file | 80ms | 2026-09-19T20:20:05 | |
| tc_e37d4f25 | extract_optical_file | 57ms | 2026-09-19T20:20:05 | |
| tc_8710ecf6 | get_raw_output | 10ms | 2026-09-19T20:20:07 | |
| tc_c2a019c6 | extract_optical_file | 51ms | 2026-09-19T20:20:10 | |
| tc_21d83aa5 | track_progress | 13ms | 2026-09-19T20:20:25 | |
| tc_958cc36c | analyze_pdf | 0ms | 2026-09-19T20:20:29 | |
| tc_97f9ce4c | analyze_office_document | 0ms | 2026-09-19T20:20:29 | |
| tc_2618b300 | detect_steganography | 183ms | 2026-09-19T20:20:29 | |
| tc_65a9384f | get_investigation_summary | 5ms | 2026-09-19T20:20:33 | |
| tc_79ddc3da | submit_finding | 10ms | 2026-09-19T20:20:44 | |
| tc_10aa412f | open_case | 31ms | 2026-09-19T20:20:55 | |
| tc_a0aae92d | get_investigation_summary | 5ms | 2026-09-19T20:20:58 | |
| tc_7cb38d6d | list_sources | 2ms | 2026-09-19T20:20:58 | |
| tc_331abe1f | submit_finding | 16ms | 2026-09-19T20:21:01 | |
| tc_30b0ed61 | search | 5ms | 2026-09-19T20:21:05 | |
| tc_c3661661 | search | 3ms | 2026-09-19T20:21:05 | |
| tc_68795a10 | get_findings | 2ms | 2026-09-19T20:21:06 | |
| tc_b8a8b6ad | get_raw_output | 101ms | 2026-09-19T20:21:07 | |
| tc_22848d76 | get_raw_output | 100ms | 2026-09-19T20:21:07 | |
| tc_1829697a | get_raw_output | 12ms | 2026-09-19T20:21:09 | |
| tc_756b7de1 | get_findings | 1ms | 2026-09-19T20:21:22 | |
| tc_ac184a8c | get_raw_output | 100ms | 2026-09-19T20:21:23 | |
| tc_c0ed9ce1 | get_raw_output | 101ms | 2026-09-19T20:21:24 | |
| tc_595504ec | search | 5ms | 2026-09-19T20:21:24 | |
| tc_1aa8685b | get_raw_output | 29ms | 2026-09-19T20:21:32 | |
| tc_a46c0d82 | search | 3ms | 2026-09-19T20:21:32 | |
| tc_b1d2c51e | get_raw_output | 24ms | 2026-09-19T20:21:33 | |
| tc_8b3c8603 | submit_finding | 17ms | 2026-09-19T20:21:35 | |
| tc_629dba26 | get_raw_output | 30ms | 2026-09-19T20:21:42 | |
| tc_5dcbe8c5 | search | 18ms | 2026-09-19T20:21:43 | |
| tc_b17a62bf | search | 3ms | 2026-09-19T20:21:44 | |
| tc_0d96ed96 | submit_finding | 14ms | 2026-09-19T20:21:51 | |
| tc_37144a43 | update_finding | 13ms | 2026-09-19T20:21:57 | |
| tc_a2c1ba73 | search | 6ms | 2026-09-19T20:21:59 | |
| tc_22be6ae1 | get_raw_output | 21ms | 2026-09-19T20:22:00 | |
| tc_902b2ab6 | search | 3ms | 2026-09-19T20:22:01 | |
| tc_5de8b591 | submit_finding | 16ms | 2026-09-19T20:22:25 | |
| tc_32f79702 | detect_steganography | 0ms | 2026-09-19T20:22:30 | |
| tc_a4d9c259 | search | 7ms | 2026-09-19T20:22:31 | |
| tc_abde6e1f | search | 3ms | 2026-09-19T20:22:31 | |
| tc_c54bacf1 | search | 3ms | 2026-09-19T20:22:31 | |
| tc_592fd970 | search | 4ms | 2026-09-19T20:22:41 | |
| tc_e1bf8ffe | search | 4ms | 2026-09-19T20:22:42 | |
| tc_1a86b3fa | search | 7ms | 2026-09-19T20:22:52 | |
| tc_22dfb308 | search | 3ms | 2026-09-19T20:23:04 | |
| tc_ffffae1f | bookmark_window | 11ms | 2026-09-19T20:23:04 | |
| tc_25ee53d8 | search | 3ms | 2026-09-19T20:23:04 | |
| tc_cd65d07a | bookmark_window | 11ms | 2026-09-19T20:23:06 | |
| tc_2fc026db | get_raw_output | 10ms | 2026-09-19T20:23:10 | |
| tc_a391d3b7 | submit_finding | 16ms | 2026-09-19T20:23:37 | |
| tc_875be0b4 | get_raw_output | 101ms | 2026-09-19T20:23:39 | |
| tc_a595ac42 | search | 3ms | 2026-09-19T20:23:40 | |
| tc_7b74272d | get_raw_output | 10ms | 2026-09-19T20:23:42 | |
| tc_5710e16c | get_raw_output | 21ms | 2026-09-19T20:24:05 | |
| tc_d2824989 | search | 3ms | 2026-09-19T20:24:06 | |
| tc_2ad86f46 | get_raw_output | 98ms | 2026-09-19T20:24:09 | |
| tc_65681ab9 | update_finding | 14ms | 2026-09-19T20:24:36 | |
| tc_750e3f49 | get_findings | 2ms | 2026-09-19T20:24:36 | |
| tc_b176cecf | get_findings | 2ms | 2026-09-19T20:24:40 | |
| tc_92ee1248 | submit_finding | 15ms | 2026-09-19T20:25:00 | |
| tc_a79ee921 | search | 3ms | 2026-09-19T20:25:11 | |
| tc_1e645d03 | submit_finding | 16ms | 2026-09-19T20:25:26 | |
| tc_bd1cba01 | search | 3ms | 2026-09-19T20:25:29 | |
| tc_8db29125 | list_sources | 2ms | 2026-09-19T20:25:29 | |
| tc_68f03228 | submit_finding | 15ms | 2026-09-19T20:25:54 | |
| tc_26018347 | get_raw_output | 10ms | 2026-09-19T20:26:07 | |
| tc_4812264a | submit_finding | 15ms | 2026-09-19T20:26:17 | |
| tc_66130bd6 | submit_finding | 14ms | 2026-09-19T20:26:29 | |
| tc_fa7c3c68 | update_finding | 13ms | 2026-09-19T20:26:38 | |
| tc_6e013b44 | submit_finding | 15ms | 2026-09-19T20:26:54 | |
| tc_40f7218a | submit_finding | 16ms | 2026-09-19T20:26:58 | |
| tc_c9968a40 | get_investigation_summary | 4ms | 2026-09-19T20:27:01 | |
| tc_e48e1d3a | track_progress | 13ms | 2026-09-19T20:27:11 | |
| tc_f743a00f | get_investigation_summary | 5ms | 2026-09-19T20:27:46 | |
| tc_da55dc6e | track_progress | 12ms | 2026-09-19T20:27:55 | |
| tc_a5caa83d | get_investigation_summary | 5ms | 2026-09-19T20:28:15 | |
| tc_8c88c671 | open_case | 31ms | 2026-09-19T20:28:20 | |
| tc_75bd86cb | get_findings | 3ms | 2026-09-19T20:28:23 | |
| tc_aec1ef00 | get_investigation_summary | 5ms | 2026-09-19T20:28:23 | |
| tc_704cb1a3 | list_sources | 2ms | 2026-09-19T20:28:23 | |
| tc_968362d1 | get_source_stats | 101ms | 2026-09-19T20:28:24 | |
| tc_5d7aa48c | get_bookmarks | 3ms | 2026-09-19T20:28:24 | |
| tc_075294ed | get_findings | 2ms | 2026-09-19T20:28:28 | |
| tc_2f4d9fdb | get_timeline | 22ms | 2026-09-19T20:28:29 | |
| tc_6fa0c48a | open_case | 32ms | 2026-09-19T20:29:48 | |
| tc_2d28557e | analyze_execution_timeline._query(ez.shimcache) | 20ms | 2026-09-19T20:30:36 | |
| tc_9f77d879 | find_execution_evidence._query(ez.shimcache) | 18ms | 2026-09-19T20:30:36 | |
| tc_406d53e8 | analyze_execution_timeline | 65ms | 2026-09-19T20:30:36 | |
| tc_b4cececb | reconstruct_execution_chains._query(volatility.pstree) | 71ms | 2026-09-19T20:30:36 | |
| tc_00f4f3f8 | find_execution_evidence | 79ms | 2026-09-19T20:30:36 | |
| tc_879145c1 | reconstruct_execution_chains._query(volatility.cmdline) | 13ms | 2026-09-19T20:30:36 | |
| tc_6077e147 | find_defense_evasion._search(all) | 109ms | 2026-09-19T20:30:36 | |
| tc_5a97e16b | reconstruct_execution_chains._query(volatility.netscan) | 15ms | 2026-09-19T20:30:36 | |
| tc_ebbb7847 | find_defense_evasion._search(ez.mft) | 18ms | 2026-09-19T20:30:36 | |
| tc_4e62c35f | reconstruct_execution_chains._query(volatility.malfind) | 48ms | 2026-09-19T20:30:36 | |
| tc_d364fc83 | reconstruct_execution_chains | 172ms | 2026-09-19T20:30:36 | |
| tc_f97d3e7f | find_defense_evasion._search(all) | 43ms | 2026-09-19T20:30:36 | |
| tc_52ae5070 | correlate_pcap_with_host | 0ms | 2026-09-19T20:30:36 | |
| tc_e2112d6f | find_file_staging._search(tsk.filelist) | 15ms | 2026-09-19T20:30:36 | |
| tc_fc275573 | find_defense_evasion._search(all) | 18ms | 2026-09-19T20:30:36 | |
| tc_50b41624 | find_file_staging._search(ez.mft) | 22ms | 2026-09-19T20:30:36 | |
| tc_55b5d0df | find_defense_evasion._search(all) | 17ms | 2026-09-19T20:30:36 | |
| tc_4b151b53 | find_defense_evasion | 235ms | 2026-09-19T20:30:36 | |
| tc_34c2e01a | correlate_across_sources | 365ms | 2026-09-19T20:30:37 | |
| tc_2fc28d99 | correlate_across_sources | 507ms | 2026-09-19T20:30:37 | |
| tc_e77292b7 | correlate_across_sources | 591ms | 2026-09-19T20:30:37 | |
| tc_009d6086 | correlate_across_sources | 627ms | 2026-09-19T20:30:37 | |
| tc_535a136d | correlate_across_sources | 608ms | 2026-09-19T20:30:37 | |
| tc_a9017d4b | find_file_staging._query(tsk.filelist) | 591ms | 2026-09-19T20:30:37 | |
| tc_1627cc1d | correlate_across_sources | 716ms | 2026-09-19T20:30:37 | |
| tc_02eb8a48 | find_file_staging._query(ez.mft) | 277ms | 2026-09-19T20:30:37 | |
| tc_d8585d8e | find_file_staging._search(ez.mft) | 148ms | 2026-09-19T20:30:38 | |
| tc_1884b486 | find_data_exfiltration_indicators._query(bulk.url) | 1608ms | 2026-09-19T20:30:38 | |
| tc_a03b2c7a | find_file_staging._search(ez.mft) | 74ms | 2026-09-19T20:30:38 | |
| tc_77aea2df | find_file_staging | 1625ms | 2026-09-19T20:30:38 | |
| tc_0d1f87a5 | find_data_exfiltration_indicators._query(bulk.email) | 13ms | 2026-09-19T20:30:39 | |
| tc_f6463f9c | find_data_exfiltration_indicators._query(bulk.domain) | 159ms | 2026-09-19T20:30:39 | |
| tc_255d9424 | find_data_exfiltration_indicators._search(all) | 64ms | 2026-09-19T20:30:39 | |
| tc_9bf32f83 | find_data_exfiltration_indicators | 2931ms | 2026-09-19T20:30:39 | |
| tc_69ade31b | open_case | 33ms | 2026-09-19T20:31:20 | |
| tc_8907bac0 | get_investigation_summary | 6ms | 2026-09-19T20:31:22 | |
| tc_97ce2e6f | list_sources | 2ms | 2026-09-19T20:31:23 | |
| tc_cdee811f | get_findings | 2ms | 2026-09-19T20:31:23 | |
| tc_3f1b5f08 | get_findings | 2ms | 2026-09-19T20:31:27 | |
| tc_3845b160 | get_raw_output | 101ms | 2026-09-19T20:31:28 | |
| tc_01eb9753 | get_raw_output | 100ms | 2026-09-19T20:31:28 | |
| tc_75898c6a | get_raw_output | 100ms | 2026-09-19T20:31:34 | |
| tc_680ef6a6 | get_raw_output | 99ms | 2026-09-19T20:31:34 | |
| tc_f5536811 | get_raw_output | 100ms | 2026-09-19T20:31:35 | |
| tc_70ba2377 | search | 5ms | 2026-09-19T20:31:43 | |
| tc_d32d9910 | search | 6ms | 2026-09-19T20:31:45 | |
| tc_5fffd349 | search | 4ms | 2026-09-19T20:31:46 | |
| tc_a8fe2dc1 | search | 6ms | 2026-09-19T20:31:53 | |
| tc_edead4e7 | search | 4ms | 2026-09-19T20:31:54 | |
| tc_d0a4d731 | search | 8ms | 2026-09-19T20:31:55 | |
| tc_754cd2ae | get_raw_output | 102ms | 2026-09-19T20:32:05 | |
| tc_83273c80 | get_raw_output | 100ms | 2026-09-19T20:32:06 | |
| tc_373acc1e | get_raw_output | 101ms | 2026-09-19T20:32:06 | |
| tc_6da0ef72 | lookup_attack_technique | 569ms | 2026-09-19T20:33:00 | |
| tc_8011990e | lookup_attack_technique | 0ms | 2026-09-19T20:33:00 | |
| tc_7adf830a | lookup_attack_technique | 1ms | 2026-09-19T20:33:01 | |
| tc_87c84a9f | submit_finding | 16ms | 2026-09-19T20:33:34 | |
| tc_0c60952b | submit_finding | 16ms | 2026-09-19T20:34:03 | |
| tc_c1012d66 | submit_finding | 15ms | 2026-09-19T20:34:26 | |
| tc_4f01bd00 | search | 4ms | 2026-09-19T20:34:30 | |
| tc_ebedaa32 | search | 5ms | 2026-09-19T20:34:31 | |
| tc_b61cdd39 | search | 4ms | 2026-09-19T20:34:39 | |
| tc_ab549bb9 | search | 5ms | 2026-09-19T20:34:40 | |
| tc_3aabfd50 | delete_finding | 12ms | 2026-09-19T20:35:07 | |
| tc_c9c629ed | delete_finding | 11ms | 2026-09-19T20:35:08 | |
| tc_1f84cccd | delete_finding | 11ms | 2026-09-19T20:35:08 | |
| tc_749f7c2f | delete_finding | 11ms | 2026-09-19T20:35:08 | |
| tc_5950b0c1 | delete_finding | 11ms | 2026-09-19T20:35:09 | |
| tc_d515b990 | delete_finding | 11ms | 2026-09-19T20:35:13 | |
| tc_207865ef | delete_finding | 11ms | 2026-09-19T20:35:13 | |
| tc_83236b1a | delete_finding | 11ms | 2026-09-19T20:35:14 | |
| tc_38928c06 | update_finding | 14ms | 2026-09-19T20:35:35 | |
| tc_8edba7e2 | update_finding | 12ms | 2026-09-19T20:35:48 | |
| tc_5066be6e | update_finding | 11ms | 2026-09-19T20:36:02 | |
| tc_c06b78be | delete_finding | 11ms | 2026-09-19T20:36:02 | |
| tc_1b577aca | get_ioc_summary | 651ms | 2026-09-19T20:36:06 | |
| tc_4a839002 | get_findings | 2ms | 2026-09-19T20:36:06 | |
| tc_3febca2c | get_raw_output | 100ms | 2026-09-19T20:37:39 | |
| tc_da2f276a | search | 6ms | 2026-09-19T20:37:39 | |
| tc_82e86e9a | search | 4ms | 2026-09-19T20:37:40 | |
| tc_d1ca0391 | search | 4ms | 2026-09-19T20:37:46 | |
| tc_9f3e3cea | search | 3ms | 2026-09-19T20:37:46 | |
| tc_3fdcefd9 | search | 4ms | 2026-09-19T20:37:47 | |
| tc_d0efb232 | search | 3ms | 2026-09-19T20:38:02 | |
| tc_2ea567cd | search | 5ms | 2026-09-19T20:38:02 | |
| tc_d666451d | search | 4ms | 2026-09-19T20:38:03 | |
| tc_4fcd5f08 | search | 3ms | 2026-09-19T20:38:13 | |
| tc_e6929599 | search | 3ms | 2026-09-19T20:38:13 | |
| tc_9e03e67e | search | 3ms | 2026-09-19T20:38:14 | |
| tc_c43a20d8 | get_raw_output | 10ms | 2026-09-19T20:38:19 | |
| tc_50fcca9c | search | 3ms | 2026-09-19T20:38:20 | |
| tc_2308f2c6 | search | 4ms | 2026-09-19T20:38:20 | |
| tc_a684547d | get_findings | 2ms | 2026-09-19T20:38:39 | |
| tc_701b3a64 | search | 4ms | 2026-09-19T20:38:45 | |
| tc_686ae07c | search | 3ms | 2026-09-19T20:38:46 | |
| tc_80ed30b7 | search | 3ms | 2026-09-19T20:38:46 | |
| tc_507a3065 | get_raw_output | 10ms | 2026-09-19T20:38:53 | |
| tc_2d80233a | search | 3ms | 2026-09-19T20:38:54 | |
| tc_f8dce5f0 | submit_finding | 14ms | 2026-09-19T20:39:24 | |
| tc_c8cc648e | submit_finding | 16ms | 2026-09-19T20:39:34 | |
| tc_62cc037f | search | 6ms | 2026-09-19T20:39:42 | |
| tc_9c5c04d2 | search | 6ms | 2026-09-19T20:39:43 | |
| tc_aec4e36b | update_finding | 13ms | 2026-09-19T20:39:55 | |
| tc_8c7fcb45 | search | 4ms | 2026-09-19T20:39:59 | |
| tc_b0bc169e | search | 3ms | 2026-09-19T20:40:00 | |
| tc_4aa7b784 | get_raw_output | 98ms | 2026-09-19T20:40:13 | |
| tc_70477b9f | search | 5ms | 2026-09-19T20:40:14 | |
| tc_92f2379a | search | 3ms | 2026-09-19T20:40:25 | |
| tc_7eb5ce57 | search | 3ms | 2026-09-19T20:40:25 | |
| tc_56d24f56 | get_investigation_summary | 4ms | 2026-09-19T20:40:29 | |
| tc_56cbbe81 | get_findings | 2ms | 2026-09-19T20:40:33 | |
| tc_c3dab416 | get_findings | 2ms | 2026-09-19T20:40:39 | |
| tc_ffef54ed | get_findings | 2ms | 2026-09-19T20:40:43 | |
| tc_9142e342 | delete_finding | 12ms | 2026-09-19T20:41:30 | |
| tc_09e2cc59 | delete_finding | 11ms | 2026-09-19T20:41:31 | |
| tc_68209b88 | delete_finding | 12ms | 2026-09-19T20:41:31 | |
| tc_5e58a044 | delete_finding | 13ms | 2026-09-19T20:41:31 | |
| tc_8ca82c48 | delete_finding | 11ms | 2026-09-19T20:41:32 | |
| tc_6ccab090 | update_finding | 13ms | 2026-09-19T20:41:51 | |
| tc_d84bca85 | delete_finding | 11ms | 2026-09-19T20:41:52 | |
| tc_3b09938c | update_finding | 13ms | 2026-09-19T20:42:04 | |
| tc_4018aa9f | delete_finding | 11ms | 2026-09-19T20:42:09 | |
| tc_de6ce5c2 | update_finding | 12ms | 2026-09-19T20:42:25 | |
| tc_e82e5057 | delete_finding | 11ms | 2026-09-19T20:42:29 | |
| tc_4b0b10cc | update_finding | 13ms | 2026-09-19T20:42:56 | |
| tc_7d80626d | enrich_iocs | 125ms | 2026-09-19T20:43:03 | |
| tc_1f78296d | get_investigation_summary | 3ms | 2026-09-19T20:43:03 | |
| tc_78961313 | update_finding | 14ms | 2026-09-19T20:43:39 | |
| tc_19b414af | update_finding | 13ms | 2026-09-19T20:43:40 | |
| tc_66b26088 | search | 6ms | 2026-09-19T20:43:46 | |
| tc_a6b97a0a | search | 3ms | 2026-09-19T20:43:47 | |
| tc_bd7b40f0 | get_source_stats | 99ms | 2026-09-19T20:43:59 | |
| tc_ed2b54a6 | track_progress | 14ms | 2026-09-19T20:44:34 | |
| tc_65611963 | get_investigation_summary | 5ms | 2026-09-19T20:45:01 | |
| tc_de330688 | open_case | 34ms | 2026-09-19T20:45:06 | |
| tc_e9e907bf | get_findings | 3ms | 2026-09-19T20:45:08 | |
| tc_05e1e2ad | get_investigation_summary | 5ms | 2026-09-19T20:45:09 | |
| tc_18063f89 | list_sources | 2ms | 2026-09-19T20:45:09 | |
| tc_53d81a7a | get_findings | 2ms | 2026-09-19T20:45:15 | |
| tc_84ae2d95 | get_timeline | 25ms | 2026-09-19T20:45:15 | |
| tc_5a5c22b5 | open_case | 33ms | 2026-09-19T20:47:13 | |
| tc_28861984 | search | 32ms | 2026-09-19T20:49:02 | |
| tc_1d326101 | search | 40ms | 2026-09-19T20:49:02 | |
| tc_08703afa | search | 56ms | 2026-09-19T20:49:02 | |
| tc_b8acc297 | search | 64ms | 2026-09-19T20:49:02 | |
| tc_8f4da285 | search | 28ms | 2026-09-19T20:49:02 | |
| tc_3b2dfb67 | find_file_staging._search(tsk.filelist) | 62ms | 2026-09-19T20:49:02 | |
| tc_8d2d0653 | search | 80ms | 2026-09-19T20:49:02 | |
| tc_038e742c | search | 73ms | 2026-09-19T20:49:02 | |
| tc_f92db7aa | search | 143ms | 2026-09-19T20:49:02 | |
| tc_b827042b | deduplicate_findings | 67ms | 2026-09-19T20:49:02 | |
| tc_2d314b8c | search | 89ms | 2026-09-19T20:49:02 | |
| tc_7654ea49 | find_file_staging._search(ez.mft) | 76ms | 2026-09-19T20:49:02 | |
| tc_1e2a7b1c | get_source_stats | 183ms | 2026-09-19T20:49:02 | |
| tc_b13d89e7 | find_file_staging._query(tsk.filelist) | 115ms | 2026-09-19T20:49:02 | |
| tc_db1a0c95 | detect_timestomping | 886ms | 2026-09-19T20:49:03 | |
| tc_84d41df4 | find_file_staging._query(ez.mft) | 638ms | 2026-09-19T20:49:03 | |
| tc_31441b9d | find_file_staging._search(ez.mft) | 19ms | 2026-09-19T20:49:03 | |
| tc_704e7b93 | find_file_staging._search(ez.mft) | 9ms | 2026-09-19T20:49:03 | |
| tc_ae60a2ea | find_file_staging | 1328ms | 2026-09-19T20:49:03 | |
| tc_3ab430ac | correlate_across_sources | 1701ms | 2026-09-19T20:49:04 | |
| tc_7990bd79 | search | 4ms | 2026-09-19T20:49:07 | |
| tc_0a323957 | search | 7ms | 2026-09-19T20:49:30 | |
| tc_4f0d39e2 | search | 8ms | 2026-09-19T20:49:30 | |
| tc_18a3277a | search | 9ms | 2026-09-19T20:49:30 | |
| tc_0a1be91f | search | 14ms | 2026-09-19T20:49:39 | |
| tc_b65f91f2 | search | 23ms | 2026-09-19T20:49:39 | |
| tc_1107133a | search | 37ms | 2026-09-19T20:49:39 | |
| tc_2f22a660 | detect_timestomping | 329ms | 2026-09-19T20:49:40 | |
| tc_13124891 | search | 10ms | 2026-09-19T20:49:50 | |
| tc_22c7222a | search | 11ms | 2026-09-19T20:49:50 | |
| tc_5560642a | find_file_staging._search(tsk.filelist) | 14ms | 2026-09-19T20:49:50 | |
| tc_0b6a3f18 | find_file_staging._search(ez.mft) | 8ms | 2026-09-19T20:49:50 | |
| tc_71bca53b | find_file_staging._query(tsk.filelist) | 100ms | 2026-09-19T20:49:51 | |
| tc_422bd909 | find_file_staging._query(ez.mft) | 159ms | 2026-09-19T20:49:51 | |
| tc_981f2e5c | find_file_staging._search(ez.mft) | 17ms | 2026-09-19T20:49:51 | |
| tc_9dd823f6 | find_file_staging._search(ez.mft) | 9ms | 2026-09-19T20:49:51 | |
| tc_27051ed3 | find_file_staging | 680ms | 2026-09-19T20:49:51 | |
| tc_beb77c8a | search | 32ms | 2026-09-19T20:50:11 | |
| tc_f5c238f6 | deduplicate_findings | 52ms | 2026-09-19T20:50:12 | |
| tc_fbf1b96a | search | 58ms | 2026-09-19T20:50:12 | |
| tc_fcf81019 | get_source_stats | 145ms | 2026-09-19T20:50:12 | |
| tc_305597cd | correlate_across_sources | 562ms | 2026-09-19T20:50:12 | |
| tc_4b5ba790 | open_case | 34ms | 2026-09-19T20:51:02 | |
| tc_eb428c82 | get_findings | 2ms | 2026-09-19T20:51:04 | |
| tc_f8babbdc | get_investigation_summary | 5ms | 2026-09-19T20:51:04 | |
| tc_b4bbfc98 | get_findings | 2ms | 2026-09-19T20:51:07 | |
| tc_4e6fe5d8 | search | 5ms | 2026-09-19T20:51:25 | |
| tc_f9fb3d7d | search | 6ms | 2026-09-19T20:51:25 | |
| tc_0a2e3340 | search | 4ms | 2026-09-19T20:51:26 | |
| tc_c79bcb22 | search | 3ms | 2026-09-19T20:51:35 | |
| tc_329e1440 | search | 4ms | 2026-09-19T20:51:35 | |
| tc_2eea072e | search | 3ms | 2026-09-19T20:51:36 | |
| tc_09e43290 | get_raw_output | 100ms | 2026-09-19T20:51:41 | |
| tc_bd98643c | get_raw_output | 99ms | 2026-09-19T20:51:41 | |
| tc_a2ab8e3a | get_raw_output | 99ms | 2026-09-19T20:51:42 | |
| tc_424b098d | get_raw_output | 101ms | 2026-09-19T20:52:35 | |
| tc_115ea3c7 | search | 3ms | 2026-09-19T20:52:36 | |
| tc_8a5f47d9 | search | 4ms | 2026-09-19T20:52:36 | |
| tc_cd9f6ca3 | get_raw_output | 99ms | 2026-09-19T20:52:40 | |
| tc_7daf55d8 | search | 4ms | 2026-09-19T20:52:41 | |
| tc_a7236b0e | update_finding | 13ms | 2026-09-19T20:53:51 | |
| tc_3f883d33 | update_finding | 14ms | 2026-09-19T20:54:36 | |
| tc_867f8dfa | search | 4ms | 2026-09-19T20:55:05 | |
| tc_2b8aea7b | search | 4ms | 2026-09-19T20:55:06 | |
| tc_ec9563b8 | search | 6ms | 2026-09-19T20:55:06 | |
| tc_64f90f66 | get_raw_output | 100ms | 2026-09-19T20:55:10 | |
| tc_238c6428 | audit_evidence_coverage | 451ms | 2026-09-19T20:55:31 | |
| tc_0eebeded | audit_tool_coverage | 2ms | 2026-09-19T20:55:31 | |
| tc_37be9118 | deduplicate_findings | 40ms | 2026-09-19T20:55:50 | |
| tc_bc66d0c3 | check_finalize_readiness | 4ms | 2026-09-19T20:56:00 | |
| tc_51f7b400 | search | 4ms | 2026-09-19T20:56:08 | |
| tc_765e2236 | search | 5ms | 2026-09-19T20:56:08 | |
| tc_836b73b3 | update_finding | 14ms | 2026-09-19T20:56:34 | |
| tc_3e3798f5 | track_progress | 13ms | 2026-09-19T20:57:17 | |
| tc_de971dd5 | get_investigation_summary | 5ms | 2026-09-19T20:57:39 | |
| tc_49a69095 | check_finalize_readiness | 4ms | 2026-09-19T20:57:39 | |
| tc_957823dc | open_case | 10ms | 2026-09-19T20:57:49 | |
| tc_ed8c5847 | get_findings | 2ms | 2026-09-19T20:57:52 | |
| tc_6ed8a5dc | get_investigation_summary | 5ms | 2026-09-19T20:57:53 | |
| tc_d014f67e | get_ioc_summary | 658ms | 2026-09-19T20:57:53 | |
| tc_6c09f85c | get_bookmarks | 3ms | 2026-09-19T20:57:53 | |
| tc_cf9112b9 | get_source_stats | 101ms | 2026-09-19T20:57:54 | |
| tc_90fa5309 | get_findings | 2ms | 2026-09-19T20:58:00 | |
| tc_1f336160 | get_findings | 1ms | 2026-09-19T20:58:00 | |
| tc_941e3704 | get_findings | 1ms | 2026-09-19T20:58:01 | |
| tc_2db554c2 | check_finalize_readiness | 4ms | 2026-09-19T20:58:23 | |
| tc_33b6f975 | audit_evidence_coverage | 458ms | 2026-09-19T20:58:24 | |
| tc_c3ae406b | audit_tool_coverage | 2ms | 2026-09-19T20:58:24 | |
| tc_d0ab6f70 | submit_narrative | 13ms | 2026-09-19T21:01:22 | |
| tc_15e65281 | check_finalize_readiness | 4ms | 2026-09-19T21:01:30 |
Each finding traces back to the specific tool calls that produced the supporting evidence.