Executive Summary

📂25 sources (74 disk, 59 other)
🔍596 tool calls
⏱️1.1 hours elapsed
🚨23 findings (3 critical, 9 high)
19 confirmed
🤔4 inference
🔒 SHA-256 hashes

The attack timeline spans 2015-02-15 to 2015-03-25. The earliest activity was Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2) (2015-02-15). The investigation subsequently uncovered Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3); Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft. The most recent activity was Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Executed After Exfiltration (2015-03-25).

Key Threats
  • Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)
  • Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft
  • Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)

0
Total Findings
0
Critical
0
High
0
Medium
0
Confirmed
0
Inference
0
Sources
0
Tool Calls
Severity Breakdown
Critical (3) High (9) Medium (5) Info (6)
☑ Forensic Soundness and Evidence Integrity
Analysis was executed via a read-only Model Context Protocol (MCP) server mapped to the SANS SIFT toolchain. The MCP architecture enforces structural evidence protection: original evidence files were mounted as read-only volumes, all tool interactions are typed functions (no shell access), and every finding is validated against the append-only audit log before acceptance. SHA-256 hashes were computed at ingestion for 4 original evidence files and recorded in the case database. 596 tool calls executed across 25 indexed sources with full provenance tracking.
⚠ Critical Findings
  • Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)
    2015-02-15T16:51:38 — 2015-03-24T10:00:18
  • Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft
    2015-03-22T14:33:13 — 2015-03-25T15:29:08
  • Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)
    2015-02-15T16:51:38 — 2015-03-24T20:57:03
⚔ MITRE ATT&CK Coverage
Reconnaissance
Resource Development
Initial Access (1)
Execution (2)
Persistence (3)
Privilege Escalation (2)
Defense Evasion (4)
Credential Access
Discovery (1)
Lateral Movement
Collection (2)
Command and Control
Exfiltration (2)
Impact (1)
Inhibit Response Function
Evasion
Impair Process Control
Initial Access (1)Execution (2)Persistence (3)Privilege Escalation (2)Defense Evasion (4)Discovery (1)Collection (2)Exfiltration (2)Impact (1)
14 techniques across 23 findings
★ IOC Summary
External IPs0
Internal IPs1
File Paths1
Hashes0
Emails7
Investigation Metadata
Case IDndlc
Evidence Root/evidence
Report Generated2026-09-19T21:01:34
Investigation Start2026-09-19T19:55:01
Investigation End2026-09-19T21:01:30
Total Processing2926.1s
Audit Log/home/mulder/.mulder/cases/ndlc.audit.jsonl
4 FILES Hashes computed during evidence ingestion. Compare against your local copies to confirm integrity.
FileSHA-256Size
cfreds_2015_data_leakage_pc.E01 e6365e44f1004252171acb73e6779be05277cbd57d09d7febed22d2463a956a9 2.0 GB
cfreds_2015_data_leakage_rm1.E01 a14150a21bc1e3700b51912c2ab20cd9587ad3e27ee67475af64508a7e760121 74.6 MB
cfreds_2015_data_leakage_rm2.E01 25215f9bcb51ceee9147886ed3f5c13ef148de634fc5114491e0f8dad8b15696 243.2 MB
cfreds_2015_data_leakage_rm3_type3.E01 336e1307721ef5f63679379961d1716b74f986e69df8c40117d9cea7858d512b 90.2 MB

Insider Threat Data Exfiltration Investigation — CFREDS 2015 Data Leakage Case

Background

This investigation was initiated to examine a suspected insider threat data exfiltration incident involving a departing employee at a government organization. The subject, identified through converging forensic evidence as "Iaman Informant" (username: informant, email: iaman.informant@nist.gov), is alleged to have systematically copied classified "Secret Project Data" from a secured network file share to multiple removable media devices and potentially to cloud storage, employing a variety of anti-forensic techniques to conceal the theft.

The forensic examination encompassed four disk images: the subject's workstation (cfreds_2015_data_leakage_pc.E01, hostname "informant-PC," running Windows 7 64-bit in the Eastern Standard Time zone), and three removable media devices — RM1 (cfreds_2015_data_leakage_rm1.E01, a 4GB USB device with dual partitions), RM2 (cfreds_2015_data_leakage_rm2.E01, a FAT32 USB device), and RM3 (cfreds_2015_data_leakage_rm3_type3.E01, a CD-R disc). Analysis drew upon 25 indexed evidence sources spanning 16 distinct artifact types including filesystem analysis (Sleuthkit), registry examination (RegRipper, python-registry), event log analysis (Chainsaw, Hayabusa), MFT parsing (EZTools), bulk content extraction (bulk_extractor), string analysis, EXIF metadata extraction, optical media session reconstruction, and file masquerade detection.

The source PC was connected to an internal network on subnet 10.11.11.0/24, where the subject accessed a secured network share at \\10.11.11.128\secured_drive. The PC's own DHCP-assigned address was 10.11.11.129. The investigation identified the "informant" user account (RID 1000, login count 10, created 2015-03-22 at 14:33:54 UTC) as the sole actor in the exfiltration campaign. Three additional local accounts — admin11 (RID 1001), ITechTeam (RID 1002), and temporary (RID 1003) — were created by the informant account within a two-minute window on the same day, but none of these accounts accessed the Secret Project Data or performed any substantive activity relevant to the data theft.

Incident Timeline

The exfiltration campaign unfolded over approximately five weeks, from February 15 through March 25, 2015, and can be divided into five distinct operational phases.

Phase 1 — Initial Data Copy (February 15, 2015). The earliest evidence of exfiltration dates to Sunday, February 15, 2015. At 16:51:38 UTC, the Secret Project Data directory structure was created on RM1's exFAT partition (volume label "Authorized USB," volume serial 5c75-4d3e). Between 16:52:08 and 16:52:20 UTC, five classified Office documents were copied to this partition with their original filenames intact: [secret_project]_design_concept.ppt, [secret_project]_detailed_design.pptx, [secret_project]_revised_points.ppt, [secret_project]_detailed_proposal.docx, and [secret_project]_proposal.docx. These files had modification dates ranging from December 4, 2014 to January 23, 2015, consistent with active project documents. Twelve days later, on February 27, 2015, at 17:20:18 UTC, the root "Secret Project Data" directory on this partition was deleted, though the files themselves remained accessible in subdirectories.

Phase 2 — Workstation Setup and Network Reconnaissance (March 22, 2015). On Sunday, March 22, the subject logged into the PC for the first time at 14:33:13 UTC and began setting up the environment. Internet Explorer 11 was installed at 15:12:32 UTC, and Chrome was configured. At 14:52:22 UTC, shellbag artifacts record the first access to the \\10.11.11.128\secured_drive network share, where the subject navigated through the complete directory tree including Secret Project Data, Common Data, and Past Projects subdirectories. Between 15:51:54 and 15:53:01 UTC, the subject created three additional local accounts (admin11, ITechTeam, temporary) and added admin11 and ITechTeam to the local Administrators group. Security event logs (Event ID 4720/4732, confirmed via Chainsaw and Hayabusa) definitively attribute these creations to the informant account's SID (S-1-5-21-2425377081-3129163575-2985601102-1000).

Phase 3 — Document Access, Research, and Staging (March 23, 2015). The subject's activity intensified on Monday, March 23. Cover image files (24 photographs including amalfi.bmp, barn.gif, boudicca.bmp, cactus.png, and others) were created on RM2's FAT32 partition between 16:55:17 and 16:55:37 UTC, establishing an innocuous appearance for the media. Chrome was launched at 17:26:50 UTC, followed by browsing to Bing and Google. The subject searched for "secret" using Windows Explorer's search bar at 18:40:17 UTC (recorded in the WordWheelQuery registry key). Secret project files were opened using their respective Office applications — Excel opened (secret_project)_pricing_decision.xlsx at 20:26:50 UTC, and PowerPoint opened [secret_project]_final_meeting.pptx at 20:27:33 UTC. Google Drive was installed at approximately 20:01:53 UTC, with ShimCache confirming googledrivesync.exe was executed. Critically, the subject conducted extensive browser research during this period into topics including "anti-forensic+tools" (85 search instances), "ccleaner" (65 instances), "eraser" (51 instances), "external+device+and+forensics" (65 instances), "cd+burning+method" (64 instances), "information+leakage+cases" (47 instances), and "DLP DRM" (90 instances). This research directly preceded and informed every subsequent anti-forensic action.

Phase 4 — Multi-Media Exfiltration and CD-R Burning (March 24, 2015). On Tuesday, March 24, the subject executed the primary exfiltration operation. Between 09:59:26 and 10:00:18 UTC, seventeen masqueraded copies of the Secret Project Data documents were created on both RM1's FAT32 partition and RM2, organized into five directories mirroring the corporate share structure (design, pricing decision, progress, proposal, technical review). Every document was renamed with a false file extension to disguise its Office format — for example, [secret_project]detailed_proposal.docx became "a_gift_from_you.gif" (35,226,880 bytes), and [secret_project]_detailed_design.pptx became "winter_whether_advisory.zip" (16,381,123 bytes). The USBSTOR driver was last written at 13:37:59 UTC, and shellbag evidence records the subject browsing E:\RM#1\Secret Project Data at 13:38:31 UTC and the D: drive directories (de, tr, pd, prop, prog) between 19:47:48 and 20:44:18 UTC. The subject saved Resignation_Letter(Iaman_Informant).docx at 18:48:40 UTC.

Between 20:54:16 and 20:57:03 UTC, the subject burned data to the CD-R (RM3, volume label "IAMAN CD") in nine UDF VAT sessions. The disc preserves evidence of iterative concealment refinement: sessions -7 through -3 used full directory names matching the corporate share structure; session -1 used abbreviated names (de, pd, prog, prop, tr); and the final session (0) deleted all data directories, leaving only three stock Windows 7 sample photographs (Koala.jpg, Penguins.jpg, Tulips.jpg) as cover content. All seventeen masqueraded documents were subsequently deleted from RM1's FAT32 partition and RM2, leaving only orphaned file system entries.

Phase 5 — Anti-Forensic Cleanup and Departure (March 25, 2015). On Wednesday, March 25, the subject executed the final phase of the operation. Outlook was used at 14:41:03 UTC for email activity. At 14:50:14 UTC, the Eraser 6.2.0.2962 installer was run from the Desktop\Download directory, followed by the CCleaner v5.04 installer (ccsetup504.exe) at 14:57:56 UTC. Eraser was executed at 15:12:28 UTC for secure file deletion, and CCleaner64.exe was executed at 15:15:50 UTC for system trace cleaning. Google Drive sync was then launched at 15:21:30 UTC — notably after the anti-forensic cleanup, raising the possibility that the subject cleaned traces first and then synced remaining data to the cloud. WINWORD.EXE was used at 15:24:48 UTC (the subject's fourth run) to finalize the resignation letter, which was converted to XPS format at 15:28:47 UTC. The last RecentDocs registry write occurred at 15:29:08 UTC, marking the final recorded activity on the system. Google Drive's sync_config.db, cacerts, and snapshot.db files were all found deleted, consistent with Eraser's secure deletion capability having been used to destroy cloud synchronization evidence.

Key Findings

The investigation produced 23 findings, of which 3 are critical severity, 9 are high severity, 5 are medium severity, and the remainder are informational. The findings are organized below by operational category.

Data Collection and Exfiltration. The core of the incident is the confirmed exfiltration of 17 classified Office documents — collectively titled "Secret Project Data" — from the network share at \\10.11.11.128\secured_drive to three separate removable media devices. The documents encompassed design specifications (PPT, PPTX), proposals (DOCX), pricing decisions (XLSX), progress reports (DOCX), and technical reviews (DOCX, PPTX, OLE). RM1's exFAT partition contained original-name copies dating to February 15, 2015. RM1's FAT32 partition, RM2, and RM3 all contained byte-identical masqueraded copies created on March 24, 2015. Cross-media verification confirmed that file sizes matched exactly across all three media — for example, a_gift_from_you.gif was consistently 35,226,880 bytes (the true [secret_project]_detailed_proposal.docx), and winter_whether_advisory.zip was consistently 16,381,123 bytes (the true [secret_project]_detailed_design.pptx). The same three email addresses embedded within the document content — Eric_P._Lauer@omb.eop.gov, wayne.longman@att.net, and mmun@loc.gov — appeared at proportional disc offsets on both RM2 and RM3, providing independent confirmation of byte-identical content across media.

File Extension Masquerading. All 17 exfiltrated documents were systematically renamed with false file extensions across all three media devices. OLE-format documents (PPT, XLS) were given extensions such as .amr, .db, .avi, and .svg, while OOXML-format documents (DOCX, PPTX, XLSX) were given extensions including .zip, .7z, .jpg, .png, .one, .gif, and .txt. The filenames themselves were changed to innocuous personal-sounding names (winter_storm, my_favorite_cars, diary_#1d, landscape, a_gift_from_you). Sleuthkit masquerade detection confirmed the mismatch between file signatures and extensions. This technique maps to MITRE ATT&CK T1036.008 (Masquerading: Match Legitimate Name or Location).

Multi-Layered Anti-Forensic Concealment. The subject employed at least five distinct anti-forensic techniques. First, file extension masquerading as described above. Second, systematic deletion of all exfiltrated documents from all removable media after copying. Third, multi-session CD-R burning exploiting UDF VAT to progressively obscure and ultimately "delete" data on write-once media — though the subject apparently did not understand that UDF's Virtual Allocation Table preserves all previous generations on write-once discs. Fourth, placement of cover content (personal photographs on RM1/RM2 and stock Windows 7 sample photos on RM3) to make media appear innocuous upon casual inspection. Fifth, execution of dedicated anti-forensic tools — Eraser for secure file deletion and CCleaner for system trace cleaning — on the final day of activity.

Dual-Partition USB Structure. RM1 was configured with two distinct partitions to enable plausible deniability. The first partition (exFAT, labeled "Authorized USB") contained Secret Project Data files with their original names, appearing as a legitimate work device. The second partition (FAT32, labeled "IAMAN $_@") contained the masqueraded copies in a directory structure mirroring the corporate share, all of which were subsequently deleted. If the USB device was inspected casually, only the first "Authorized USB" partition would be readily visible.

Potential Cloud Exfiltration. Google Drive was installed on March 23 and last launched at 15:21:30 UTC on March 25 — six minutes after CCleaner was executed. The timing sequence (anti-forensic cleanup followed by cloud sync) suggests the subject may have synced documents to Google Drive as a supplementary exfiltration vector. However, the destruction of all Google Drive configuration files (sync_config.db, cacerts, snapshot.db) by Eraser means the investigation cannot definitively confirm what, if any, data was uploaded. Apple iCloud was also installed (icloudsetup.exe appeared in UserAssist), though no definitive evidence of iCloud data synchronization was found. These findings are assessed at medium severity with inference-level confidence.

Potential Co-Conspirator Contact. Bulk extractor recovered an Outlook contact entry for "spy" with email address spy.conspirator@nist.gov from the PC's disk image. The provocative naming convention mirrors the subject's own email naming pattern. However, this finding is assessed at inference confidence: only one evidence source supports it, no email message content between the two addresses was recovered, and no evidence indicates Secret Project Data was transmitted via email. The exfiltration pathway appears to have been exclusively through removable media and potentially cloud storage.

Negative Finding: No Encryption or Steganography. Analysis across all three removable media devices found no evidence of encrypted containers (TrueCrypt, VeraCrypt, BitLocker) or steganographic tools or content. Cover images contained genuine, unmodified EXIF metadata. The subject's anti-forensic techniques were limited to the five categories described above.

Threat Intelligence and Attribution

This incident presents a textbook insider threat profile: a privileged user with legitimate access to sensitive data who exploits that access for unauthorized data exfiltration prior to departure. The attribution to the "informant" user account is confirmed with high confidence based on multiple independent evidence streams. The user's account (RID 1000, login count 10) was the only account that accessed the Secret Project Data via the network share, the only account whose shellbag artifacts reference the removable media devices, and the only account under which the anti-forensic tools were installed and executed. The password hint "IAMAN" directly ties the user account to the volume labels on RM2 ("IAMAN $_@") and RM3 ("IAMAN CD").

The subject's premeditation is extensively documented through browser search history recovered by bulk_extractor. The subject researched "information+leakage+cases," "how+to+leak+a+secret," "intellectual+property+theft," and "data+leakage+methods" before executing the campaign. The subject then researched the specific tools and techniques subsequently employed: anti-forensic tools, CCleaner, Eraser, CD burning methods, cloud storage options, and data recovery counter-measures. The subject also demonstrated forensic investigation awareness, researching "e-mail+investigation," "Forensic+Email+Investigation," "what+is+windows+system+artifacts," "windows+event+logs," and "external+device+and+forensics" — indicating a deliberate attempt to understand and evade forensic investigation. Each search topic maps directly to an action taken during the campaign.

No evidence links this incident to external threat actors or organized campaigns. The tradecraft — while showing deliberate effort — contains fundamental operational security failures, most notably the use of UDF write-once media for concealment (which preserves rather than destroys data), the failure to thoroughly clean registry shellbag artifacts, and the retention of browser search history in unallocated disk space despite running CCleaner. The operational pattern is consistent with a motivated but technically unsophisticated insider acting independently, with the possible involvement of the spy.conspirator@nist.gov contact whose role, if any, remains undetermined.

Impact Assessment

The scope of this incident is significant. Seventeen classified Office documents collectively comprising the organization's "Secret Project Data" portfolio — including design specifications, detailed proposals, pricing decisions, progress reports, and technical review materials — were exfiltrated to three separate physical media devices and potentially to cloud storage. The total volume of exfiltrated data across the 17 documents exceeds 135 megabytes, with individual files ranging from 27,414 bytes to 35,226,880 bytes. The documents contain content referencing government entities including the Office of Management and Budget (Eric_P._Lauer@omb.eop.gov), the Library of Congress (mmun@loc.gov), and external contacts (wayne.longman@att.net), indicating sensitive inter-agency or partner content.

The creation of redundant copies across three physically separate media — two USB devices and one CD-R — represents a deliberate strategy to ensure the data survived confiscation of any single device. The potential cloud exfiltration via Google Drive introduces the possibility that the data exists in an additional, uncontrolled location. The subject's destruction of Google Drive synchronization evidence means the full scope of cloud-based data exposure cannot be determined from available evidence.

Only one system — the subject's workstation informant-PC — was directly compromised. However, the compromised data originated from the network share at \\10.11.11.128\secured_drive, meaning the exposure extends to all Secret Project Data stored on that share. The subject's legitimate credentials (iaman@nist.gov, iaman.informant@nist.gov) were used throughout; no credential theft or privilege escalation beyond the subject's existing access was necessary or observed. The three additional accounts created by the subject (admin11, ITechTeam, temporary) did not access any sensitive data and appear to have been diversionary or experimental in nature.

The creation and saving of Resignation_Letter_(Iaman_Informant).docx and its XPS conversion on the final day of activity, combined with the anti-forensic cleanup sequence, strongly indicate the subject intended this to be their last day at the organization. The business impact extends beyond data loss to potential competitive harm, intellectual property theft, and regulatory compliance violations, depending on the classification and contractual protections governing the Secret Project Data.

Immediate Tactical Containment

  1. Disable the "informant" user account (iaman.informant@nist.gov, iaman@nist.gov, RID 1000) across all organizational systems including Active Directory, email, VPN, and remote access services immediately.
  2. Disable the three accounts created by the subject — admin11 (RID 1001), ITechTeam (RID 1002), and temporary (RID 1003) — on informant-PC and verify they do not exist on any domain controllers.
  3. Isolate the workstation informant-PC (IP 10.11.11.129) from the network pending full forensic preservation.
  4. Revoke all access to the network share \\10.11.11.128\secured_drive for the informant account and audit current access control lists to identify any other accounts with access that may be associated with the subject.
  5. Seize and forensically preserve all three removable media devices: RM1 (USB, volume labels "Authorized USB" and "IAMAN $@"), RM2 (USB, volume label "IAMAN $@", Volume ID 0xb4d85399), and RM3 (CD-R, volume label "IAMAN CD"). Maintain chain of custody.
  6. Initiate a Google Workspace administrative hold on the Google Drive account associated with iaman.informant.personal@gmail.com and request preservation of all synced content and access logs.
  7. Block the email address spy.conspirator@nist.gov and place the associated account under monitoring pending determination of their involvement.
  8. Issue credential reset for all accounts that had access to \\10.11.11.128\secured_drive\Secret Project Data to prevent potential credential sharing.
  9. Preserve all event logs on the file server at 10.11.11.128, particularly SMB access logs covering the period February 15 through March 25, 2015.

Strategic Remediation

The subject accessed the full Secret Project Data directory tree on the network share at \\10.11.11.128\secured_drive without triggering any data loss prevention alert, despite the data's classified status. This indicates the absence or misconfiguration of Data Loss Prevention (DLP) controls on the file server. The subject's own research into "DLP DRM" (90 search instances) suggests awareness that such controls might exist and a desire to understand them. Implementing content-aware DLP monitoring on the secured_drive share — with rules that detect bulk file access, file copying to removable media, and access from accounts with pending departures — would have generated an alert during the initial February 15 exfiltration or during the systematic March 24 copy operation.

The subject downloaded, installed, and executed two anti-forensic tools (Eraser 6.2.0.2962 and CCleaner v5.04) from the Desktop\Download directory without any application whitelisting or endpoint detection response. No alerts were generated when the subject installed Eraser (which requires .NET 4.0 installation), CCleaner, or Google Drive on a workstation that presumably should have had controlled software installation policies. Implementing application whitelisting or endpoint detection and response (EDR) with rules to flag known anti-forensic and data wiping tools — specifically including Eraser.exe, CCleaner64.exe, and ccsetup504.exe — would have detected the cleanup phase of this operation in real time.

The subject copied approximately 135 megabytes of classified data to two USB devices and one CD-R over a period of five weeks without any removable media access controls intervening. The USBSTOR driver loaded successfully at 13:37:59 UTC on March 24, and the CD-R was burned with nine sessions between 20:54 and 20:57 UTC the same day. Implementing a removable media policy that requires encryption, logging, and administrative approval for USB and optical media write operations — or disabling USB mass storage and CD/DVD burning entirely for users without a documented business need — would have blocked the primary exfiltration vector (T1052.001).

The subject's browser search history reveals extensive research into "how+to+leak+a+secret," "anti-forensic+tools," "data+leakage+methods," and "intellectual+property+theft" totaling hundreds of search instances, none of which generated any user behavior analytics alert. Deploying a User and Entity Behavior Analytics (UEBA) solution with rules that flag searches for data exfiltration methods, anti-forensic tools, and intellectual property theft — particularly when correlated with HR data indicating pending departure — would have identified the subject's intent well before the exfiltration was executed.

The subject maintained unmonitored access to a Google Drive personal account (iaman.informant.personal@gmail.com) and Apple iCloud, installing synchronization clients on the workstation. The post-cleanup timing of the Google Drive sync launch at 15:21:30 UTC suggests potential cloud exfiltration, yet no cloud access security broker (CASB) or web filtering system flagged the personal cloud storage usage. Restricting personal cloud storage synchronization clients on corporate endpoints and monitoring for their installation via endpoint management would have addressed the potential cloud exfiltration vector (T1567.002).

Conclusion

This investigation conclusively establishes that user "Iaman Informant" (iaman.informant@nist.gov) conducted a premeditated, multi-stage data exfiltration campaign targeting classified Secret Project Data from the organization's secured network file share. The following conclusions address each investigation question:

Q1. What systems were compromised? One workstation was directly involved: informant-PC (Windows 7 64-bit, IP 10.11.11.129). The data originated from the network file share at \\10.11.11.128\secured_drive. No evidence of compromise to other systems was identified.

Q2. How did the attacker gain initial access? This was an insider threat scenario. The subject used legitimate credentials (iaman.informant@nist.gov, account RID 1000) with authorized access to the network share. No external intrusion, credential theft, or privilege escalation was required or observed.

Q3. What lateral movement occurred? N/A. The subject operated from a single workstation and accessed the network share using authorized SMB connectivity. No lateral movement to additional systems was detected. The three accounts created by the subject (admin11, ITechTeam, temporary) were not used for lateral movement.

Q4. What persistence mechanisms were installed? N/A in the traditional malware sense. However, the subject created three local accounts on informant-PC (admin11, ITechTeam, temporary), two of which were added to the Administrators group. These accounts could have served as persistence mechanisms for continued access, though none were used for data access.

Q5. Was data exfiltrated, and if so, what and how much? Yes. Seventeen classified Office documents from the Secret Project Data portfolio were exfiltrated to three separate removable media devices (two USB drives and one CD-R), totaling over 135 megabytes across five content categories: design, pricing decision, progress, proposal, and technical review. Potential additional exfiltration via Google Drive cloud storage is suspected but cannot be confirmed due to anti-forensic destruction of synchronization evidence.

Q6. What is the full timeline of the incident? The incident spanned February 15 to March 25, 2015. Phase 1 (Feb 15): Initial data copy to RM1 exFAT. Phase 2 (Mar 22): PC setup, network share access, account creation. Phase 3 (Mar 23): Document access, anti-forensic research, cloud tool installation. Phase 4 (Mar 24): Multi-media masqueraded exfiltration to RM1 FAT32, RM2, and RM3 CD-R; resignation letter drafted. Phase 5 (Mar 25): Anti-forensic tool execution (Eraser, CCleaner), Google Drive sync, resignation letter finalized.

Q7. What is the total scope and business impact? The entire Secret Project Data portfolio was exfiltrated, including documents containing references to government officials (OMB, Library of Congress) and external contacts. Three physically separate copies ensure data survival even if one or two devices are recovered. The potential cloud exfiltration via Google Drive means the data may exist in additional uncontrolled locations. The business impact includes potential loss of competitive advantage, intellectual property theft, regulatory compliance violations, and reputational harm.

Q8. What are the recommended remediation actions? The five strategic recommendations above address the specific root causes identified in this investigation: absence of DLP controls on the file share, lack of application whitelisting or EDR to detect anti-forensic tools, unrestricted removable media access, absence of user behavior analytics to detect pre-exfiltration research patterns, and unmonitored personal cloud storage access from corporate endpoints. Immediate tactical containment requires disabling all associated accounts, isolating the workstation, seizing removable media, and preserving Google Drive and file server logs.

2015-02-15
2015-02-15T16:51:38 — 2015-03-24T10:00:18
Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)
critical confirmed
tsk.masquerade, tsk.timeline, tsk.filelist, registry.usrclass.informant, tsk.fsstat
2015-02-15T16:51:38 — 2015-03-24T20:57:03
Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)
critical confirmed
tsk.filelist, tsk.masquerade, tsk.timeline, optical.listing, bulk.email, registry.usrclass.informant
2015-02-15T16:51:38 — 2015-03-25T15:29:08
Complete Cross-System Exfiltration and Anti-Forensic Timeline Reconstruction
high confirmed
tsk.timeline, registry.usrclass.informant, registry.ntuser.informant, registry.system
2015-02-15T16:51:38 — 2015-03-24T17:02:36
Dual-Partition USB Device Structure Enables Plausible Deniability
medium confirmed
tsk.fsstat, tsk.filelist, tsk.masquerade
2015-02-15T16:51:38 — 2015-03-24T20:57:03
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across RM1, RM2, and RM3
medium inference
bulk.email, bulk.domain, bulk.exif, optical.listing
2015-03-22
2015-03-22T14:33:13 — 2015-03-25T15:29:08
Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft
critical confirmed
registry.ntuser.informant, bulk.email, registry.usrclass.informant
2015-03-22T14:33:13 — 2015-03-25T15:29:08
Cross-System: Premeditated Anti-Forensic and Data Leakage Research Preceding Exfiltration Campaign
high confirmed
bulk.url_searches, bulk.url, registry.ntuser.informant, ez.shimcache
2015-03-22T14:33:13 — 2015-03-25T15:29:08
Application Execution Timeline: Document Access and Exfiltration Workflow
info confirmed
registry.ntuser.informant, registry.usrclass.informant, ez.shimcache
2015-03-22T14:33:54 — 2015-03-25T14:45:59
System Configuration: User Accounts, Timezone, and PC Identity
info confirmed
registry.system, registry.query.system, hayabusa.alerts
2015-03-22T14:52:22 — 2015-03-24T20:54:07
USB Device Tied to Source PC via Shellbag and Registry Evidence
high confirmed
registry.usrclass.informant, registry.system, tsk.fsstat
2015-03-22T14:52:22 — 2015-03-24T13:57:40
Network Share Access to Secured Corporate Data from Internal Network (10.11.11.128)
high confirmed
registry.usrclass.informant, registry.system, registry.ntuser.informant, bulk.domain
2015-03-22T15:03:29 — 2015-03-25T15:28:47
Potential Co-Conspirator Contact Entry — spy.conspirator@nist.gov in Outlook Data
medium inference
bulk.email
2015-03-22T15:51:54 — 2015-03-22T15:58:26
Cross-System: Diversionary User Account Creation by Insider (admin11, ITechTeam, temporary)
medium inference
chainsaw.hunt, hayabusa.alerts, registry.ntuser.admin11, registry.usrclass.admin11, registry.ntuser.temporary, registry.usrclass.temporary, bulk.url_searches
2015-03-23
2015-03-23T18:38:21 — 2015-03-25T15:29:08
RecentDocs, WordWheelQuery, and OpenSaveMRU: Evidence of Document Search and Access Pattern
info confirmed
registry.ntuser.informant
2015-03-23T20:01:53 — 2015-03-25T15:21:30
Potential Cloud Exfiltration via Google Drive and iCloud — Sync Config Destroyed by Anti-Forensic Tools
medium inference
registry.ntuser.informant, tsk.filelist
2015-03-24
2015-03-24T09:59:26 — 2015-03-24T10:00:18
Environment-Wide File Extension Masquerading Across All 3 Removable Media — 17 Disguised Office Documents
high confirmed
tsk.masquerade, tsk.filelist, tsk.timeline, optical.listing
2015-03-24T09:59:26 — 2015-03-24T15:51:48
Environment-Wide Deletion of Exfiltrated Documents Across All 3 Removable Media
high confirmed
tsk.timeline, tsk.filelist, tsk.masquerade, optical.listing
2015-03-24T20:54:16 — 2015-03-24T20:57:03
CD-R (RM3) Multi-Session Anti-Forensic Technique: Iterative Directory Renaming and Deletion on Write-Once Media
high confirmed
optical.listing, tsk.masquerade
2015-03-24T20:54:16 — 2015-03-24T20:57:03
CD-R (RM3) EXIF Metadata: Cover Images Are Stock Windows 7 Photos, Document-Embedded Images Show Kodak and Adobe Processing
info confirmed
bulk.exif, optical.listing
2015-03-24T20:57:00 — 2015-03-25T14:45:59
CD-R (RM3) Data Exfiltration: 9 Burn Sessions with Masqueraded Documents
high confirmed
optical.listing, registry.usrclass.informant, registry.ntuser.informant
2015-03-25
2015-03-25T14:50:14 — 2015-03-25T15:15:50
Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Executed After Exfiltration
high confirmed
registry.ntuser.informant, ez.mft
critical confirmed Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2)

Corporate "Secret Project Data" was exfiltrated from the network share \10.11.11.128\secured_drive to multiple removable media devices by user "informant" (Iaman Informant, iaman.informant@nist.gov):

RM1 (Authorized USB, exFAT, Volume Serial: 5c75-4d3e):
Contains complete Secret Project Data with original filenames in two copies:
- Secret Project Data/Secret Project Data/design/ (3 PPT/PPTX files)
- Secret Project Data/Secret Project Data/proposal/ (2 DOCX files + deleted temp ~$ecret_project]_proposal.docx)
- RM#1/ mirror with same files

Timeline: Files accessed on 2015-02-15 16:52 UTC (access/birth timestamps), modified dates range from 2014-12-04 to 2015-01-23.

RM2 (IAMAN $_@, FAT32, Volume ID: 0xb4d85399):
Contains same data but deliberately disguised with false filenames and extensions (see masquerading finding). All 17 files are deleted orphans, created 2015-03-24 09:59-10:00 UTC. Additional ~24 deleted image files (amalfi.bmp, barn.gif, cactus.png, etc.) created 2015-03-23 16:55 UTC appear to be cover images.

The RM2 folder structure (design, PRICIN~1, progress, proposal, TECHNI~1) maps directly to the network share categories: design, pricing decision, progress, proposal, technical review. File sizes prove byte-for-byte copies:
- winter_storm.amr (14,547,968) = [secret_project]_revised_points.ppt (14,547,968)
- winter_whether_advisory.zip (16,381,123) = [secret_project]_detailed_design.pptx (16,381,123)
- a_gift_from_you.gif (35,226,880) = [secret_project]_detailed_proposal.docx (35,226,880)
- landscape.png (6,484,502) = [secret_project]_proposal.docx (6,484,502)

Evidence strength:
5 refs
tsk.masqueradetsk.timelinetsk.filelistregistry.usrclass.informanttsk.fsstat

Evidence Chain

tc_ec173722 get_raw_output 99ms
tc_7e1c1241 get_raw_output 11ms
tc_27bf2a30 get_raw_output 22ms
tc_7f5abba9 get_raw_output 99ms
tc_8478da81 get_raw_output 101ms
Time: 2015-02-15T16:51:38 — 2015-03-24T10:00:18
Sources: tsk.masquerade, tsk.timeline, tsk.filelist, registry.usrclass.informant, tsk.fsstat
Evidence Refs: tc_ec173722, tc_7e1c1241, tc_27bf2a30, tc_7f5abba9, tc_8478da81
critical confirmed Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft

The user responsible for the data exfiltration has been identified as "Iaman Informant" based on converging evidence:

User identity:
- PC username: "informant" (Users/informant profile)
- Email: iaman.informant@nist.gov (from Outlook OST file references on PC)
- Also: iaman@nist.gov (BASIC authentication references)
- USB volume label: "IAMAN $_@" (FAT32 volume on RM2)
- CD volume label: "IAMAN CD" (optical media RM3)

Resignation letter:
- RecentDocs shows "Resignation_Letter_(Iaman_Informant).docx" as the most recently accessed document (MRU position 8)
- Also converted to XPS: "Resignation_Letter_(Iaman_Informant).xps" (MRU position 14)
- OpenSavePidlMRU confirms both files were saved: Resignation_Letter_(Iaman_Informant).docx (2015-03-24 18:48:40) and .xps (2015-03-25 15:28:33)
- WINWORD.EXE (4 runs) and XPS viewer (1 run) execution confirms document editing

Embedded email addresses in documents on RM2/RM3:
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget)
- wayne.longman@att.net (personal contact embedded in documents)
- mmun@loc.gov (Library of Congress)

Search activity:
- WordWheelQuery shows the user searched for "secret" on the PC (2015-03-23 18:40:17)

The combination of a resignation letter, systematic access to sensitive corporate data via network share, deliberate file disguising, exfiltration to multiple removable media, and subsequent anti-forensic cleanup constitutes a classic insider threat data theft scenario by a departing employee.

Evidence strength:
3 refs
registry.ntuser.informantbulk.emailregistry.usrclass.informant

Evidence Chain

tc_2beaa53c get_raw_output 100ms
tc_6ad4d887 get_raw_output 30ms
tc_7f5abba9 get_raw_output 99ms
Time: 2015-03-22T14:33:13 — 2015-03-25T15:29:08
Sources: registry.ntuser.informant, bulk.email, registry.usrclass.informant
Evidence Refs: tc_2beaa53c, tc_6ad4d887, tc_7f5abba9
ATT&CK: T1078.001
critical confirmed Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3)

File size analysis, masquerade detection, and document metadata confirm that the SAME 17 Office documents containing Secret Project Data were exfiltrated to three separate removable media devices, creating redundant copies for distribution or safekeeping.

Cross-Media File Size Verification (5 sources independently confirm):
Four files can be traced from the original network share (\\10.11.11.128\secured_drive) through all three media:

Original Document Size RM1 exFAT RM1 FAT32 RM2 RM3
[secret_project]_detailed_proposal.docx 35,226,880 ✓ original a_gift_from_you.gif a_gift_from_you.gif /prop/a_gift_from_you.gif
[secret_project]_proposal.docx 6,484,502 ✓ original landscape.png landscape.png /prop/landscape.png
[secret_project]_detailed_design.pptx 16,381,123 ✓ original winter_whether_advisory.zip winter_whether_advisory.zip /de/winter_whether_advisory.zip
[secret_project]_revised_points.ppt 14,547,968 ✓ original winter_storm.amr winter_storm.amr /de/winter_storm.amr

All 17 masqueraded files have byte-identical sizes across RM1 (FAT32 partition), RM2, and RM3.

Email Address Convergence Across Media:
The same three embedded email addresses appear in documents on RM2 AND RM3, confirming identical document content:
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget)
- wayne.longman@att.net (personal contact)
- mmun@loc.gov (Library of Congress)

Volume Label Attribution:
- RM1 FAT32 partition: "IAMAN $@"
- RM2: "IAMAN $
@" (same label as RM1 FAT32)
- RM3: "IAMAN CD"
- PC user password hint: "IAMAN"

Directory Structure Evolution Across Media (anti-forensic refinement):
- RM1 exFAT: Original names (design/, proposal/)
- RM1 FAT32: Full category names (design/, PRICIN~1/, progress/, proposal/, TECHNI~1/)
- RM2: Identical to RM1 FAT32
- RM3 sessions -7 to -3: Full names (design/, pricing decision/, progress/, proposal/, technical review/)
- RM3 session -1: Abbreviated (de/, pd/, prog/, prop/, tr/)
- RM3 session 0: All deleted, replaced with stock photos

This progressive directory name obfuscation reveals the suspect iteratively refining their concealment strategy across media.

Timeline of Multi-Media Exfiltration:
1. 2015-02-15: First copy to RM1 exFAT (original filenames)
2. 2015-03-24 09:59-10:00: Masqueraded copies to RM1 FAT32 and RM2 (deleted after)
3. 2015-03-24 20:54-20:57: Burned to RM3 CD-R with 9 session iterations

Evidence strength:
3 refs
tsk.filelisttsk.masqueradetsk.timelineoptical.listingbulk.emailregistry.usrclass.informant

Evidence Chain

tc_754cd2ae get_raw_output 102ms
tc_83273c80 get_raw_output 100ms
tc_680ef6a6 get_raw_output 99ms
Time: 2015-02-15T16:51:38 — 2015-03-24T20:57:03
Sources: tsk.filelist, tsk.masquerade, tsk.timeline, optical.listing, bulk.email, registry.usrclass.informant
Evidence Refs: tc_754cd2ae, tc_83273c80, tc_680ef6a6
high confirmed Environment-Wide File Extension Masquerading Across All 3 Removable Media — 17 Disguised Office Documents

The SAME 17 Office documents containing Secret Project Data were disguised with false file extensions on all three removable media devices (RM1 FAT32 partition, RM2, and RM3 CD-R). This was a systematic anti-forensic technique applied consistently across all exfiltration media.

Masquerade Scheme (identical across RM1 FAT32, RM2, RM3):

design/ directory:
- winter_storm.amr → Actually OLE (14,547,968 bytes) = [secret_project]_revised_points.ppt
- winter_whether_advisory.zip → Actually PPTX (16,381,123 bytes) = [secret_project]_detailed_design.pptx

PRICIN~1/ (pricing decision) directory:
- my_favorite_cars.db → Actually OLE (1,260,544 bytes)
- my_favorite_movies.7z → Actually XLSX (100,078 bytes)
- new_years_day.jpg → Actually XLSX (10,237,535 bytes)
- super_bowl.avi → Actually OLE (10,289,152 bytes)

progress/ directory:
- my_friends.svg → Actually OLE (58,368 bytes)
- my_smartphone.png → Actually DOCX (4,440,235 bytes)
- new_year_calendar.one → Actually DOCX (27,414 bytes)

proposal/ directory:
- a_gift_from_you.gif → Actually DOCX (35,226,880 bytes) = [secret_project]_detailed_proposal.docx
- landscape.png → Actually DOCX (6,484,502 bytes) = [secret_project]_proposal.docx

TECHNI~1/ (technical review) directory:
- diary_#1d.txt → DOCX; diary_#1p.txt → PPTX; diary_#2d.txt → DOCX; diary_#2p.txt → OLE; diary_#3d.txt → OLE; diary_#3p.txt → OLE

Cross-media confirmation: File sizes are byte-identical across all three media. The same false filenames and extensions were used consistently. On RM3 CD-R, the multiple VAT sessions show the user first used full directory names (design, pricing decision, etc.) then abbreviated (de, pd, etc.).

Evidence strength:
3 refs
tsk.masqueradetsk.filelisttsk.timelineoptical.listing

Evidence Chain

tc_62987b1e get_raw_output 104ms
tc_d67ae8aa get_raw_output 21ms
tc_b61a548a get_raw_output 11ms
Time: 2015-03-24T09:59:26 — 2015-03-24T10:00:18
Sources: tsk.masquerade, tsk.filelist, tsk.timeline, optical.listing
Evidence Refs: tc_62987b1e, tc_d67ae8aa, tc_b61a548a
high confirmed Environment-Wide Deletion of Exfiltrated Documents Across All 3 Removable Media

All 17 masqueraded Office documents were deleted on EVERY removable media device after being copied, demonstrating systematic anti-forensic cleanup across the entire exfiltration campaign:

RM1 FAT32 partition: All 17 masqueraded documents are now orphaned entries (under $OrphanFiles). 22 cover image files also deleted. The exFAT partition's root "Secret Project Data" directory was also deleted (mtime: 2015-02-27).

RM2 (FAT32): All 17 masqueraded documents are deleted orphan files. 24 cover image files (amalfi.bmp, barn.gif, boudicca.bmp, cactus.png, etc.) also deleted. Timeline shows cover images existed first → deleted → disguised project files copied → project files deleted — at least two rounds of intentional staging and cleanup.

RM3 CD-R: All document directories marked as deleted in the final UDF VAT session. Only 3 stock Windows 7 sample photos (Koala.jpg, Penguins.jpg, Tulips.jpg) remain active. However, the write-once nature of UDF means deleted data remains physically on the disc.

Deletion timeline:
1. 2015-02-27: Root "Secret Project Data" directory on RM1 exFAT deleted
2. 2015-03-23 ~16:55: Cover images placed on RM2
3. 2015-03-24 09:59-10:00: Masqueraded files created on RM1 FAT32 and RM2
4. After creation: All files deleted from RM1 FAT32 and RM2
5. 2015-03-24 20:54-20:57: Files burned to RM3 in multiple sessions, then deleted in final session
6. 2015-03-25 15:12-15:16: Eraser and CCleaner executed on PC to destroy remaining traces

Evidence strength:
3 refs
tsk.timelinetsk.filelisttsk.masqueradeoptical.listing

Evidence Chain

tc_b61a548a get_raw_output 11ms
tc_d67ae8aa get_raw_output 21ms
tc_62987b1e get_raw_output 104ms
Time: 2015-03-24T09:59:26 — 2015-03-24T15:51:48
Sources: tsk.timeline, tsk.filelist, tsk.masquerade, optical.listing
Evidence Refs: tc_b61a548a, tc_d67ae8aa, tc_62987b1e
high confirmed USB Device Tied to Source PC via Shellbag and Registry Evidence

The "informant" user account on the source PC (cfreds_2015_data_leakage_pc.E01) has extensive shellbag evidence tying this user to browsing the USB device contents and the source network share:

Network Share Access (data source):
- \10.11.11.128\secured_drive\Secret Project Data — accessed 2015-03-22 14:52:22, with subdirectories for design, final, pricing decision, proposal, progress, technical review, Common Data, Past Projects
- File V:\Secret Project Data also accessed (alternate drive letter)

USB Device Access (exfiltration destination):
- E:\RM#1\Secret Project Data — accessed 2015-03-24 13:38:31
- E:\RM#1\Secret Project Data\design — accessed 2015-03-24 13:38:52
- E:\Secret Project Data (including all subdirectories: design, pricing decision, progress, proposal, technical review) — accessed 2015-03-24 13:57-14:01
- E:\Secret Project Data\design\winter_whether_advisory.zip [16381123] — the user specifically opened the masqueraded file and explored its ppt\ subdirectory, confirming awareness of the file's true PPTX content

Second Partition Access:
- D:\de, D:\tr, D:\pd, D:\prop, D:\prog — accessed 2015-03-24 19:47-20:41 (abbreviated versions of the FAT32 partition directories)
- D:\de\winter_whether_advisory.zip [16381123] — same file size as the masqueraded PPTX

USBSTOR driver loaded: 2015-03-24 13:37:59 UTC

User Identity:
- Email: iaman.informant@nist.gov (found in Outlook profile data on PC)
- The FAT32 partition volume label "IAMAN $_@" contains the user's "IAMAN" identifier

Evidence strength:
3 refs
registry.usrclass.informantregistry.systemtsk.fsstat

Evidence Chain

tc_f26ac21a get_raw_output 113ms
tc_b88e2a9b search 3ms
tc_f0925a2e search 3ms
Time: 2015-03-22T14:52:22 — 2015-03-24T20:54:07
Sources: registry.usrclass.informant, registry.system, tsk.fsstat
Evidence Refs: tc_f26ac21a, tc_b88e2a9b, tc_f0925a2e
ATT&CK: T1052.001
high confirmed Network Share Access to Secured Corporate Data from Internal Network (10.11.11.128)

User "informant" accessed a secured network share at \10.11.11.128\secured_drive containing the Secret Project Data. Evidence from multiple sources:

Shellbags (registry.usrclass.informant):
Browsed the complete directory tree of the network share starting 2015-03-22 14:52:22 UTC:
- \10.11.11.128\secured_drive\Common Data
- \10.11.11.128\secured_drive\Past Projects (MRU: 2015-03-24 13:47:54)
- \10.11.11.128\secured_drive\Secret Project Data (with subdirs: design, pricing decision, final, technical review, proposal, progress)

The share was also mapped as V: drive, with shellbags showing:
- V:\Secret Project Data (MRU: 2015-03-23 20:27:24)
- V:\Secret Project Data\final (MRU: 2015-03-23 20:27:29)

Registry (system):
Network configuration shows DHCP IP address 10.11.11.x on the same subnet as the share server. USBSTOR driver last write: 2015-03-24 13:37:59Z confirms USB storage access during the same timeframe.

Bulk extractor domains (PC):
Multiple references to \10.11.11.128\secured_drive and \10.11.11.128\SECURED_DRIVE found in unallocated space.

Recent Documents:
The informant's RecentDocs key (last written 2015-03-25 15:29:08Z) includes: [secret_project]_proposal.docx, [secret_project]_design_concept.ppt, (secret_project)_pricing_decision.xlsx, [secret_project]_final_meeting.pptx, and winter_whether_advisory.zip — confirming these project files were opened on the PC.

Evidence strength:
3 refs
registry.usrclass.informantregistry.systemregistry.ntuser.informantbulk.domain

Evidence Chain

tc_7f5abba9 get_raw_output 99ms
tc_9373d670 search 11ms
tc_2beaa53c get_raw_output 100ms
Time: 2015-03-22T14:52:22 — 2015-03-24T13:57:40
Sources: registry.usrclass.informant, registry.system, registry.ntuser.informant, bulk.domain
Evidence Refs: tc_7f5abba9, tc_9373d670, tc_2beaa53c
ATT&CK: T1039, T1135
high confirmed Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Executed After Exfiltration

User "informant" downloaded, installed, and executed two anti-forensic/data wiping tools on 2015-03-25, the day AFTER the data exfiltration to removable media. Cross-system evidence confirms these tools were the culmination of deliberate research.

Execution Timeline (UserAssist, ShimCache, MFT):
- 14:50:14Z: Eraser 6.2.0.2962.exe installer run (from Desktop\Download)
- 14:57:56Z: ccsetup504.exe (CCleaner v5.04) installer run
- 15:12:28Z: Eraser.exe executed (secure file deletion, 1 run)
- 15:15:50Z: CCleaner64.exe executed (system trace cleaning, 1 run)
- 15:18:36Z: Software...\Run key emptied (by CCleaner removing startup entries)
- 15:21:30Z: Google Drive sync launched (cloud exfiltration)
- 15:24:48Z: WINWORD.EXE (resignation letter)
- 15:28:47Z: XPS viewer (resignation letter conversion)

ShimCache Confirmation: C:\Program Files\Eraser\Eraser.exe — Executed=Yes
MFT Confirmation: C:\Program Files\CCleaner\ files created 2015-03-25 14:58:35Z

Cross-System Correlation with Search History:
- User searched "ccleaner" (n=65 URL search instances) before downloading
- User searched "eraser" (n=51 instances) before downloading
- User searched "anti-forensic+tools" (n=85), "system+cleaner" (n=6), "how+to+delete+data" (n=5)
- Download URL carved: http://iweb.dl.sourceforge.net/project/eraser/Eraser%206/6.2/Eraser%206.2.0.2962.exe

Impact Assessment:
- Browser history: 0 windows recovered (consistent with CCleaner clearing browser data)
- Google Drive sync_config.db and related files: ALL DELETED (anti-forensic cleanup)
- RM2 USB files: All 17 masqueraded documents deleted (orphan entries only)
- Startup entries: Run key emptied

Eraser .NET dependency: dotNetFx40_Full_setup.exe was run from Eraser's temp directory, confirming the installation required and installed .NET 4.0.

Evidence strength:
3 refs
registry.ntuser.informantez.mft

Evidence Chain

tc_2beaa53c get_raw_output 100ms
tc_2fa622d5 search 6ms
tc_92db7fe9 search 4ms
Time: 2015-03-25T14:50:14 — 2015-03-25T15:15:50
Sources: registry.ntuser.informant, ez.mft
Evidence Refs: tc_2beaa53c, tc_2fa622d5, tc_92db7fe9
high confirmed Complete Cross-System Exfiltration and Anti-Forensic Timeline Reconstruction

Synthesizing all evidence sources across PC, RM1 (USB), RM2 (USB), and RM3 (CD-R), the following complete exfiltration timeline is reconstructed:

2015-02-15 (Sunday) — Initial Data Copy:
- 16:51:38 UTC: RM#1 directory modified on RM1 exFAT
- 16:52:08-20 UTC: Five secret project files copied to RM1 exFAT (design_concept.ppt, detailed_design.pptx, revised_points.ppt, detailed_proposal.docx, proposal.docx)

2015-02-27 — Cleanup:
- 17:20:18 UTC: "Secret Project Data" root directory deleted on RM1 exFAT

2015-03-22 (Sunday) — PC Setup and Network Access:
- 14:33:13Z: First login as "informant" (account created 14:33:54Z, login count=10)
- 14:52:22Z: First access to \\10.11.11.128\secured_drive via shellbags
- 15:11-15:17Z: Chrome, IE11 installed; Google Update running
- 15:51-15:53Z: Created admin11, ITechTeam, temporary accounts

2015-03-23 (Monday) — Document Work and Research:
- 16:55:17-37Z: Cover image files born on RM2 FAT32 (24 images)
- 17:26-17:28Z: Chrome launched, Bing/Google searched
- 18:37-18:40Z: Secret project files opened (LNK files created)
- 18:40:17Z: WordWheelQuery search for "secret"
- 20:02Z: Google Drive installed (clickonce_bootstrap.exe)
- 20:10Z: cmd.exe run (4x) — command-line operations
- 20:23-20:28Z: V: drive (network share) browsed, Excel/PowerPoint used

2015-03-24 (Tuesday) — Multi-Media Exfiltration:
- 09:59:26-10:00:18Z: 17 masqueraded files created on RM1 FAT32 and RM2 in 5 directories
- 13:37:59Z: USBSTOR driver last written (USB device connected)
- 13:38:31-14:01:29Z: E:\RM#1\Secret Project Data browsed on PC (shellbags)
- 18:48:40Z: Resignation_Letter_(Iaman_Informant).docx saved
- 19:47:48-20:44:18Z: D:\de, D:\tr, D:\pd, D:\prop, D:\prog browsed (CD-R/RM3 directories)
- 20:54:16-20:57:03Z: CD-R burned with 9 VAT sessions (17 documents + 3 cover photos)

2015-03-25 (Wednesday) — Anti-Forensics and Departure:
- 14:41:03Z: Outlook (5x total) — final email activity
- 14:50:14Z: Eraser installer run from Desktop\Download
- 14:57:56Z: CCleaner installer run from Desktop\Download
- 15:12:28Z: Eraser executed — secure file deletion
- 15:15:50Z: CCleaner64 executed — system trace cleaning
- 15:21:30Z: Google Drive sync launched — potential cloud exfiltration
- 15:24:48Z: WINWORD.EXE — resignation letter (4 total runs)
- 15:28:47Z: XPS viewer — resignation letter converted to XPS
- 15:29:08Z: Last RecentDocs write (final system activity)

Evidence strength:
4 refs
tsk.timelineregistry.usrclass.informantregistry.ntuser.informantregistry.system

Evidence Chain

tc_7e1c1241 get_raw_output 11ms
tc_7f5abba9 get_raw_output 99ms
tc_2beaa53c get_raw_output 100ms
tc_44f9e584 search 5ms
Time: 2015-02-15T16:51:38 — 2015-03-25T15:29:08
Sources: tsk.timeline, registry.usrclass.informant, registry.ntuser.informant, registry.system
Evidence Refs: tc_7e1c1241, tc_7f5abba9, tc_2beaa53c, tc_44f9e584
high confirmed CD-R (RM3) Data Exfiltration: 9 Burn Sessions with Masqueraded Documents

The CD-R disc image (rm3_type3.E01, volume label "IAMAN CD") contains a UDF write-once filesystem with 9 VAT (Virtual Allocation Table) generations, indicating the disc was burned in multiple sessions. The same set of 17 masqueraded secret project documents found on RM1's FAT32 partition and RM2 were also burned to this CD-R, using the SAME disguised filename scheme (.amr, .zip, .db, .7z, .jpg, .avi, .svg, .png, .one, .gif, .txt extensions).

Session Progression (9 VAT generations) — Directory Naming Evolution:
The CD-R preserves evidence of the user iteratively refining their concealment strategy across multiple burn sessions:

  • Sessions -7 to -3: Files first burned using FULL directory names matching the corporate network share structure:
  • /design/ (session -7): winter_storm.amr (14,547,968 bytes), winter_whether_advisory.zip (16,381,123 bytes)
  • /pricing decision/ (session -6): my_favorite_cars.db, my_favorite_movies.7z, new_years_day.jpg, super_bowl.avi
  • /progress/ (session -5): my_friends.svg, my_smartphone.png, new_year_calendar.one
  • /proposal/ (session -4): a_gift_from_you.gif (35,226,880 bytes), landscape.png (6,484,502 bytes)
  • /technical review/ (session -3): diary_#1d.txt through diary_#3p.txt (6 files)

  • Session -1: Files re-burned with ABBREVIATED directory names to obscure the connection to project categories:

  • /de/, /pd/, /prog/, /prop/, /tr/ — same 17 files, same sizes

  • Session 0 (final/active): All data directories deleted; only 3 stock Windows 7 photos remain:

  • Koala.jpg (780,831 bytes, created 2015-03-24T20:57:00Z)
  • Penguins.jpg (777,835 bytes, created 2015-03-24T20:57:00Z)
  • Tulips.jpg (620,888 bytes, created 2015-03-24T20:57:03Z)

Anti-forensic Deletion Pattern:
Files burned in earlier sessions were "deleted" in subsequent sessions (marked as deleted in UDF allocation). The write-once nature of UDF with VAT means deleted data remains physically on the disc despite being marked as removed in the active allocation table.

Shellbags confirm CD-R access: "BD-RE Drive (D:) IAMAN CD" with directories D:\de, D:\tr, D:\pd, D:\prop, D:\prog browsed 2015-03-24 19:47-20:44 UTC.

Evidence strength:
3 refs
optical.listingregistry.usrclass.informantregistry.ntuser.informant

Evidence Chain

tc_bfaf8fda get_raw_output 97ms
tc_293e882d get_raw_output 99ms
tc_2f1a7111 get_raw_output 99ms
Time: 2015-03-24T20:57:00 — 2015-03-25T14:45:59
Sources: optical.listing, registry.usrclass.informant, registry.ntuser.informant
Evidence Refs: tc_bfaf8fda, tc_293e882d, tc_2f1a7111
high confirmed CD-R (RM3) Multi-Session Anti-Forensic Technique: Iterative Directory Renaming and Deletion on Write-Once Media

The CD-R demonstrates a sophisticated multi-stage anti-forensic approach exploiting the user's misunderstanding of UDF write-once media behavior. The 9 VAT generations reveal the suspect's iterative attempt to conceal the exfiltrated data.

Anti-forensic technique #1 — File extension masquerading:
All 17 exfiltrated Office documents were renamed with false extensions to disguise their content:
- OLE documents (.ppt, .xls) given extensions: .amr, .db, .avi, .svg
- OOXML documents (.docx, .pptx, .xlsx) given extensions: .zip, .7z, .jpg, .png, .one, .gif, .txt
The filenames themselves were changed to innocuous personal-sounding names (winter_storm, my_favorite_cars, diary_#1d, etc.)

Anti-forensic technique #2 — Directory name obfuscation across sessions:
The disc preserves evidence of the user progressively obscuring the connection between directory names and the corporate project structure:
- Earlier sessions (-7 to -3): Full names "design", "pricing decision", "progress", "proposal", "technical review" — directly mapping to \\10.11.11.128\secured_drive\Secret Project Data subdirectories
- Later session (-1): Abbreviated to "de", "pd", "prog", "prop", "tr" — reducing the forensic connection
- Final session (0): All directories marked as deleted (both full and abbreviated names appear as empty deleted directories)

Anti-forensic technique #3 — Data overwriting with cover content:
After deleting all exfiltrated documents, the user burned 3 stock Windows 7 sample photos (Koala.jpg, Penguins.jpg, Tulips.jpg) to the active session. This would make the disc appear to contain only innocent sample photos if casually examined.

Anti-forensic failure — UDF VAT preservation:
The user likely did not understand that UDF's Virtual Allocation Table on write-once media preserves all previous generations. Each "deletion" only updated the VAT to mark files as removed, while the actual data remained physically intact on the disc. All 9 generations are recoverable through forensic analysis, exposing the complete history of the user's concealment attempts.

Session 0 final state shows both sets of deleted directory names:
The final session's deleted directory listing reveals BOTH the original full names AND the abbreviated names as empty deleted directories, providing direct evidence that the user created both naming schemes during the disc's lifecycle.

Evidence strength:
2 refs
optical.listingtsk.masquerade

Evidence Chain

tc_b8a8b6ad get_raw_output 101ms
tc_875be0b4 get_raw_output 101ms
Time: 2015-03-24T20:54:16 — 2015-03-24T20:57:03
Sources: optical.listing, tsk.masquerade
Evidence Refs: tc_b8a8b6ad, tc_875be0b4
high confirmed Cross-System: Premeditated Anti-Forensic and Data Leakage Research Preceding Exfiltration Campaign

Browser search history from the PC (bulk.url_searches) reveals the user "informant" conducted extensive research into data leakage techniques, anti-forensic tools, and digital forensics BEFORE executing the exfiltration campaign. This demonstrates premeditation and a deliberate attempt to understand — and evade — forensic investigation.

Anti-Forensic Tool Research (directly leading to tool downloads):
- "anti-forensic+tools" (n=85 search instances)
- "anti-forensics" (multiple direct searches)
- "ccleaner" (n=65) → Led to download of ccsetup504.exe, executed 2015-03-25 14:57:56Z
- "eraser" (n=51) → Led to download of Eraser 6.2.0.2962.exe, executed 2015-03-25 14:50:14Z
- "system+cleaner" (n=5+1)
- "how+to+delete+data" (n=5)

Data Leakage Planning Research:
- "information+leakage+cases" (n=47)
- "how+to+leak+a+secret" (n=6)
- "intellectual+property+theft" (n=6)
- "leaking+confidential+information" (n=2)
- "data+leakage+methods" (n=1)

Forensic Investigation Awareness (counter-forensics):
- "e-mail+investigation" (n=88)
- "Forensic+Email+Investigation" (n=78)
- "what+is+windows+system+artifacts" (n=79)
- "windows+event+logs" (n=61)
- "investigation+on+windows+machine" (n=64)
- "external+device+and+forensics" (n=65)
- "digital+forensics" (multiple)

Exfiltration Vector Research:
- "cloud+storage" (n=6) → Led to Google Drive and iCloud installation
- "google+drive" (n=10) → googledrivesync.exe downloaded and executed
- "apple+icloud" (n=1) → icloudsetup.exe installed
- "cd+burning+method" (n=64) → CD-R burning with masqueraded files
- "cd+burning+method+in+windows" (n=53)
- "security+checkpoint+cd-r" (n=1) — researched security controls for CD media

Data Protection/DLP Awareness:
- "DLP%20DRM" (n=90) — researched Data Loss Prevention and Digital Rights Management
- "file+sharing+and+tethering" (n=491)

Data Recovery Counter-Research:
- "data+recovery+tools" (multiple) — researched what tools could recover deleted data
- "how+to+recover+data" (multiple) — understood what investigators could find

Wired Article on Data Theft:
- Visited: http://www.wired.com/2015/03/stealing-data-computers-using-heat/ — article about "stealing data from computers using heat"

CONVERGENCE ACROSS EVIDENCE SOURCES:
This research activity (from bulk_extractor URL search histograms on the PC disk) directly correlates with actions documented in registry artifacts (UserAssist, ShimCache), removable media filesystems (masqueraded files, CD-R burns), and event logs (account creation). Each searched topic maps to a specific action taken:
1. Searched "ccleaner"/"eraser" → Downloaded and executed both tools
2. Searched "cloud+storage"/"google+drive" → Installed and ran googledrivesync.exe
3. Searched "cd+burning+method" → Burned data to CD-R with 9 VAT sessions
4. Searched "anti-forensic+tools" → Implemented file masquerading, deletion, and wiping
5. Searched "data+leakage+methods" → Executed multi-media exfiltration campaign

Evidence strength:
3 refs
bulk.url_searchesbulk.urlregistry.ntuser.informantez.shimcache

Evidence Chain

tc_754cd2ae get_raw_output 102ms
tc_edead4e7 search 4ms
tc_a8fe2dc1 search 6ms
Time: 2015-03-22T14:33:13 — 2015-03-25T15:29:08
Sources: bulk.url_searches, bulk.url, registry.ntuser.informant, ez.shimcache
Evidence Refs: tc_754cd2ae, tc_edead4e7, tc_a8fe2dc1
medium confirmed Dual-Partition USB Device Structure Enables Plausible Deniability

RM1 is a 4GB USB device containing two distinct partitions configured for apparent plausible deniability:

Partition 1 (exFAT):
- Volume Label: "Authorized USB"
- Volume Serial: 5c75-4d3e
- Contains active Secret Project Data files openly (in design/ and proposal/ subdirectories)
- Appears as an "authorized" work USB

Partition 2 (FAT32):
- Volume Label: "IAMAN $_@" — notably contains the user identifier "IAMAN" matching email addresses iaman@nist.gov and iaman.informant@nist.gov found on the source PC
- Volume ID: 0xb4d85399
- Originally contained 17 masqueraded copies of secret project documents (all deleted)
- Originally contained 22 cover image files (all deleted)
- Directory structure (design, pricing decision, progress, proposal, technical review) mirrors the network share at \10.11.11.128\secured_drive\Secret Project Data

The use of two partitions — one "clean" and one for covert storage — along with the false file extensions and subsequent deletion of all files on the second partition, demonstrates a deliberate multi-layered concealment strategy. If the USB was inspected casually, only the first "Authorized USB" partition would be visible, appearing to contain legitimate project files.

Evidence strength:
3 refs
tsk.fsstattsk.filelisttsk.masquerade

Evidence Chain

tc_f88b7a7a get_raw_output 102ms
tc_d67ae8aa get_raw_output 21ms
tc_62987b1e get_raw_output 104ms
Time: 2015-02-15T16:51:38 — 2015-03-24T17:02:36
Sources: tsk.fsstat, tsk.filelist, tsk.masquerade
Evidence Refs: tc_f88b7a7a, tc_d67ae8aa, tc_62987b1e
medium inference Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across RM1, RM2, and RM3

Bulk extractor analysis across all removable media carved identical document metadata, confirming the same documents are present on all three devices and providing attribution information.

Embedded email addresses (found on all three media):
- Eric_P._Lauer@omb.eop.gov (Office of Management and Budget, Executive Office of the President) — found in document content embedded at consistent offsets across RM2 and RM3
- wayne.longman@att.net — found as mailto: hyperlinks within document content, multiple occurrences
- mmun@loc.gov (Library of Congress) — found in context "(email address: mmun@loc.gov)" preceding a "PREFACE" section

Government/institutional domain references (from bulk.domain):
- www.iec.ch (International Electrotechnical Commission) — extensive references
- www.whitehouse.gov/omb — government OMB policy documents
- lcweb.loc.gov (Library of Congress)
- desert-estates.info — hyperlink in document content
- digitalcorpora.org/corpora/govdocs — GovDocs corpus references

EXIF metadata from document-embedded images:
- Kodak DC260 camera images (2003): Technical photographs
- Adobe Photoshop CS Macintosh processed images (2006): Document illustrations
- Cover images on RM1/RM2: Genuine personal photos from various sources (2004-2013 era)
- Cover images on RM3: Unmodified Windows 7 sample photos (Corbis/Microsoft, 2008-2009)

User identity confirmed across sources:
- iaman.informant@nist.gov (Outlook OST on PC)
- iaman.informant.personal@gmail.com (personal email in registry)
- Password hint "IAMAN" matches volume labels "IAMAN $_@" and "IAMAN CD"

Cross-media email convergence: The same three embedded email addresses appear at proportional disc offsets on RM2 and RM3, confirming byte-identical document content across media.

Evidence strength:
3 refs
bulk.emailbulk.domainbulk.exifoptical.listing

Evidence Chain

tc_532a7d97 search 7ms
tc_46252f53 search 3ms
tc_a4b039b1 get_raw_output 24ms
Time: 2015-02-15T16:51:38 — 2015-03-24T20:57:03
Sources: bulk.email, bulk.domain, bulk.exif, optical.listing
Evidence Refs: tc_532a7d97, tc_46252f53, tc_a4b039b1
ATT&CK: T1052.001
medium inference Potential Cloud Exfiltration via Google Drive and iCloud — Sync Config Destroyed by Anti-Forensic Tools

The user installed cloud storage applications representing additional exfiltration vectors. Anti-forensic cleanup destroyed evidence of what was synced.

Google Drive (confirmed execution):
- googledrivesync.exe installed: C:\Program Files (x86)\Google\Drive\ (MFT shows 27+ language files created 2015-03-23 20:02:43Z)
- ShimCache: googledrivesync.exe modified 2015-02-19 18:24:23, Executed=Yes
- UserAssist: Last executed 2015-03-25 15:21:30Z (1 GUI run)
- Shellbags: "Users\Google Drive" directory browsed (MRU 2015-03-25 15:20:59Z)
- CRITICAL: Google Drive launched AFTER Eraser (15:12Z) and CCleaner (15:15Z) — suggesting the user cleaned up first, then synced remaining data to cloud
- User searched "google+drive" (n=10) and "cloud+storage" (n=6) in browser

Google Drive Sync Evidence Destroyed:
- sync_config.db-shm (deleted, inode 73728)
- cacerts (deleted, inode 75037)
- snapshot.db (deleted, inode 75039)
- sync_config.db (deleted, inode 75040)
These deletions are consistent with Eraser's secure file deletion capability.

Apple iCloud (installed but uncertain usage):
- icloudsetup.exe in UserAssist (executed at some point)
- Bonjour Service installed: 2015-03-23 20:00:56Z (Apple dependency)
- User searched "apple+icloud" (n=1) in browser
- No definitive evidence of iCloud data sync

Significance:
The sequence (anti-forensic cleanup → Google Drive sync → resignation letter) suggests the user synced documents to Google Drive as a cloud exfiltration method complementing physical media. However, the destruction of sync configuration files means we cannot definitively confirm what was uploaded.

Evidence strength:
3 refs
registry.ntuser.informanttsk.filelist

Evidence Chain

tc_2beaa53c get_raw_output 100ms
tc_54511de3 search 6ms
tc_e8401491 get_raw_output 10ms
Time: 2015-03-23T20:01:53 — 2015-03-25T15:21:30
Sources: registry.ntuser.informant, tsk.filelist
Evidence Refs: tc_2beaa53c, tc_54511de3, tc_e8401491
medium inference Cross-System: Diversionary User Account Creation by Insider (admin11, ITechTeam, temporary)

On 2015-03-22, the "informant" user created three additional accounts within 2 minutes during initial PC setup. Chainsaw/Hayabusa security event analysis confirms the creation events, and registry analysis shows minimal activity on these accounts, suggesting they may have been diversionary.

Account Creation Events (from chainsaw.hunt and hayabusa.alerts):
- 2015-03-22 15:51:54Z: "admin11" created (Local User Creation + Added to Administrators group)
- 2015-03-22 15:52:30Z: "ITechTeam" created (Local User Creation + Added to Administrators group)
- 2015-03-22 15:53:01Z: "temporary" created (Local User Creation, NOT added to Administrators)

Hayabusa Alert: "User Added To Local Admin Grp" (high severity) at 2015-03-22 15:51:54Z — SrcSID matches informant's SID (S-1-5-21-2425377081-3129163575-2985601102-1001)

Account Activity Assessment (from per-user NTUSER.DAT and UsrClass.dat):
- admin11 (RID 1001): Login count=2, last login 2015-03-22 15:57:02Z. UserAssist shows only standard Windows exploration (Welcome Center, Control Panel). Shellbags show only Libraries/Desktop browsing. NO access to Secret Project Data, network shares, or removable media.
- ITechTeam (RID 1002): Never logged in (login count=0). No UserAssist or shellbag data.
- temporary (RID 1003): Login count=1. UserAssist shows only Welcome Center exploration (2015-03-22 15:56:13Z). Shellbags show only Libraries browsing. NO Secret Project Data access.

Correlation with Forensic Research:
The user's search history includes "investigation+on+windows+machine" (n=64), "what+is+windows+system+artifacts" (n=79), and "windows+event+logs" (n=61). Creating multiple accounts with varying privilege levels may have been an attempt to:
1. Create confusion about which account performed the data theft
2. Test whether account creation would be logged
3. Establish plausible deniability ("maybe admin11 did it")

Counter-analysis note (confidence downgrade from "confirmed" to "inference"):
The existence and creation of these accounts is confirmed. However, characterizing them as "diversionary" is an inference. Alternative explanations include: (1) testing account creation as part of learning Windows administration, (2) standard lab/test environment setup, or (3) creating accounts for other users who never used them. The diversionary interpretation is supported by the convergent forensic research evidence, but cannot be confirmed without direct evidence of intent. The accounts' creation is consistent with the broader attack chain pattern but does not independently prove anti-forensic motivation.

Significance: None of the three created accounts accessed the Secret Project Data. ALL exfiltration activity was performed under the "informant" account.

Evidence strength:
2 refs
chainsaw.hunthayabusa.alertsregistry.ntuser.admin11registry.usrclass.admin11registry.ntuser.temporaryregistry.usrclass.temporarybulk.url_searches

Evidence Chain

tc_83273c80 get_raw_output 100ms
tc_754cd2ae get_raw_output 102ms
Time: 2015-03-22T15:51:54 — 2015-03-22T15:58:26
Sources: chainsaw.hunt, hayabusa.alerts, registry.ntuser.admin11, registry.usrclass.admin11, registry.ntuser.temporary, registry.usrclass.temporary, bulk.url_searches
Evidence Refs: tc_83273c80, tc_754cd2ae
ATT&CK: T1136.001, T1098
medium inference Potential Co-Conspirator Contact Entry — spy.conspirator@nist.gov in Outlook Data

The informant's Outlook OST data store on the PC contains an email contact entry for "spy" with email address spy.conspirator@nist.gov. Bulk extractor recovered this from two locations in the disk image:

  • Offset 15509094608: Raw email address spy.conspirator@nist.gov in UTF-16 encoding within Outlook data structures
  • Offset 15509095786: Formatted display name entry spy <spy.conspirator@nist.gov> — indicating this was stored as a contact or autocomplete entry in the Outlook cache

The deliberately provocative naming convention (display name "spy", email "spy.conspirator") mirrors the informant's own email naming pattern (iaman.informant@nist.gov) and suggests this may be a co-conspirator in the data exfiltration scheme. The contact resided within the cached offline store (.ost) for iaman.informant@nist.gov.

Counter-analysis note (confidence downgrade from "confirmed" to "inference"):
- Only one evidence source (bulk.email from PC disk image) — no corroboration from a second independent source
- No actual email message content between the informant and this contact was recovered
- The provocative naming matches the synthetic naming convention used throughout this NIST CFREDS 2015 scenario (iaman.informant, spy.conspirator)
- The presence of a contact entry proves only that the address existed in Outlook autocomplete/contacts, not that conspiratorial communication occurred
- No evidence of secret project data being transmitted via email to any address

The exfiltration pathway appears to have been exclusively through removable media (RM1, RM2, RM3) and potentially cloud storage (Google Drive), not email.

Evidence strength:
2 refs
bulk.email

Evidence Chain

tc_507a3065 get_raw_output 10ms
tc_d0efb232 search 3ms
Time: 2015-03-22T15:03:29 — 2015-03-25T15:28:47
Sources: bulk.email
Evidence Refs: tc_507a3065, tc_d0efb232
ATT&CK: T1052.001
info confirmed Negative Finding: No Encrypted Containers or Steganographic Content on Any Removable Media

Analysis across all three removable media devices found no evidence of encrypted containers (TrueCrypt, VeraCrypt, BitLocker) or steganographic tools/content.

RM1 (USB): String analysis and YARA scanning produced no hits for encryption or steganography signatures. Cover images on the FAT32 partition contain genuine EXIF data from Kodak DC260 cameras and Adobe Photoshop CS.

RM3 (CD-R): steg.detection returned no results. YARA scan: no matches. The three active cover images (Koala.jpg, Penguins.jpg, Tulips.jpg) are unmodified Windows 7 sample photos from C:\Users\Public\Pictures\Sample Pictures\ — confirmed by exact file size matching against MFT entries on the PC. No size modification indicating appended steganographic data.

Anti-forensic techniques used were limited to:
1. File extension masquerading (false extensions on Office documents)
2. File deletion (all exfiltrated documents deleted after copying)
3. Multi-session CD burning with deletion (exploiting UDF VAT)
4. Cover content placement (stock/personal photos)
5. Anti-forensic tool execution (Eraser, CCleaner)

Evidence strength:
3 refs
strings.output

Evidence Chain

tc_614ce225 search 3ms
tc_2491e9ca search 3ms
tc_4febb050 search 5ms
Sources: strings.output
Evidence Refs: tc_614ce225, tc_2491e9ca, tc_4febb050
info confirmed System Configuration: User Accounts, Timezone, and PC Identity

System: informant-PC (Windows 7, 64-bit)
Timezone: Eastern Standard Time (UTC-5 standard / UTC-4 during EDT). Registry key ControlSet001\Control\TimeZoneInformation: Bias=300, ActiveTimeBias=240, TimeZoneKeyName=Eastern Standard Time. Last written: 2015-03-25T10:34:25Z.

User Accounts (from SAM hive):

  1. informant (RID 1000) - Primary active user
  2. Created: 2015-03-22 14:33:54Z
  3. Last Login: 2015-03-25 14:45:59Z
  4. Login Count: 10
  5. Password Hint: "IAMAN" (matches volume labels "IAMAN $_@" and "IAMAN CD")
  6. Account Type: Admin
  7. This user created all other accounts and is the primary actor

  8. admin11 (RID 1001) - Admin

  9. Created: 2015-03-22 15:51:54Z (created BY informant per Security event logs)
  10. Last Login: 2015-03-22 15:57:02Z
  11. Login Count: 2

  12. ITechTeam (RID 1002) - Admin

  13. Created: 2015-03-22 15:52:30Z (created BY informant)
  14. Never logged in

  15. temporary (RID 1003) - Limited user

  16. Created: 2015-03-22 15:53:01Z (created BY informant)
  17. Login Count: 1

  18. Administrator (RID 500) - Disabled

  19. Guest (RID 501) - Disabled

Security Event Log confirms: The informant user (S-1-5-21-...1000) created admin11, ITechTeam, and temporary accounts and added admin11 and ITechTeam to Administrators group on 2015-03-22. Password hint "IAMAN" directly links the user to the removable media labels.

Evidence strength:
3 refs
registry.systemregistry.query.systemhayabusa.alerts

Evidence Chain

tc_1236077e get_raw_output 10ms
tc_9e1064ac query_registry_value 4814ms
tc_49bb0cdc get_raw_output 100ms
Time: 2015-03-22T14:33:54 — 2015-03-25T14:45:59
Sources: registry.system, registry.query.system, hayabusa.alerts
Evidence Refs: tc_1236077e, tc_9e1064ac, tc_49bb0cdc
info confirmed Application Execution Timeline: Document Access and Exfiltration Workflow

UserAssist, ShimCache, and RecentDocs artifacts reconstruct the complete application execution timeline on the informant-PC, revealing a methodical data access, exfiltration, and cover-up workflow.

Application Execution Chronology (UserAssist timestamps, UTC):

Day 1 - 2015-03-22 (System Setup):
- 14:33:13Z: First login, standard Windows apps explored
- 15:12:32Z: IE11 installer downloaded and run (C:\Users\informant\Desktop\Download\IE11-Windows6.1-x64-en-us.exe)
- 15:24:47Z: System licensing (slui.exe, 3x)
- 15:51-15:53Z: Created admin11, ITechTeam, temporary accounts

Day 2 - 2015-03-23 (Document Work Begins):
- 17:26:50Z: Chrome launched
- 17:28:18Z: TypedURLs → bing.com, google.com
- 20:10:19Z: cmd.exe (4x) — command-line operations
- 20:23:28Z: First access to \10.11.11.128\secured_drive (shellbags)
- 20:26:50Z: Excel (1x) — (secret_project)_pricing_decision.xlsx
- 20:27:33Z: PowerPoint (2x) — [secret_project]_final_meeting.pptx

Day 3 - 2015-03-24 (Data Access and CD-R Burning):
- 13:37:59Z: USBSTOR driver last written (USB device connected)
- 13:38:31Z: E:\RM#1\Secret Project Data browsed (shellbags)
- 13:47:54Z-13:48:00Z: V:\Secret Project Data subdirectories accessed
- 14:16:37Z: rundll32.exe (1x)
- 18:31:55Z: Sticky Notes (13x total)
- 20:44:18Z: winter_whether_advisory.zip accessed (RecentDocs)
- 20:57:00Z: CD-R stock photos created (Koala.jpg, Penguins.jpg, Tulips.jpg)
- 21:01:14Z: Stock photos on CD-R viewed (RecentDocs .jpg)
- 21:05:38Z: Chrome (7x total)

Day 4 - 2015-03-25 (Final Day — Anti-Forensics and Departure):
- 14:41:03Z: Outlook (5x total) — email activity
- 14:42:47Z: Windows Media Player (1x)
- 14:46:05Z: Internet Explorer (5x total)
- 14:50:14Z: Eraser installer run from Desktop\Download
- 14:57:56Z: CCleaner installer run from Desktop\Download
- 15:12:28Z: Eraser executed — secure file deletion
- 15:15:50Z: CCleaner executed — system trace cleaning
- 15:21:30Z: Google Drive sync launched — cloud exfiltration
- 15:24:48Z: WINWORD.EXE (4x total) — resignation letter
- 15:28:47Z: XPS viewer — resignation letter conversion
- 15:29:08Z: Last RecentDocs write (Resignation_Letter_.docx)

Key ShimCache Entries (additional execution evidence):
- C:\Program Files\Eraser\Eraser.exe (modified 2015-01-12, Executed=Yes)
- C:\Program Files (x86)\Google\Drive\googledrivesync.exe (modified 2015-02-19, Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\OUTLOOK.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\WINWORD.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\POWERPNT.EXE (Executed=Yes)
- C:\Program Files\Microsoft Office\Office15\EXCEL.EXE (Executed=Yes)

Evidence strength:
3 refs
registry.ntuser.informantregistry.usrclass.informantez.shimcache

Evidence Chain

tc_8710ecf6 get_raw_output 10ms
tc_1829697a get_raw_output 12ms
tc_b6b7e690 search 5ms
Time: 2015-03-22T14:33:13 — 2015-03-25T15:29:08
Sources: registry.ntuser.informant, registry.usrclass.informant, ez.shimcache
Evidence Refs: tc_8710ecf6, tc_1829697a, tc_b6b7e690
info confirmed RecentDocs, WordWheelQuery, and OpenSaveMRU: Evidence of Document Search and Access Pattern

Multiple registry artifacts from the informant user's NTUSER.DAT hive document the systematic pattern of accessing and handling secret project documents.

WordWheelQuery (Windows Explorer Search):
- LastWrite: 2015-03-23 18:40:17Z
- Search term: "secret"
- This search was used to locate secret project documents on the network share or local system

RecentDocs (MRU Order, LastWrite 2015-03-25 15:29:08Z):
Most recently accessed first:
1. Resignation_Letter_(Iaman_Informant).docx
2. Resignation_Letter_(Iaman_Informant).xps
3. BD-RE Drive (D:) IAMAN CD
4. Tulips.jpg → 5. Koala.jpg → 6. Penguins.jpg (stock photos on CD-R)
7. BD-RE Drive (D:)
8. winter_whether_advisory.zip
9. final (folder)
10. [secret_project]_final_meeting.pptx
11. pricing decision (folder)
12. (secret_project)_pricing_decision.xlsx
13. secret (folder)
14. [secret_project]_design_concept.ppt
15. [secret_project]_proposal.docx

RecentDocs by Extension:
- .docx: [secret_project]proposal.docx, Resignation_Letter(Iaman_Informant).docx
- .ppt: [secret_project]design_concept.ppt (LastWrite 2015-03-23 18:38:21Z)
- .pptx: [secret_project]_final_meeting.pptx (LastWrite 2015-03-23 20:27:33Z)
- .xlsx: (secret_project)_pricing_decision.xlsx (LastWrite 2015-03-23 20:26:53Z)
- .xps: Resignation_Letter
(Iaman_Informant).xps (LastWrite 2015-03-25 15:28:33Z)
- .zip: winter_whether_advisory.zip (LastWrite 2015-03-24 20:44:18Z)
- .jpg: Tulips.jpg, Koala.jpg, Penguins.jpg (LastWrite 2015-03-24 21:01:14Z)
- Folders: BD-RE Drive IAMAN CD, BD-RE Drive, final, pricing decision, secret

OpenSavePidlMRU (File Open/Save Dialog History):
- LastWrite 2015-03-25 15:28:33Z
- Files accessed via open/save dialogs (MRU order):
1. Resignation_Letter_(Iaman_Informant).xps
2. Download\ccsetup504.exe
3. Download\Eraser 6.2.0.2962.exe
4. Resignation_Letter_(Iaman_Informant).docx
5. Download\IE11-Windows6.1-x64-en-us.exe
- .docx type: Resignation_Letter saved on 2015-03-24 18:48:40Z
- .exe type: ccsetup504.exe, Eraser installer, IE11 installer (LastWrite 2015-03-25 14:48:28Z)
- .xps type: Resignation Letter saved as XPS on 2015-03-25 15:28:33Z

TypedURLs (Internet Explorer):
- LastWrite 2015-03-23 17:28:18Z
- url1: http://www.bing.com/
- url2: http://google.com/
- url3: http://go.microsoft.com/fwlink/?LinkId=69157

These artifacts collectively demonstrate the user: (1) searched for "secret" documents, (2) accessed all secret project files in their original formats, (3) accessed the CD-R drive contents, (4) downloaded anti-forensic tools, and (5) created and saved a resignation letter.

Evidence strength:
2 refs
registry.ntuser.informant

Evidence Chain

tc_2fc026db get_raw_output 10ms
tc_8710ecf6 get_raw_output 10ms
Time: 2015-03-23T18:38:21 — 2015-03-25T15:29:08
Sources: registry.ntuser.informant
Evidence Refs: tc_2fc026db, tc_8710ecf6
info confirmed CD-R (RM3) EXIF Metadata: Cover Images Are Stock Windows 7 Photos, Document-Embedded Images Show Kodak and Adobe Processing

EXIF analysis of image data on the CD-R reveals two distinct classes of images:

1. Active Cover Images (3 files in final session):
The three remaining active files are stock Windows 7 sample photographs:
- Koala.jpg (780,831 bytes): Artist="Corbis", DateTimeOriginal=2008-02-11 11:32:43, modified 2009-03-12 13:48:28. SHA1: 8ed079594882a366e55d2435a8ef465e273a41ac
- Penguins.jpg (777,835 bytes): Artist="Corbis", DateTimeOriginal=2008-02-18 05:07:31, modified 2009-03-12 13:48:35. SHA1: 5db7f51e7ec17bd17335c85b069025072ba6614c
- Tulips.jpg (620,888 bytes): Copyright="Microsoft Corporation", DateTimeOriginal=2008-02-07 11:33:11, modified 2009-03-12 13:48:39. SHA1: 80824aa4a492d18585c4659632069dc9cc79fd47

These are standard Windows 7 sample photos (C:\Users\Public\Pictures\Sample Pictures) used as cover content to make the CD appear innocuous. Their modified dates (2009-07-14 05:32:31, the Windows 7 RTM date) and Corbis/Microsoft attribution confirm they are unmodified system files. They were burned to the CD on 2015-03-24 at 20:57:00-20:57:03 UTC, after all exfiltrated documents were deleted from the active filesystem.

2. Document-Embedded Image EXIF (from deleted sessions):
The masqueraded Office documents contain embedded images with EXIF data from two distinct sources:

a) Kodak DC260 photographs (2003 era):
- Camera: "Eastman Kodak Company" / "KODAK DIGITAL SCIENCE DC260 (V01.00)"
- DateTimeOriginal: 2003-09-24 15:33:42 and 2003-12-10 17:27:44
- Resolution: 1536×1024 pixels
- No GPS data present
- Found at offsets 1310146 and 9203260 in the CD-R image

b) Adobe Photoshop CS Macintosh processed images (2006 era):
- Software: "Adobe Photoshop CS Macintosh"
- DateTime stamps: 2006-03-21, between 11:19:46 and 13:39:22 (same day processing batch)
- Various dimensions (157×207 to 539×273 pixels) — small images typical of document illustrations
- Multiple distinct SHA1 hashes confirm these are unique images
- Found at 9 offsets between 95018581 and 99647667 in the CD-R image

No GPS coordinates were found in any images on the CD-R. The EXIF data does not contain steganographic indicators. The document-embedded images suggest the exfiltrated documents contain technical illustrations that were originally photographed with a Kodak DC260 camera in 2003 and processed in Adobe Photoshop CS on a Mac in March 2006.

Evidence strength:
2 refs
bulk.exifoptical.listing

Evidence Chain

tc_b1d2c51e get_raw_output 24ms
tc_b8a8b6ad get_raw_output 101ms
Time: 2015-03-24T20:54:16 — 2015-03-24T20:57:03
Sources: bulk.exif, optical.listing
Evidence Refs: tc_b1d2c51e, tc_b8a8b6ad
info confirmed No Valid PCAP Data Available — SMB File Transfer Analysis Not Possible

Investigation question: "Is there any evidence in the PCAP data of SMB file transfers between the PC and 10.11.11.128?"

Answer: No valid PCAP network capture files exist in the disk image. The only .cap files found were ATI GPU driver files (atiumd6a.cap, atiumdva.cap) located in the Windows driver store at C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_*. TShark confirmed these are not valid packet capture files.

Despite the absence of PCAP evidence, the SMB connection to \10.11.11.128\secured_drive is confirmed through multiple other artifacts:
- Shellbag entries showing navigation to the network share path
- File metadata timestamps on USB documents matching the source on the secured drive
- The PC's own IP was 10.11.11.129 (DHCP, same /24 subnet as the file server at 10.11.11.128)

Evidence strength:
2 refs
pcap.disk.atiumd6apcap.disk.atiumdvaregistry.system

Evidence Chain

tc_9f3e3cea search 3ms
tc_c43a20d8 get_raw_output 10ms
Sources: pcap.disk.atiumd6a, pcap.disk.atiumdva, registry.system
Evidence Refs: tc_9f3e3cea, tc_c43a20d8
0
Techniques
0
Tactics
0
Findings Mapped
Reconnaissance
Resource Development
Initial Access1
Execution2
Persistence3
Privilege Escalation2
Defense Evasion4
Credential Access
Discovery1
Lateral Movement
Collection2
Command and Control
Exfiltration2
Impact1
Inhibit Response Function
Evasion
Impair Process Control
Initial Access
Default Accounts
1F
Execution
PowerShell
1F
Malicious File
1F
Persistence
Default Accounts
1F
Account Manipulation
1F
Local Account
2F
Privilege Escalation
Default Accounts
1F
Account Manipulation
1F
Defense Evasion
Masquerade File Type
7F
Clear Command History
1F
File Deletion
7F
Default Accounts
1F
Discovery
Network Share Discovery
1F
Collection
Data from Network Shared Drive
2F
Local Data Staging
3F
Exfiltration
Exfiltration over USB
12F
Exfiltration to Cloud Storage
3F
Impact
Data Destruction
1F
0
Total IOCs
0
External IPs
0
File IOCs
0
Emails
Network IOCs (1)
TypeValueEnrichmentContextActions
Internal IP 10.11.11.128 Dual-Partition USB Device Structure Enables Plausible Deniability VT
File IOCs (1)
TypeValueEnrichmentContextActions
Path C:\Program Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Execute
Email IOCs (7)
TypeValueEnrichmentContextActions
Email iaman@nist.gov Dual-Partition USB Device Structure Enables Plausible Deniability
Email iaman.informant@nist.gov Dual-Partition USB Device Structure Enables Plausible Deniability
Email eric_p._lauer@omb.eop.gov Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across
Email wayne.longman@att.net Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across
Email mmun@loc.gov Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across
Email iaman.informant.personal@gmail.com Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across
Email spy.conspirator@nist.gov Potential Co-Conspirator Contact Entry — spy.conspirator@nist.gov in Outlook Dat
Select a source
Select a source from the tree to view raw evidence output.
Source Name Extractor Lines Hash Referenced By
tsk.partitions sleuthkit 8 blake2b:3eed10c8...
tsk.fsstat sleuthkit 37 blake2b:2d2079ee... 3 findings
tsk.partitions sleuthkit 9 blake2b:83c0b87c...
tsk.filelist sleuthkit 27 blake2b:ae86d6dd... 6 findings
hashdeep.hashes hashdeep 6 blake2b:c270e797...
tsk.fsstat sleuthkit 40 blake2b:9e253812... 3 findings
tsk.filelist sleuthkit 51 blake2b:55fc9962... 6 findings
tsk.partitions sleuthkit 8 blake2b:3eed10c8...
tsk.partitions sleuthkit 9 blake2b:83c0b87c...
tsk.partitions sleuthkit 10 blake2b:67b9085f...
optical.listing mulder-optical 58 blake2b:65ca19c0... 7 findings
ez.mft eztools 98918 blake2b:6381ab0d... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:3da38cb8...
bulk.domain bulk_extractor 237 blake2b:29444e46... 2 findings
bulk.email bulk_extractor 12 blake2b:26c081a6... 4 findings
bulk.exif bulk_extractor 21 blake2b:c2dd544d... 2 findings
bulk.rfc822 bulk_extractor 41 blake2b:e3da4d10...
bulk.url bulk_extractor 300 blake2b:28d82359... 1 finding
bulk.url_services bulk_extractor 21 blake2b:6224c8f2... 1 finding
tsk.filelist sleuthkit 104709 blake2b:171e0914... 6 findings
tsk.filelist.p1 sleuthkit 93 blake2b:5bdfadd3... 6 findings
bulk.bulk_extractor bulk_extractor 1 blake2b:c2a52474...
bulk.domain bulk_extractor 264 blake2b:c8b97b94... 2 findings
bulk.duplicates bulk_extractor 9 blake2b:9ba9de0c...
bulk.email bulk_extractor 43 blake2b:eb085c00... 4 findings
bulk.exif bulk_extractor 27 blake2b:eaa48964... 2 findings
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9...
bulk.url bulk_extractor 288 blake2b:d727c498... 1 finding
bulk.url_services bulk_extractor 19 blake2b:01e609ea... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:54705fdb...
bulk.domain bulk_extractor 189 blake2b:ae916b75... 2 findings
bulk.duplicates bulk_extractor 9 blake2b:bb406faf...
bulk.exif bulk_extractor 20 blake2b:d7c9e32a... 2 findings
bulk.url bulk_extractor 207 blake2b:039de0b6... 1 finding
bulk.url_services bulk_extractor 14 blake2b:2eac1377... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:cd0c5cdc...
bulk.domain bulk_extractor 366963 blake2b:fc1062a8... 2 findings
bulk.duplicates bulk_extractor 12 blake2b:f8b9f6c0...
bulk.email bulk_extractor 6851 blake2b:1790b6a7... 4 findings
bulk.ether bulk_extractor 6 blake2b:0825117f...
bulk.exif bulk_extractor 793 blake2b:2158d20a... 2 findings
bulk.rfc822 bulk_extractor 7326 blake2b:cfe35c27...
bulk.url bulk_extractor 421750 blake2b:c2ca3420... 1 finding
bulk.url_facebook-address bulk_extractor 19 blake2b:7fe55073... 1 finding
bulk.url_searches bulk_extractor 155 blake2b:b928562c... 2 findings
bulk.url_services bulk_extractor 3637 blake2b:c01e89c3... 1 finding
bulk.winpe bulk_extractor 29138 blake2b:16029dc9...
bulk.winpe_carved bulk_extractor 29130 blake2b:8048b50e...
registry.system regripper 186 blake2b:5cd5d58a... 5 findings
registry.system regripper 7 blake2b:e4c6f012... 5 findings
registry.system regripper 7 blake2b:e4c6f012... 5 findings
registry.system regripper 69 blake2b:6b7bf22c... 5 findings
registry.system regripper 8 blake2b:3c5e87f4... 5 findings
pcap.disk.atiumd6a tshark 8 blake2b:e0cc3007... 1 finding
tsk.masquerade sleuthkit 0 blake2b:empty... 6 findings
registry.system regripper 33492 blake2b:9ef84a11... 5 findings
pcap.disk.atiumdva tshark 8 blake2b:717532ef... 1 finding
evtx.manifest evtx-extract 54 blake2b:62bd3681...
tsk.masquerade sleuthkit 17 blake2b:97440a18... 6 findings
registry.system regripper 283 blake2b:fc484f66... 5 findings
ez.shimcache eztools 307 blake2b:a4845f8d... 2 findings
registry.system regripper 283 blake2b:3a9de3b9... 5 findings
pcap.disk.atiumd6a tshark 8 blake2b:e0cc3007... 1 finding
registry.query.software python-registry 1 blake2b:5779bd0c...
registry.system regripper 5209 blake2b:271fd1be... 5 findings
registry.system regripper 199 blake2b:35341c41... 5 findings
pcap.disk.atiumdva tshark 8 blake2b:717532ef... 1 finding
registry.system regripper 199 blake2b:2be4a97a... 5 findings
pcap.disk.atiumd6a tshark 8 blake2b:e0cc3007... 1 finding
hayabusa.alerts hayabusa 35 blake2b:8f8ce27e... 2 findings
pcap.disk.atiumdva tshark 8 blake2b:717532ef... 1 finding
registry.query.system python-registry 1 blake2b:2ae2eb16... 1 finding
registry.query.system python-registry 1 blake2b:8639046c... 1 finding
registry.query.system python-registry 1 blake2b:106b833a... 1 finding
tsk.timeline sleuthkit 344089 blake2b:4cc4645b... 5 findings
registry.system regripper 381 blake2b:070a4d56... 5 findings
registry.system regripper 255 blake2b:0d77cf74... 5 findings
registry.system regripper 255 blake2b:0d77cf74... 5 findings
registry.usrclass.admin11 regripper 11 blake2b:26a43778... 1 finding
registry.ntuser.admin11 regripper 133 blake2b:bf617a09... 1 finding
registry.ntuser.default regripper 74 blake2b:8518dc3f...
registry.usrclass.informant regripper 102 blake2b:9f1344c3... 8 findings
registry.ntuser.informant regripper 306 blake2b:597d71cd... 9 findings
registry.usrclass.temporary regripper 15 blake2b:3ef5eb22... 1 finding
registry.ntuser.temporary regripper 118 blake2b:800424ee... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:7d6368ee...
bulk.domain bulk_extractor 5206 blake2b:1f177d2c... 2 findings
bulk.duplicates bulk_extractor 1298 blake2b:a115e731...
bulk.email bulk_extractor 15 blake2b:23d970cf... 4 findings
bulk.exif bulk_extractor 20 blake2b:d7c9e32a... 2 findings
bulk.url bulk_extractor 5226 blake2b:db311642... 1 finding
bulk.url_services bulk_extractor 25 blake2b:d5889ea9... 1 finding
bulk.zip_carved bulk_extractor 3851 blake2b:34af67f4...
exiftool.metadata exiftool 9 blake2b:f2d57075...
hashdeep.hashes hashdeep 6 blake2b:0e07b059...
tsk.timeline sleuthkit 67 blake2b:822b5179... 5 findings
strings.output strings 22065 blake2b:9705a003... 1 finding
bulk.bulk_extractor bulk_extractor 1 blake2b:b880e20a...
bulk.domain bulk_extractor 7330 blake2b:c953e364... 2 findings
bulk.duplicates bulk_extractor 1742 blake2b:f0cc1b26...
bulk.email bulk_extractor 61 blake2b:85d5f607... 4 findings
bulk.exif bulk_extractor 27 blake2b:eaa48964... 2 findings
bulk.rfc822 bulk_extractor 41 blake2b:283d0ef9...
bulk.url bulk_extractor 7192 blake2b:e1252d17... 1 finding
bulk.url_services bulk_extractor 58 blake2b:033e5d0e... 1 finding
bulk.zip_carved bulk_extractor 5221 blake2b:75538583...
tsk.timeline sleuthkit 187 blake2b:da03c607... 5 findings
exiftool.metadata exiftool 9 blake2b:e7b52a8d...
strings.output strings 165747 blake2b:2b7a943c... 1 finding
tsk.masquerade sleuthkit 3 blake2b:42bb5e7d... 6 findings
chainsaw.hunt chainsaw 99 blake2b:d992d688... 1 finding
registry.query.system python-registry 1 blake2b:106b833a... 1 finding
exiftool.metadata exiftool 9 blake2b:bb09ed66...
hashdeep.hashes hashdeep 6 blake2b:28ba0ef4...
strings.output strings 34815 blake2b:89a5dd6d... 1 finding
composite.timeline composite 172 blake2b:1204d042...
composite.execution composite 122 blake2b:06171204...
composite.defense_evasion composite 216 blake2b:243251bc...
composite.correlation composite 1 blake2b:3b4df503...
composite.correlation composite 1 blake2b:b900b4f1...
composite.correlation composite 1 blake2b:bebebfd1...
composite.correlation composite 1 blake2b:7d8d456d...
composite.correlation composite 1 blake2b:d3b22136...
composite.correlation composite 1 blake2b:454d74b0...
composite.file_staging composite 578 blake2b:06da57a3...
composite.exfil composite 2494 blake2b:fc05150a...
enrichment.iocs enrichment 59 blake2b:d99d9021...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 578 blake2b:06da57a3...
composite.correlation composite 1 blake2b:69e54f70...
forensic.timestomping timestomp_detector 1 blake2b:a8aad413...
composite.file_staging composite 578 blake2b:06da57a3...
composite.correlation composite 1 blake2b:69e54f70...
0
Tool Calls
0
Unique Tools
2926.1s
Processing Time
266,680
Tokens
5,468
Tokens/min
Tool Distribution
Token Breakdown
Input Tokens36,946
Output Tokens229,734
Total Tokens266,680
Per-Model Breakdown
claude-opus-4-6266,680
Token Throughput Over Time
Estimated token consumption by model over time. Each bar represents a 5-minute window.
ID Tool Duration Timestamp Actions
tc_bee59d22 scan_evidence 2103ms 2026-09-19T19:55:01
tc_1fba11a8 list_directory 2ms 2026-09-19T19:55:06
tc_01a72692 list_sources 2ms 2026-09-19T19:55:06
tc_f4deafe2 get_source_stats 2ms 2026-09-19T19:55:06
tc_4d0f2fba open_case 29ms 2026-09-19T19:55:42
tc_67cc39a0 list_directory 2ms 2026-09-19T19:55:42
tc_cfbf6412 open_case 30ms 2026-09-19T19:55:43
tc_8f805a0b open_case 30ms 2026-09-19T19:55:43
tc_70e7bba8 list_directory 2ms 2026-09-19T19:55:43
tc_3c2c10cf list_directory 2ms 2026-09-19T19:55:43
tc_87c1d7d2 list_sources 2ms 2026-09-19T19:55:56
tc_2de15df9 list_sources 2ms 2026-09-19T19:55:58
tc_13c71e56 open_case 29ms 2026-09-19T19:56:32
tc_a5145cbc run_mmls 36ms 2026-09-19T19:56:43
tc_5507e8cf run_fsstat 57ms 2026-09-19T19:56:43
tc_b9d2a50d open_case 30ms 2026-09-19T19:56:45
tc_54ffed04 start_extraction_batch 5ms 2026-09-19T19:56:48
tc_070272f9 run_mmls 75ms 2026-09-19T19:56:51
tc_7c98d92a run_fls 3638ms 2026-09-19T19:56:51
tc_e3412c14 run_hashdeep 1507ms 2026-09-19T19:56:52
tc_13f8e27f run_fsstat 59ms 2026-09-19T19:56:56
tc_5d4dee95 start_extraction_batch 5ms 2026-09-19T19:56:56
tc_9dee8d78 run_photorec 4ms 2026-09-19T19:56:56
tc_b8375fca run_fls 1097ms 2026-09-19T19:56:57
tc_b5265e6e open_case 34ms 2026-09-19T20:00:44
tc_92a19233 run_mmls 35ms 2026-09-19T20:00:48
tc_23b0d6e3 run_mmls 62ms 2026-09-19T20:00:48
tc_f80f3cff run_mmls 77ms 2026-09-19T20:00:48
tc_11254085 start_extraction_batch 16ms 2026-09-19T20:00:55
tc_b7a115d4 run_optical_listing 96ms 2026-09-19T20:00:55
tc_c5591884 run_mft_parser 8312ms 2026-09-19T20:01:03
tc_677fa84a run_bulk_extractor 9384ms 2026-09-19T20:01:04
tc_7643f576 run_fls 17856ms 2026-09-19T20:01:12
tc_8809a1ab run_bulk_extractor 107053ms 2026-09-19T20:02:42
tc_97db2ec7 run_bulk_extractor 109406ms 2026-09-19T20:02:44
tc_96e4a04b run_bulk_extractor 343098ms 2026-09-19T20:06:38
tc_2f02ff8f get_completed_results 0ms 2026-09-19T20:06:40
tc_b41c0821 start_extraction_batch 9ms 2026-09-19T20:06:48
tc_570cb1da run_amcache_parser 0ms 2026-09-19T20:07:02
tc_9eb3e729 detect_masquerading 6100ms 2026-09-19T20:07:08
tc_4e8e7d7e run_evtx_parser 19201ms 2026-09-19T20:07:13
tc_af92ace0 detect_masquerading 4909ms 2026-09-19T20:07:13
tc_1cd93a63 detect_masquerading 0ms 2026-09-19T20:07:13
tc_4d185fe0 run_shimcache_parser 21072ms 2026-09-19T20:07:14
tc_2914cb8d query_registry_value 19657ms 2026-09-19T20:07:15
tc_6a24bf13 parse_browser_history 23751ms 2026-09-19T20:07:19
tc_0c767bd7 run_hayabusa 28707ms 2026-09-19T20:07:22
tc_a9928c82 query_registry_value 27633ms 2026-09-19T20:07:23
tc_52e81cfe query_registry_value 27706ms 2026-09-19T20:07:23
tc_f771dca9 analyze_disk_pcaps 28636ms 2026-09-19T20:07:24
tc_83c7c047 query_registry_value 29038ms 2026-09-19T20:07:24
tc_7d7f8be9 run_prefetch_parser 34281ms 2026-09-19T20:07:28
tc_509498f3 run_mactime 39074ms 2026-09-19T20:07:32
tc_87da887d run_registry_parser 52894ms 2026-09-19T20:07:41
tc_df928ac0 run_bulk_extractor 711588ms 2026-09-19T20:08:39
tc_792f16d8 get_completed_results 0ms 2026-09-19T20:08:41
tc_a1a0e4ab start_extraction_batch 4ms 2026-09-19T20:09:06
tc_1b335a94 run_photorec 4ms 2026-09-19T20:09:06
tc_513d4a13 run_mft_parser 26ms 2026-09-19T20:09:06
tc_e261c801 detect_masquerading 0ms 2026-09-19T20:09:08
tc_c80813e8 run_exiftool 88ms 2026-09-19T20:09:08
tc_4ffb4939 run_hashdeep 424ms 2026-09-19T20:09:08
tc_d6ef4645 run_mactime 3611ms 2026-09-19T20:09:10
tc_539b5057 run_strings 671ms 2026-09-19T20:09:14
tc_b21d3456 yara_scan_files 6701ms 2026-09-19T20:09:15
tc_527c518b get_completed_results 0ms 2026-09-19T20:09:23
tc_38245ae9 open_case 31ms 2026-09-19T20:09:38
tc_ea58f110 get_investigation_summary 5ms 2026-09-19T20:09:42
tc_b7e12a25 list_sources 2ms 2026-09-19T20:09:42
tc_12f14b79 get_raw_output 118ms 2026-09-19T20:09:49
tc_f88b7a7a get_raw_output 102ms 2026-09-19T20:09:51
tc_d67ae8aa get_raw_output 21ms 2026-09-19T20:09:51
tc_62987b1e get_raw_output 104ms 2026-09-19T20:10:18
tc_d1bbd94c get_raw_output 103ms 2026-09-19T20:10:18
tc_895e4b1b get_raw_output 99ms 2026-09-19T20:10:19
tc_6d9c776c get_raw_output 84ms 2026-09-19T20:10:35
tc_532a7d97 search 7ms 2026-09-19T20:10:36
tc_a4b039b1 get_raw_output 24ms 2026-09-19T20:10:36
tc_67c35a0e search 4ms 2026-09-19T20:10:45
tc_b88e2a9b search 3ms 2026-09-19T20:10:45
tc_46ac5417 search 5ms 2026-09-19T20:10:46
tc_393cf1ce search 4ms 2026-09-19T20:10:56
tc_f0925a2e search 3ms 2026-09-19T20:10:57
tc_f6ac5d20 search 5ms 2026-09-19T20:10:58
tc_3e22222d search 3ms 2026-09-19T20:11:04
tc_82e1e3e4 get_deleted_files 150ms 2026-09-19T20:11:04
tc_1f6ef439 search 3ms 2026-09-19T20:11:05
tc_0d2e8d40 run_bulk_extractor 854434ms 2026-09-19T20:11:10
tc_b7d88ffd search 9ms 2026-09-19T20:11:13
tc_4d5d332a get_raw_output 29ms 2026-09-19T20:11:14
tc_c9e19e77 search 3ms 2026-09-19T20:11:14
tc_90be43e2 get_completed_results 0ms 2026-09-19T20:11:15
tc_f26ac21a get_raw_output 113ms 2026-09-19T20:11:20
tc_71789dbd search 3ms 2026-09-19T20:11:20
tc_46252f53 search 3ms 2026-09-19T20:11:21
tc_f268e215 start_extraction_batch 4ms 2026-09-19T20:11:40
tc_73c115e3 detect_masquerading 0ms 2026-09-19T20:11:40
tc_cc93cbdc run_mft_parser 40ms 2026-09-19T20:11:40
tc_cbe4a670 run_mactime 1006ms 2026-09-19T20:11:41
tc_79ec605a run_exiftool 85ms 2026-09-19T20:11:41
tc_a7a2af9c run_strings 2558ms 2026-09-19T20:11:43
tc_6f8e6e9c yara_scan_files 8316ms 2026-09-19T20:11:49
tc_97df813f search 11ms 2026-09-19T20:11:53
tc_de89001e detect_masquerading 300015ms 2026-09-19T20:11:53
tc_4f50aa15 search 3ms 2026-09-19T20:11:53
tc_facbb9dd get_completed_results 0ms 2026-09-19T20:11:57
tc_ce5da528 search 3ms 2026-09-19T20:11:57
tc_b61a548a get_raw_output 11ms 2026-09-19T20:11:58
tc_8527a47d get_completed_results 0ms 2026-09-19T20:11:58
tc_4f23b9af run_chainsaw 1426ms 2026-09-19T20:12:07
tc_7526da95 open_case 31ms 2026-09-19T20:12:26
tc_01de4c73 yara_scan_files 20685ms 2026-09-19T20:12:26
tc_c3bca976 get_investigation_summary 5ms 2026-09-19T20:12:30
tc_781c5a00 list_sources 2ms 2026-09-19T20:12:30
tc_5d633d74 list_partitions 2ms 2026-09-19T20:12:30
tc_27bf2a30 get_raw_output 22ms 2026-09-19T20:12:38
tc_ec173722 get_raw_output 99ms 2026-09-19T20:12:39
tc_65432829 get_raw_output 101ms 2026-09-19T20:12:40
tc_3c7ae72c submit_finding 74ms 2026-09-19T20:12:47
tc_d42d6199 open_case 31ms 2026-09-19T20:13:01
tc_4743f57a search 5ms 2026-09-19T20:13:02
tc_5f00137e get_raw_output 100ms 2026-09-19T20:13:03
tc_43799fbc wait_all 0ms 2026-09-19T20:13:03
tc_a3f0d0c1 get_raw_output 99ms 2026-09-19T20:13:04
tc_336f9f8f submit_finding 8ms 2026-09-19T20:13:06
tc_a41d526e open_case 31ms 2026-09-19T20:13:14
tc_9640a91c search 4ms 2026-09-19T20:13:15
tc_7e1c1241 get_raw_output 11ms 2026-09-19T20:13:16
tc_6ad4d887 get_raw_output 30ms 2026-09-19T20:13:16
tc_d000ecc6 get_investigation_summary 5ms 2026-09-19T20:13:17
tc_223ab028 list_sources 2ms 2026-09-19T20:13:17
tc_38170e9e submit_finding 10ms 2026-09-19T20:13:20
tc_8bbde21a get_findings 1ms 2026-09-19T20:13:25
tc_decdaf2e get_raw_output 102ms 2026-09-19T20:13:26
tc_af2aabc4 search 5ms 2026-09-19T20:13:26
tc_0ad0039a search 4ms 2026-09-19T20:13:27
tc_7f5abba9 get_raw_output 99ms 2026-09-19T20:13:28
tc_5176505e search 3ms 2026-09-19T20:13:29
tc_9373d670 search 11ms 2026-09-19T20:13:30
tc_e61bdc86 submit_finding 10ms 2026-09-19T20:13:34
tc_8478da81 get_raw_output 101ms 2026-09-19T20:13:36
tc_44f9e584 search 5ms 2026-09-19T20:13:37
tc_2beaa53c get_raw_output 100ms 2026-09-19T20:13:38
tc_9e1064ac query_registry_value 4814ms 2026-09-19T20:13:39
tc_ca7900d6 search 5ms 2026-09-19T20:13:39
tc_247a599e get_raw_output 20ms 2026-09-19T20:13:39
tc_9e2a03d3 get_raw_output 98ms 2026-09-19T20:13:39
tc_97bd88d5 get_raw_output 9ms 2026-09-19T20:13:49
tc_bfaf8fda get_raw_output 97ms 2026-09-19T20:13:50
tc_f1c8214a search 5ms 2026-09-19T20:13:51
tc_a0f52611 search 8ms 2026-09-19T20:13:51
tc_e6f39a77 submit_finding 17ms 2026-09-19T20:13:52
tc_1236077e get_raw_output 10ms 2026-09-19T20:13:59
tc_9e99e9af search 4ms 2026-09-19T20:14:01
tc_628b2522 get_raw_output 100ms 2026-09-19T20:14:01
tc_2f1a7111 get_raw_output 99ms 2026-09-19T20:14:02
tc_fe3dc26b submit_finding 15ms 2026-09-19T20:14:07
tc_24cae0ce search 8ms 2026-09-19T20:14:11
tc_82b27a64 search 3ms 2026-09-19T20:14:12
tc_0c33ddac bookmark_window 11ms 2026-09-19T20:14:16
tc_4dd992d9 bookmark_window 11ms 2026-09-19T20:14:18
tc_19589fad search 3ms 2026-09-19T20:14:22
tc_9c417cac get_raw_output 30ms 2026-09-19T20:14:23
tc_2cd31b75 search 3ms 2026-09-19T20:14:24
tc_46f8345c search 3ms 2026-09-19T20:14:32
tc_67ae5f95 search 4ms 2026-09-19T20:14:34
tc_293e882d get_raw_output 99ms 2026-09-19T20:14:35
tc_eb524e79 search 5ms 2026-09-19T20:14:35
tc_02869b8d submit_finding 15ms 2026-09-19T20:14:38
tc_b7dbfc57 list_files 216ms 2026-09-19T20:14:41
tc_59fae84e search 4ms 2026-09-19T20:14:41
tc_0a00bd6e search 3ms 2026-09-19T20:14:42
tc_64af1c79 search 7ms 2026-09-19T20:14:43
tc_eb98478b submit_finding 17ms 2026-09-19T20:14:49
tc_bb05b01c search 4ms 2026-09-19T20:14:50
tc_ca2004a9 get_raw_output 99ms 2026-09-19T20:14:50
tc_2ab5967b search 8ms 2026-09-19T20:14:52
tc_9129ac52 search 6ms 2026-09-19T20:14:53
tc_914bc2ec submit_finding 17ms 2026-09-19T20:14:55
tc_6164f7f6 search 3ms 2026-09-19T20:14:59
tc_b52193cf search 3ms 2026-09-19T20:14:59
tc_614ce225 search 3ms 2026-09-19T20:15:05
tc_2491e9ca search 3ms 2026-09-19T20:15:05
tc_45ac10ec submit_finding 16ms 2026-09-19T20:15:06
tc_4febb050 search 5ms 2026-09-19T20:15:06
tc_37df8f97 submit_finding 16ms 2026-09-19T20:15:17
tc_fe7d1774 bookmark_window 12ms 2026-09-19T20:15:21
tc_88406e78 bookmark_window 11ms 2026-09-19T20:15:24
tc_cd3dce9a submit_finding 17ms 2026-09-19T20:15:25
tc_0b0112c3 bookmark_window 11ms 2026-09-19T20:15:26
tc_1c96587a search 4ms 2026-09-19T20:15:28
tc_49bb0cdc get_raw_output 100ms 2026-09-19T20:15:28
tc_f1270fed search 12ms 2026-09-19T20:15:29
tc_fced7036 search 4ms 2026-09-19T20:15:29
tc_24dd2874 search 4ms 2026-09-19T20:15:37
tc_8f6e736e search 3ms 2026-09-19T20:15:38
tc_7f65e9f2 search 6ms 2026-09-19T20:15:39
tc_06c1de6a submit_finding 16ms 2026-09-19T20:15:42
tc_27c06c83 track_progress 13ms 2026-09-19T20:15:45
tc_c1fe3c55 submit_finding 16ms 2026-09-19T20:15:56
tc_2fa622d5 search 6ms 2026-09-19T20:16:00
tc_92db7fe9 search 4ms 2026-09-19T20:16:01
tc_ca5339c7 get_raw_output 82ms 2026-09-19T20:16:02
tc_150847e3 get_raw_output 98ms 2026-09-19T20:16:02
tc_4f1fe60d search 3ms 2026-09-19T20:16:03
tc_531559d2 search 5ms 2026-09-19T20:16:04
tc_7dcfeb90 get_investigation_summary 6ms 2026-09-19T20:16:04
tc_5c3514df update_finding 14ms 2026-09-19T20:16:07
tc_359827b4 open_case 31ms 2026-09-19T20:16:10
tc_0d4ec4c1 list_directory 2ms 2026-09-19T20:16:10
tc_a1c8e852 list_sources 3ms 2026-09-19T20:16:19
tc_ed187b9e submit_finding 15ms 2026-09-19T20:16:25
tc_802e994f submit_finding 17ms 2026-09-19T20:16:31
tc_05d77868 submit_finding 15ms 2026-09-19T20:16:44
tc_71ef37d8 submit_finding 16ms 2026-09-19T20:17:02
tc_a1c06eb2 submit_finding 15ms 2026-09-19T20:17:23
tc_46cce383 search 3ms 2026-09-19T20:17:27
tc_54511de3 search 6ms 2026-09-19T20:17:28
tc_a110b292 get_raw_output 99ms 2026-09-19T20:17:29
tc_06ad3173 search 5ms 2026-09-19T20:17:40
tc_75c1e5d9 search 3ms 2026-09-19T20:17:41
tc_e8401491 get_raw_output 10ms 2026-09-19T20:17:49
tc_eb7fef9f submit_finding 16ms 2026-09-19T20:18:09
tc_73e4c505 get_findings 2ms 2026-09-19T20:18:11
tc_ca370897 submit_finding 16ms 2026-09-19T20:18:53
tc_62dfd609 submit_finding 17ms 2026-09-19T20:19:09
tc_535a275e open_case 33ms 2026-09-19T20:19:15
tc_f87e949a search 4ms 2026-09-19T20:19:15
tc_013d88d0 search 4ms 2026-09-19T20:19:16
tc_28fce04e search 4ms 2026-09-19T20:19:17
tc_c902226c run_exiftool 95ms 2026-09-19T20:19:21
tc_29415098 run_hashdeep 486ms 2026-09-19T20:19:22
tc_8c87095d run_strings 871ms 2026-09-19T20:19:22
tc_405f9edc search 3ms 2026-09-19T20:19:26
tc_b6b7e690 search 5ms 2026-09-19T20:19:27
tc_2b98671d yara_scan_files 6610ms 2026-09-19T20:19:28
tc_eacc58a8 extract_optical_file 0ms 2026-09-19T20:19:35
tc_331ce70d search 4ms 2026-09-19T20:19:36
tc_53423a28 search 3ms 2026-09-19T20:19:36
tc_8774bdf4 search 3ms 2026-09-19T20:19:42
tc_5b7bbc9b search 3ms 2026-09-19T20:19:44
tc_1170fb64 search 5ms 2026-09-19T20:19:47
tc_a7f5c3e0 search 5ms 2026-09-19T20:19:48
tc_2bc81e0d update_finding 13ms 2026-09-19T20:19:58
tc_551daa12 search 3ms 2026-09-19T20:20:02
tc_482fac80 search 5ms 2026-09-19T20:20:03
tc_434e6b5f extract_optical_file 83ms 2026-09-19T20:20:05
tc_19745a47 extract_optical_file 86ms 2026-09-19T20:20:05
tc_65d1ad2c extract_optical_file 100ms 2026-09-19T20:20:05
tc_b32788d6 extract_optical_file 101ms 2026-09-19T20:20:05
tc_f885c13c extract_optical_file 134ms 2026-09-19T20:20:05
tc_aa5059bb extract_optical_file 142ms 2026-09-19T20:20:05
tc_24f3365d extract_optical_file 143ms 2026-09-19T20:20:05
tc_9fedbbfb extract_optical_file 146ms 2026-09-19T20:20:05
tc_cc274e2d extract_optical_file 64ms 2026-09-19T20:20:05
tc_59767766 extract_optical_file 63ms 2026-09-19T20:20:05
tc_c36bebe1 extract_optical_file 82ms 2026-09-19T20:20:05
tc_034105a7 extract_optical_file 54ms 2026-09-19T20:20:05
tc_b73035f9 extract_optical_file 114ms 2026-09-19T20:20:05
tc_3331dbed extract_optical_file 76ms 2026-09-19T20:20:05
tc_ae4ca1ed extract_optical_file 85ms 2026-09-19T20:20:05
tc_f7884609 extract_optical_file 70ms 2026-09-19T20:20:05
tc_34306b05 extract_optical_file 87ms 2026-09-19T20:20:05
tc_b031dc9a extract_optical_file 70ms 2026-09-19T20:20:05
tc_24965fd9 extract_optical_file 106ms 2026-09-19T20:20:05
tc_419499ae extract_optical_file 70ms 2026-09-19T20:20:05
tc_5112a25c extract_optical_file 53ms 2026-09-19T20:20:05
tc_07948a6b extract_optical_file 90ms 2026-09-19T20:20:05
tc_1c57b628 extract_optical_file 85ms 2026-09-19T20:20:05
tc_f5115e23 extract_optical_file 89ms 2026-09-19T20:20:05
tc_9ea8cf94 extract_optical_file 102ms 2026-09-19T20:20:05
tc_7fae75a5 extract_optical_file 87ms 2026-09-19T20:20:05
tc_1459941e extract_optical_file 85ms 2026-09-19T20:20:05
tc_55606732 extract_optical_file 158ms 2026-09-19T20:20:05
tc_2181caa1 extract_optical_file 156ms 2026-09-19T20:20:05
tc_c3b76c3a extract_optical_file 70ms 2026-09-19T20:20:05
tc_a385242d extract_optical_file 78ms 2026-09-19T20:20:05
tc_21f4ff65 extract_optical_file 80ms 2026-09-19T20:20:05
tc_908ce257 extract_optical_file 80ms 2026-09-19T20:20:05
tc_91082f8e extract_optical_file 81ms 2026-09-19T20:20:05
tc_b7164f8d extract_optical_file 80ms 2026-09-19T20:20:05
tc_e37d4f25 extract_optical_file 57ms 2026-09-19T20:20:05
tc_8710ecf6 get_raw_output 10ms 2026-09-19T20:20:07
tc_c2a019c6 extract_optical_file 51ms 2026-09-19T20:20:10
tc_21d83aa5 track_progress 13ms 2026-09-19T20:20:25
tc_958cc36c analyze_pdf 0ms 2026-09-19T20:20:29
tc_97f9ce4c analyze_office_document 0ms 2026-09-19T20:20:29
tc_2618b300 detect_steganography 183ms 2026-09-19T20:20:29
tc_65a9384f get_investigation_summary 5ms 2026-09-19T20:20:33
tc_79ddc3da submit_finding 10ms 2026-09-19T20:20:44
tc_10aa412f open_case 31ms 2026-09-19T20:20:55
tc_a0aae92d get_investigation_summary 5ms 2026-09-19T20:20:58
tc_7cb38d6d list_sources 2ms 2026-09-19T20:20:58
tc_331abe1f submit_finding 16ms 2026-09-19T20:21:01
tc_30b0ed61 search 5ms 2026-09-19T20:21:05
tc_c3661661 search 3ms 2026-09-19T20:21:05
tc_68795a10 get_findings 2ms 2026-09-19T20:21:06
tc_b8a8b6ad get_raw_output 101ms 2026-09-19T20:21:07
tc_22848d76 get_raw_output 100ms 2026-09-19T20:21:07
tc_1829697a get_raw_output 12ms 2026-09-19T20:21:09
tc_756b7de1 get_findings 1ms 2026-09-19T20:21:22
tc_ac184a8c get_raw_output 100ms 2026-09-19T20:21:23
tc_c0ed9ce1 get_raw_output 101ms 2026-09-19T20:21:24
tc_595504ec search 5ms 2026-09-19T20:21:24
tc_1aa8685b get_raw_output 29ms 2026-09-19T20:21:32
tc_a46c0d82 search 3ms 2026-09-19T20:21:32
tc_b1d2c51e get_raw_output 24ms 2026-09-19T20:21:33
tc_8b3c8603 submit_finding 17ms 2026-09-19T20:21:35
tc_629dba26 get_raw_output 30ms 2026-09-19T20:21:42
tc_5dcbe8c5 search 18ms 2026-09-19T20:21:43
tc_b17a62bf search 3ms 2026-09-19T20:21:44
tc_0d96ed96 submit_finding 14ms 2026-09-19T20:21:51
tc_37144a43 update_finding 13ms 2026-09-19T20:21:57
tc_a2c1ba73 search 6ms 2026-09-19T20:21:59
tc_22be6ae1 get_raw_output 21ms 2026-09-19T20:22:00
tc_902b2ab6 search 3ms 2026-09-19T20:22:01
tc_5de8b591 submit_finding 16ms 2026-09-19T20:22:25
tc_32f79702 detect_steganography 0ms 2026-09-19T20:22:30
tc_a4d9c259 search 7ms 2026-09-19T20:22:31
tc_abde6e1f search 3ms 2026-09-19T20:22:31
tc_c54bacf1 search 3ms 2026-09-19T20:22:31
tc_592fd970 search 4ms 2026-09-19T20:22:41
tc_e1bf8ffe search 4ms 2026-09-19T20:22:42
tc_1a86b3fa search 7ms 2026-09-19T20:22:52
tc_22dfb308 search 3ms 2026-09-19T20:23:04
tc_ffffae1f bookmark_window 11ms 2026-09-19T20:23:04
tc_25ee53d8 search 3ms 2026-09-19T20:23:04
tc_cd65d07a bookmark_window 11ms 2026-09-19T20:23:06
tc_2fc026db get_raw_output 10ms 2026-09-19T20:23:10
tc_a391d3b7 submit_finding 16ms 2026-09-19T20:23:37
tc_875be0b4 get_raw_output 101ms 2026-09-19T20:23:39
tc_a595ac42 search 3ms 2026-09-19T20:23:40
tc_7b74272d get_raw_output 10ms 2026-09-19T20:23:42
tc_5710e16c get_raw_output 21ms 2026-09-19T20:24:05
tc_d2824989 search 3ms 2026-09-19T20:24:06
tc_2ad86f46 get_raw_output 98ms 2026-09-19T20:24:09
tc_65681ab9 update_finding 14ms 2026-09-19T20:24:36
tc_750e3f49 get_findings 2ms 2026-09-19T20:24:36
tc_b176cecf get_findings 2ms 2026-09-19T20:24:40
tc_92ee1248 submit_finding 15ms 2026-09-19T20:25:00
tc_a79ee921 search 3ms 2026-09-19T20:25:11
tc_1e645d03 submit_finding 16ms 2026-09-19T20:25:26
tc_bd1cba01 search 3ms 2026-09-19T20:25:29
tc_8db29125 list_sources 2ms 2026-09-19T20:25:29
tc_68f03228 submit_finding 15ms 2026-09-19T20:25:54
tc_26018347 get_raw_output 10ms 2026-09-19T20:26:07
tc_4812264a submit_finding 15ms 2026-09-19T20:26:17
tc_66130bd6 submit_finding 14ms 2026-09-19T20:26:29
tc_fa7c3c68 update_finding 13ms 2026-09-19T20:26:38
tc_6e013b44 submit_finding 15ms 2026-09-19T20:26:54
tc_40f7218a submit_finding 16ms 2026-09-19T20:26:58
tc_c9968a40 get_investigation_summary 4ms 2026-09-19T20:27:01
tc_e48e1d3a track_progress 13ms 2026-09-19T20:27:11
tc_f743a00f get_investigation_summary 5ms 2026-09-19T20:27:46
tc_da55dc6e track_progress 12ms 2026-09-19T20:27:55
tc_a5caa83d get_investigation_summary 5ms 2026-09-19T20:28:15
tc_8c88c671 open_case 31ms 2026-09-19T20:28:20
tc_75bd86cb get_findings 3ms 2026-09-19T20:28:23
tc_aec1ef00 get_investigation_summary 5ms 2026-09-19T20:28:23
tc_704cb1a3 list_sources 2ms 2026-09-19T20:28:23
tc_968362d1 get_source_stats 101ms 2026-09-19T20:28:24
tc_5d7aa48c get_bookmarks 3ms 2026-09-19T20:28:24
tc_075294ed get_findings 2ms 2026-09-19T20:28:28
tc_2f4d9fdb get_timeline 22ms 2026-09-19T20:28:29
tc_6fa0c48a open_case 32ms 2026-09-19T20:29:48
tc_2d28557e analyze_execution_timeline._query(ez.shimcache) 20ms 2026-09-19T20:30:36
tc_9f77d879 find_execution_evidence._query(ez.shimcache) 18ms 2026-09-19T20:30:36
tc_406d53e8 analyze_execution_timeline 65ms 2026-09-19T20:30:36
tc_b4cececb reconstruct_execution_chains._query(volatility.pstree) 71ms 2026-09-19T20:30:36
tc_00f4f3f8 find_execution_evidence 79ms 2026-09-19T20:30:36
tc_879145c1 reconstruct_execution_chains._query(volatility.cmdline) 13ms 2026-09-19T20:30:36
tc_6077e147 find_defense_evasion._search(all) 109ms 2026-09-19T20:30:36
tc_5a97e16b reconstruct_execution_chains._query(volatility.netscan) 15ms 2026-09-19T20:30:36
tc_ebbb7847 find_defense_evasion._search(ez.mft) 18ms 2026-09-19T20:30:36
tc_4e62c35f reconstruct_execution_chains._query(volatility.malfind) 48ms 2026-09-19T20:30:36
tc_d364fc83 reconstruct_execution_chains 172ms 2026-09-19T20:30:36
tc_f97d3e7f find_defense_evasion._search(all) 43ms 2026-09-19T20:30:36
tc_52ae5070 correlate_pcap_with_host 0ms 2026-09-19T20:30:36
tc_e2112d6f find_file_staging._search(tsk.filelist) 15ms 2026-09-19T20:30:36
tc_fc275573 find_defense_evasion._search(all) 18ms 2026-09-19T20:30:36
tc_50b41624 find_file_staging._search(ez.mft) 22ms 2026-09-19T20:30:36
tc_55b5d0df find_defense_evasion._search(all) 17ms 2026-09-19T20:30:36
tc_4b151b53 find_defense_evasion 235ms 2026-09-19T20:30:36
tc_34c2e01a correlate_across_sources 365ms 2026-09-19T20:30:37
tc_2fc28d99 correlate_across_sources 507ms 2026-09-19T20:30:37
tc_e77292b7 correlate_across_sources 591ms 2026-09-19T20:30:37
tc_009d6086 correlate_across_sources 627ms 2026-09-19T20:30:37
tc_535a136d correlate_across_sources 608ms 2026-09-19T20:30:37
tc_a9017d4b find_file_staging._query(tsk.filelist) 591ms 2026-09-19T20:30:37
tc_1627cc1d correlate_across_sources 716ms 2026-09-19T20:30:37
tc_02eb8a48 find_file_staging._query(ez.mft) 277ms 2026-09-19T20:30:37
tc_d8585d8e find_file_staging._search(ez.mft) 148ms 2026-09-19T20:30:38
tc_1884b486 find_data_exfiltration_indicators._query(bulk.url) 1608ms 2026-09-19T20:30:38
tc_a03b2c7a find_file_staging._search(ez.mft) 74ms 2026-09-19T20:30:38
tc_77aea2df find_file_staging 1625ms 2026-09-19T20:30:38
tc_0d1f87a5 find_data_exfiltration_indicators._query(bulk.email) 13ms 2026-09-19T20:30:39
tc_f6463f9c find_data_exfiltration_indicators._query(bulk.domain) 159ms 2026-09-19T20:30:39
tc_255d9424 find_data_exfiltration_indicators._search(all) 64ms 2026-09-19T20:30:39
tc_9bf32f83 find_data_exfiltration_indicators 2931ms 2026-09-19T20:30:39
tc_69ade31b open_case 33ms 2026-09-19T20:31:20
tc_8907bac0 get_investigation_summary 6ms 2026-09-19T20:31:22
tc_97ce2e6f list_sources 2ms 2026-09-19T20:31:23
tc_cdee811f get_findings 2ms 2026-09-19T20:31:23
tc_3f1b5f08 get_findings 2ms 2026-09-19T20:31:27
tc_3845b160 get_raw_output 101ms 2026-09-19T20:31:28
tc_01eb9753 get_raw_output 100ms 2026-09-19T20:31:28
tc_75898c6a get_raw_output 100ms 2026-09-19T20:31:34
tc_680ef6a6 get_raw_output 99ms 2026-09-19T20:31:34
tc_f5536811 get_raw_output 100ms 2026-09-19T20:31:35
tc_70ba2377 search 5ms 2026-09-19T20:31:43
tc_d32d9910 search 6ms 2026-09-19T20:31:45
tc_5fffd349 search 4ms 2026-09-19T20:31:46
tc_a8fe2dc1 search 6ms 2026-09-19T20:31:53
tc_edead4e7 search 4ms 2026-09-19T20:31:54
tc_d0a4d731 search 8ms 2026-09-19T20:31:55
tc_754cd2ae get_raw_output 102ms 2026-09-19T20:32:05
tc_83273c80 get_raw_output 100ms 2026-09-19T20:32:06
tc_373acc1e get_raw_output 101ms 2026-09-19T20:32:06
tc_6da0ef72 lookup_attack_technique 569ms 2026-09-19T20:33:00
tc_8011990e lookup_attack_technique 0ms 2026-09-19T20:33:00
tc_7adf830a lookup_attack_technique 1ms 2026-09-19T20:33:01
tc_87c84a9f submit_finding 16ms 2026-09-19T20:33:34
tc_0c60952b submit_finding 16ms 2026-09-19T20:34:03
tc_c1012d66 submit_finding 15ms 2026-09-19T20:34:26
tc_4f01bd00 search 4ms 2026-09-19T20:34:30
tc_ebedaa32 search 5ms 2026-09-19T20:34:31
tc_b61cdd39 search 4ms 2026-09-19T20:34:39
tc_ab549bb9 search 5ms 2026-09-19T20:34:40
tc_3aabfd50 delete_finding 12ms 2026-09-19T20:35:07
tc_c9c629ed delete_finding 11ms 2026-09-19T20:35:08
tc_1f84cccd delete_finding 11ms 2026-09-19T20:35:08
tc_749f7c2f delete_finding 11ms 2026-09-19T20:35:08
tc_5950b0c1 delete_finding 11ms 2026-09-19T20:35:09
tc_d515b990 delete_finding 11ms 2026-09-19T20:35:13
tc_207865ef delete_finding 11ms 2026-09-19T20:35:13
tc_83236b1a delete_finding 11ms 2026-09-19T20:35:14
tc_38928c06 update_finding 14ms 2026-09-19T20:35:35
tc_8edba7e2 update_finding 12ms 2026-09-19T20:35:48
tc_5066be6e update_finding 11ms 2026-09-19T20:36:02
tc_c06b78be delete_finding 11ms 2026-09-19T20:36:02
tc_1b577aca get_ioc_summary 651ms 2026-09-19T20:36:06
tc_4a839002 get_findings 2ms 2026-09-19T20:36:06
tc_3febca2c get_raw_output 100ms 2026-09-19T20:37:39
tc_da2f276a search 6ms 2026-09-19T20:37:39
tc_82e86e9a search 4ms 2026-09-19T20:37:40
tc_d1ca0391 search 4ms 2026-09-19T20:37:46
tc_9f3e3cea search 3ms 2026-09-19T20:37:46
tc_3fdcefd9 search 4ms 2026-09-19T20:37:47
tc_d0efb232 search 3ms 2026-09-19T20:38:02
tc_2ea567cd search 5ms 2026-09-19T20:38:02
tc_d666451d search 4ms 2026-09-19T20:38:03
tc_4fcd5f08 search 3ms 2026-09-19T20:38:13
tc_e6929599 search 3ms 2026-09-19T20:38:13
tc_9e03e67e search 3ms 2026-09-19T20:38:14
tc_c43a20d8 get_raw_output 10ms 2026-09-19T20:38:19
tc_50fcca9c search 3ms 2026-09-19T20:38:20
tc_2308f2c6 search 4ms 2026-09-19T20:38:20
tc_a684547d get_findings 2ms 2026-09-19T20:38:39
tc_701b3a64 search 4ms 2026-09-19T20:38:45
tc_686ae07c search 3ms 2026-09-19T20:38:46
tc_80ed30b7 search 3ms 2026-09-19T20:38:46
tc_507a3065 get_raw_output 10ms 2026-09-19T20:38:53
tc_2d80233a search 3ms 2026-09-19T20:38:54
tc_f8dce5f0 submit_finding 14ms 2026-09-19T20:39:24
tc_c8cc648e submit_finding 16ms 2026-09-19T20:39:34
tc_62cc037f search 6ms 2026-09-19T20:39:42
tc_9c5c04d2 search 6ms 2026-09-19T20:39:43
tc_aec4e36b update_finding 13ms 2026-09-19T20:39:55
tc_8c7fcb45 search 4ms 2026-09-19T20:39:59
tc_b0bc169e search 3ms 2026-09-19T20:40:00
tc_4aa7b784 get_raw_output 98ms 2026-09-19T20:40:13
tc_70477b9f search 5ms 2026-09-19T20:40:14
tc_92f2379a search 3ms 2026-09-19T20:40:25
tc_7eb5ce57 search 3ms 2026-09-19T20:40:25
tc_56d24f56 get_investigation_summary 4ms 2026-09-19T20:40:29
tc_56cbbe81 get_findings 2ms 2026-09-19T20:40:33
tc_c3dab416 get_findings 2ms 2026-09-19T20:40:39
tc_ffef54ed get_findings 2ms 2026-09-19T20:40:43
tc_9142e342 delete_finding 12ms 2026-09-19T20:41:30
tc_09e2cc59 delete_finding 11ms 2026-09-19T20:41:31
tc_68209b88 delete_finding 12ms 2026-09-19T20:41:31
tc_5e58a044 delete_finding 13ms 2026-09-19T20:41:31
tc_8ca82c48 delete_finding 11ms 2026-09-19T20:41:32
tc_6ccab090 update_finding 13ms 2026-09-19T20:41:51
tc_d84bca85 delete_finding 11ms 2026-09-19T20:41:52
tc_3b09938c update_finding 13ms 2026-09-19T20:42:04
tc_4018aa9f delete_finding 11ms 2026-09-19T20:42:09
tc_de6ce5c2 update_finding 12ms 2026-09-19T20:42:25
tc_e82e5057 delete_finding 11ms 2026-09-19T20:42:29
tc_4b0b10cc update_finding 13ms 2026-09-19T20:42:56
tc_7d80626d enrich_iocs 125ms 2026-09-19T20:43:03
tc_1f78296d get_investigation_summary 3ms 2026-09-19T20:43:03
tc_78961313 update_finding 14ms 2026-09-19T20:43:39
tc_19b414af update_finding 13ms 2026-09-19T20:43:40
tc_66b26088 search 6ms 2026-09-19T20:43:46
tc_a6b97a0a search 3ms 2026-09-19T20:43:47
tc_bd7b40f0 get_source_stats 99ms 2026-09-19T20:43:59
tc_ed2b54a6 track_progress 14ms 2026-09-19T20:44:34
tc_65611963 get_investigation_summary 5ms 2026-09-19T20:45:01
tc_de330688 open_case 34ms 2026-09-19T20:45:06
tc_e9e907bf get_findings 3ms 2026-09-19T20:45:08
tc_05e1e2ad get_investigation_summary 5ms 2026-09-19T20:45:09
tc_18063f89 list_sources 2ms 2026-09-19T20:45:09
tc_53d81a7a get_findings 2ms 2026-09-19T20:45:15
tc_84ae2d95 get_timeline 25ms 2026-09-19T20:45:15
tc_5a5c22b5 open_case 33ms 2026-09-19T20:47:13
tc_28861984 search 32ms 2026-09-19T20:49:02
tc_1d326101 search 40ms 2026-09-19T20:49:02
tc_08703afa search 56ms 2026-09-19T20:49:02
tc_b8acc297 search 64ms 2026-09-19T20:49:02
tc_8f4da285 search 28ms 2026-09-19T20:49:02
tc_3b2dfb67 find_file_staging._search(tsk.filelist) 62ms 2026-09-19T20:49:02
tc_8d2d0653 search 80ms 2026-09-19T20:49:02
tc_038e742c search 73ms 2026-09-19T20:49:02
tc_f92db7aa search 143ms 2026-09-19T20:49:02
tc_b827042b deduplicate_findings 67ms 2026-09-19T20:49:02
tc_2d314b8c search 89ms 2026-09-19T20:49:02
tc_7654ea49 find_file_staging._search(ez.mft) 76ms 2026-09-19T20:49:02
tc_1e2a7b1c get_source_stats 183ms 2026-09-19T20:49:02
tc_b13d89e7 find_file_staging._query(tsk.filelist) 115ms 2026-09-19T20:49:02
tc_db1a0c95 detect_timestomping 886ms 2026-09-19T20:49:03
tc_84d41df4 find_file_staging._query(ez.mft) 638ms 2026-09-19T20:49:03
tc_31441b9d find_file_staging._search(ez.mft) 19ms 2026-09-19T20:49:03
tc_704e7b93 find_file_staging._search(ez.mft) 9ms 2026-09-19T20:49:03
tc_ae60a2ea find_file_staging 1328ms 2026-09-19T20:49:03
tc_3ab430ac correlate_across_sources 1701ms 2026-09-19T20:49:04
tc_7990bd79 search 4ms 2026-09-19T20:49:07
tc_0a323957 search 7ms 2026-09-19T20:49:30
tc_4f0d39e2 search 8ms 2026-09-19T20:49:30
tc_18a3277a search 9ms 2026-09-19T20:49:30
tc_0a1be91f search 14ms 2026-09-19T20:49:39
tc_b65f91f2 search 23ms 2026-09-19T20:49:39
tc_1107133a search 37ms 2026-09-19T20:49:39
tc_2f22a660 detect_timestomping 329ms 2026-09-19T20:49:40
tc_13124891 search 10ms 2026-09-19T20:49:50
tc_22c7222a search 11ms 2026-09-19T20:49:50
tc_5560642a find_file_staging._search(tsk.filelist) 14ms 2026-09-19T20:49:50
tc_0b6a3f18 find_file_staging._search(ez.mft) 8ms 2026-09-19T20:49:50
tc_71bca53b find_file_staging._query(tsk.filelist) 100ms 2026-09-19T20:49:51
tc_422bd909 find_file_staging._query(ez.mft) 159ms 2026-09-19T20:49:51
tc_981f2e5c find_file_staging._search(ez.mft) 17ms 2026-09-19T20:49:51
tc_9dd823f6 find_file_staging._search(ez.mft) 9ms 2026-09-19T20:49:51
tc_27051ed3 find_file_staging 680ms 2026-09-19T20:49:51
tc_beb77c8a search 32ms 2026-09-19T20:50:11
tc_f5c238f6 deduplicate_findings 52ms 2026-09-19T20:50:12
tc_fbf1b96a search 58ms 2026-09-19T20:50:12
tc_fcf81019 get_source_stats 145ms 2026-09-19T20:50:12
tc_305597cd correlate_across_sources 562ms 2026-09-19T20:50:12
tc_4b5ba790 open_case 34ms 2026-09-19T20:51:02
tc_eb428c82 get_findings 2ms 2026-09-19T20:51:04
tc_f8babbdc get_investigation_summary 5ms 2026-09-19T20:51:04
tc_b4bbfc98 get_findings 2ms 2026-09-19T20:51:07
tc_4e6fe5d8 search 5ms 2026-09-19T20:51:25
tc_f9fb3d7d search 6ms 2026-09-19T20:51:25
tc_0a2e3340 search 4ms 2026-09-19T20:51:26
tc_c79bcb22 search 3ms 2026-09-19T20:51:35
tc_329e1440 search 4ms 2026-09-19T20:51:35
tc_2eea072e search 3ms 2026-09-19T20:51:36
tc_09e43290 get_raw_output 100ms 2026-09-19T20:51:41
tc_bd98643c get_raw_output 99ms 2026-09-19T20:51:41
tc_a2ab8e3a get_raw_output 99ms 2026-09-19T20:51:42
tc_424b098d get_raw_output 101ms 2026-09-19T20:52:35
tc_115ea3c7 search 3ms 2026-09-19T20:52:36
tc_8a5f47d9 search 4ms 2026-09-19T20:52:36
tc_cd9f6ca3 get_raw_output 99ms 2026-09-19T20:52:40
tc_7daf55d8 search 4ms 2026-09-19T20:52:41
tc_a7236b0e update_finding 13ms 2026-09-19T20:53:51
tc_3f883d33 update_finding 14ms 2026-09-19T20:54:36
tc_867f8dfa search 4ms 2026-09-19T20:55:05
tc_2b8aea7b search 4ms 2026-09-19T20:55:06
tc_ec9563b8 search 6ms 2026-09-19T20:55:06
tc_64f90f66 get_raw_output 100ms 2026-09-19T20:55:10
tc_238c6428 audit_evidence_coverage 451ms 2026-09-19T20:55:31
tc_0eebeded audit_tool_coverage 2ms 2026-09-19T20:55:31
tc_37be9118 deduplicate_findings 40ms 2026-09-19T20:55:50
tc_bc66d0c3 check_finalize_readiness 4ms 2026-09-19T20:56:00
tc_51f7b400 search 4ms 2026-09-19T20:56:08
tc_765e2236 search 5ms 2026-09-19T20:56:08
tc_836b73b3 update_finding 14ms 2026-09-19T20:56:34
tc_3e3798f5 track_progress 13ms 2026-09-19T20:57:17
tc_de971dd5 get_investigation_summary 5ms 2026-09-19T20:57:39
tc_49a69095 check_finalize_readiness 4ms 2026-09-19T20:57:39
tc_957823dc open_case 10ms 2026-09-19T20:57:49
tc_ed8c5847 get_findings 2ms 2026-09-19T20:57:52
tc_6ed8a5dc get_investigation_summary 5ms 2026-09-19T20:57:53
tc_d014f67e get_ioc_summary 658ms 2026-09-19T20:57:53
tc_6c09f85c get_bookmarks 3ms 2026-09-19T20:57:53
tc_cf9112b9 get_source_stats 101ms 2026-09-19T20:57:54
tc_90fa5309 get_findings 2ms 2026-09-19T20:58:00
tc_1f336160 get_findings 1ms 2026-09-19T20:58:00
tc_941e3704 get_findings 1ms 2026-09-19T20:58:01
tc_2db554c2 check_finalize_readiness 4ms 2026-09-19T20:58:23
tc_33b6f975 audit_evidence_coverage 458ms 2026-09-19T20:58:24
tc_c3ae406b audit_tool_coverage 2ms 2026-09-19T20:58:24
tc_d0ab6f70 submit_narrative 13ms 2026-09-19T21:01:22
tc_15e65281 check_finalize_readiness 4ms 2026-09-19T21:01:30

Each finding traces back to the specific tool calls that produced the supporting evidence.

Data Exfiltration via Removable Media - Secret Project Data Staged on USB (RM1) and USB (RM2) 5 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.masquerade" }
tc_ec173722
99ms
2
get_raw_output
{ "after_id": 89133, "limit": 10, "source_name": "tsk.timeline" }
tc_7e1c1241
11ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.filelist" }
tc_27bf2a30
22ms
4
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.usrclass.informant" }
tc_7f5abba9
99ms
5
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.fsstat" }
tc_8478da81
101ms
Insider Threat - User Identity and Resignation Letter Confirm Departing Employee Data Theft 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.ntuser.informant" }
tc_2beaa53c
100ms
2
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "bulk.email" }
tc_6ad4d887
30ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.usrclass.informant" }
tc_7f5abba9
99ms
Cross-System: Identical Exfiltrated Documents Confirmed Across All Three Removable Media (RM1, RM2, RM3) 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_754cd2ae
102ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "chainsaw.hunt" }
tc_83273c80
100ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "composite.defense_evasion" }
tc_680ef6a6
99ms
Environment-Wide File Extension Masquerading Across All 3 Removable Media — 17 Disguised Office Documents 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.masquerade" }
tc_62987b1e
104ms
2
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.filelist" }
tc_d67ae8aa
21ms
3
get_raw_output
{ "after_id": 89133, "limit": 10, "source_name": "tsk.timeline" }
tc_b61a548a
11ms
Environment-Wide Deletion of Exfiltrated Documents Across All 3 Removable Media 3 refs
1
get_raw_output
{ "after_id": 89133, "limit": 10, "source_name": "tsk.timeline" }
tc_b61a548a
11ms
2
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.filelist" }
tc_d67ae8aa
21ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.masquerade" }
tc_62987b1e
104ms
USB Device Tied to Source PC via Shellbag and Registry Evidence 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.usrclass.informant" }
tc_f26ac21a
113ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "USBSTOR", "regex": false, "source": "registr...
tc_b88e2a9b
3ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "Authorized USB", "regex": false, "source": n...
tc_f0925a2e
3ms
Network Share Access to Secured Corporate Data from Internal Network (10.11.11.128) 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.usrclass.informant" }
tc_7f5abba9
99ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "10.11.11", "regex": false, "source": null, "...
tc_9373d670
11ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.ntuser.informant" }
tc_2beaa53c
100ms
Anti-Forensic Tool Suite: Eraser and CCleaner Downloaded, Installed, and Executed After Exfiltration 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.ntuser.informant" }
tc_2beaa53c
100ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "Eraser", "regex": false, "source": "ez.mft", ...
tc_2fa622d5
6ms
3
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "CCleaner", "regex": false, "source": "ez.mft"...
tc_92db7fe9
4ms
Complete Cross-System Exfiltration and Anti-Forensic Timeline Reconstruction 4 refs
1
get_raw_output
{ "after_id": 89133, "limit": 10, "source_name": "tsk.timeline" }
tc_7e1c1241
11ms
2
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.usrclass.informant" }
tc_7f5abba9
99ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.ntuser.informant" }
tc_2beaa53c
100ms
4
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "USB", "regex": false, "source": "registry.sy...
tc_44f9e584
5ms
CD-R (RM3) Data Exfiltration: 9 Burn Sessions with Masqueraded Documents 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_bfaf8fda
97ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.usrclass.informant" }
tc_293e882d
99ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "registry.ntuser.informant" }
tc_2f1a7111
99ms
CD-R (RM3) Multi-Session Anti-Forensic Technique: Iterative Directory Renaming and Deletion on Write-Once Media 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_b8a8b6ad
101ms
2
get_raw_output
{ "after_id": 0, "limit": 20, "source_name": "tsk.masquerade" }
tc_875be0b4
101ms
Cross-System: Premeditated Anti-Forensic and Data Leakage Research Preceding Exfiltration Campaign 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_754cd2ae
102ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "stealing_data", "regex": false, "source": "b...
tc_edead4e7
4ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": [ "Eraser", "CCleaner", "eraser", "ccleaner" ], "query": "",...
tc_a8fe2dc1
6ms
Dual-Partition USB Device Structure Enables Plausible Deniability 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.fsstat" }
tc_f88b7a7a
102ms
2
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.filelist" }
tc_d67ae8aa
21ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "tsk.masquerade" }
tc_62987b1e
104ms
Cross-Media Document Metadata: Email Addresses and Authorship Attribution Across RM1, RM2, and RM3 3 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "email", "regex": false, "source": "bulk.emai...
tc_532a7d97
7ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "Eric_P._Lauer", "regex": false, "source": nu...
tc_46252f53
3ms
3
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "bulk.exif" }
tc_a4b039b1
24ms
Potential Cloud Exfiltration via Google Drive and iCloud — Sync Config Destroyed by Anti-Forensic Tools 3 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "registry.ntuser.informant" }
tc_2beaa53c
100ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "Google Drive", "regex": false, "source": "ts...
tc_54511de3
6ms
3
get_raw_output
{ "after_id": 11630, "limit": 2, "source_name": "tsk.filelist" }
tc_e8401491
10ms
Cross-System: Diversionary User Account Creation by Insider (admin11, ITechTeam, temporary) 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "chainsaw.hunt" }
tc_83273c80
100ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "bulk.url_searches" }
tc_754cd2ae
102ms
Potential Co-Conspirator Contact Entry — spy.conspirator@nist.gov in Outlook Data 2 refs
1
get_raw_output
{ "after_id": 22361, "limit": 1, "source_name": "bulk.email" }
tc_507a3065
10ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "spy.conspirator", "regex": false, "source": ...
tc_d0efb232
3ms
Negative Finding: No Encrypted Containers or Steganographic Content on Any Removable Media 3 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "truecrypt", "regex": false, "source": null, ...
tc_614ce225
3ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "veracrypt", "regex": false, "source": null, ...
tc_2491e9ca
3ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": [ "bitlocker", "encrypt", "steg", "hidden" ], "query": "", "...
tc_4febb050
5ms
System Configuration: User Accounts, Timezone, and PC Identity 3 refs
1
get_raw_output
{ "after_id": 73268, "limit": 2, "source_name": "registry.system" }
tc_1236077e
10ms
2
query_registry_value
{ "case_id": "ndlc", "hive": "system", "image_path": "/evidence/cfreds_2015_data_leakage_pc.E01", "key_path": "Contro...
tc_9e1064ac
4814ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "hayabusa.alerts" }
tc_49bb0cdc
100ms
Application Execution Timeline: Document Access and Exfiltration Workflow 3 refs
1
get_raw_output
{ "after_id": 88473, "limit": 2, "source_name": "registry.ntuser.informant" }
tc_8710ecf6
10ms
2
get_raw_output
{ "after_id": 88471, "limit": 3, "source_name": "registry.usrclass.informant" }
tc_1829697a
12ms
3
search
{ "exclude_sources": [ "tsk.filelist", "tsk.timeline", "bulk" ], "max_results": 10, "queries": null, "query": "Eraser...
tc_b6b7e690
5ms
RecentDocs, WordWheelQuery, and OpenSaveMRU: Evidence of Document Search and Access Pattern 2 refs
1
get_raw_output
{ "after_id": 88475, "limit": 1, "source_name": "registry.ntuser.informant" }
tc_2fc026db
10ms
2
get_raw_output
{ "after_id": 88473, "limit": 2, "source_name": "registry.ntuser.informant" }
tc_8710ecf6
10ms
CD-R (RM3) EXIF Metadata: Cover Images Are Stock Windows 7 Photos, Document-Embedded Images Show Kodak and Adobe Processing 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 10, "source_name": "bulk.exif" }
tc_b1d2c51e
24ms
2
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "optical.listing" }
tc_b8a8b6ad
101ms
No Valid PCAP Data Available — SMB File Transfer Analysis Not Possible 2 refs
1
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "pcap", "regex": false, "source": null, "t_en...
tc_9f3e3cea
3ms
2
get_raw_output
{ "after_id": 73803, "limit": 2, "source_name": "registry.system" }
tc_c43a20d8
10ms

Tool Call Details

Copied to clipboard