Executive Summary

📂18 sources (120 memory, 94 disk, 243 other)
🔍1508 tool calls
⏱️5.6 hours elapsed
🚨55 findings (11 critical, 19 high)
43 confirmed
🤔12 inference
🔒 SHA-256 hashes

The attack timeline spans 2017-12-20 to 2018-09-07. The earliest activity was Attacker Staging Directories with Malicious Tooling on base-rd-02 (2017-12-20). The investigation subsequently uncovered Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September); base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor; Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP. The most recent activity was WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation (2018-09-07).

Key Threats
  • PowerView/PowerSploit Active Reconnaissance from Domain Controller
  • PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server
  • WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)
  • WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)
  • Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP

0
Total Findings
0
Critical
0
High
0
Medium
0
Confirmed
0
Inference
0
Sources
0
Tool Calls
Severity Breakdown
Critical (11) High (19) Medium (11) Low (2) Info (12)
☑ Forensic Soundness and Evidence Integrity
Analysis was executed via a read-only Model Context Protocol (MCP) server mapped to the SANS SIFT toolchain. The MCP architecture enforces structural evidence protection: original evidence files were mounted as read-only volumes, all tool interactions are typed functions (no shell access), and every finding is validated against the append-only audit log before acceptance. 29 evidence files were cryptographically validated via SHA-256 hashes computed at ingestion. 1508 tool calls executed across 18 indexed sources with full provenance tracking.
⚠ Critical Findings
  • PowerView/PowerSploit Active Reconnaissance from Domain Controller
    2018-08-31T22:16:12 — 2018-08-31T22:52:08
  • PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server
    2018-08-28T22:08:25 — 2018-09-06T22:11:15
  • WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)
    2018-08-30T16:43:36 — 2018-09-06T17:26:35
  • WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)
    2018-08-31T01:14:44 — 2018-09-06T19:37:40
  • Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP
    2018-08-15T16:32:11 — 2018-09-07T19:43:31
  • msadvapi2 Backdoor Malware Running as Services on Multiple Systems
    2018-06-04T20:19:12
  • base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor
    2018-06-04T20:19:38 — 2018-09-06T21:02:43
  • Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 with 20+ Rundll32 Injections and WMI Stager
    2018-08-27T21:25:58 — 2018-09-06T19:08:45
  • Environment-Wide WMI→PowerShell(64→32)→Rundll32 Attack Chain Across 8+ Systems
    2018-09-06T17:43:45 — 2018-09-07T19:43:31
  • Environment-Wide C2 Proxy Tunneling via 172.16.4.10:8080 Across 7+ Systems
    2018-08-28T20:40:22
  • Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September)
    2018-06-04T20:19:30 — 2018-09-07T19:43:31
⚔ MITRE ATT&CK Coverage
Reconnaissance
Resource Development
Initial Access (5)
Execution (5)
Persistence (6)
Privilege Escalation (8)
Defense Evasion (15)
Credential Access (3)
Discovery (7)
Lateral Movement (6)
Collection (4)
Command and Control (4)
Exfiltration
Impact
Inhibit Response Function
Evasion
Impair Process Control
Initial Access (5)Execution (5)Persistence (6)Privilege Escalation (8)Defense Evasion (15)Credential Access (3)Discovery (7)Lateral Movement (6)Collection (4)Command and Control (4)
46 techniques across 55 findings
★ IOC Summary
External IPs20
Internal IPs24
File Paths6
Hashes0
Emails3
Investigation Metadata
Case IDSRL-2018
Evidence Root/evidence
Report Generated2026-06-06T11:57:33
Investigation Start2026-06-06T06:19:22
Investigation End2026-06-06T11:56:53
Total Processing47849.4s
Audit Log/home/mulder/.mulder/cases/SRL-2018.audit.jsonl
29 FILES Hashes computed during evidence ingestion. Compare against your local copies to confirm integrity.
FileSHA-256Size
base-admin-memory.7z 65cd9e49db5d181dec1a34f4b4c67a04903007251700acb99b630485951a4950 1.0 GB
base-av-memory.7z d61379467c4f9f27b1267b0e9a164fb01f7e47b5837074de98a8d7cca19d5f8f 2.1 GB
base-dc-memory.7z 70c3094eb6f814faf2e24c15c83e6a6da1b6d27e001097a2a839022bbea634ba 808.2 MB
base-elf-memory.7z c9241f92e0e9ac6c4b4885bd2a7a6ea63c70e1d7f0f465876f213e357a9bc6ff 672.8 MB
base-file-memory.7z 6a1df2332cb8157e3634f5fbee900afeefb5ad44044877e93ca0745e7e7920cf 303.5 MB
base-file-snapshot5.7z 905e88124c12336451cfe1ef00dc3abf6c7418e0552e329e3c840679d156a3a5 774.9 MB
base-hunt-memory.7z 143640711ab5a0378dce3a7ac7c5e083166ab8155123fd14609772e76cdcd7e1 1.1 GB
base-mail-memory.7z bde969728cddff1bc688c8eb55c44672f3d91714eea44d7ace715de842303f52 2.7 GB
base-rd-02-memory.7z ec66f5076e6b699f251ab72a6102c5af4714dddf5dda7c83967050e6cbec5196 931.9 MB
base-rd-03-memory.7z 6c1852e87b20cc02b28be2f2f373f8bdea07935072e56520a2a065100993653c 932.8 MB
base-rd-04-memory.7z cf03f019a566dcf7b40ced329a3cf9d5090e8c15203f6a4b97b9a512ced110d7 997.4 MB
base-rd-05-memory.7z 31652764f1a1ad1cf66a9cc65569fa44e89a818e14075079a26e8e18dd4e5b5d 513.6 MB
base-rd-06-memory.7z ddc0d1e72fdfb54889c6a3800b10eaa9f1ffe86991def2c7b55b09215d88c465 578.6 MB
base-rd01-memory.7z 59b8cd3022625ea310223a0ba33695668c9ce532a41cb53cb855e06634d8efd5 837.6 MB
base-sp-memory.7z 7b1539b42f6faf31d83bdd7216cbb831de3bf09c80e1f608e805bcc5ec3e030c 953.8 MB
base-wkstn-01-mem.zip ef061848edb0d0014155f8ee43cbc67f759520fa96de249ffbd45045b602e29a 1.2 GB
base-wkstn-01-memory.7z 9c86f5290a25ffce013518a8c98daf90bf4be0ed37450b1239edf9239fe5cc07 984.4 MB
base-wkstn-02-memory.7z c1f17907abd262e8f502078fde7058fe06ecc9b2f8cc047333906a01d407df78 969.2 MB
base-wkstn-03-memory.7z 33f09a2c10aeceda5c079c55a20e4b2f4b834f4e94c7b770e262d0fc01b88992 890.0 MB
base-wkstn-04-memory.7z 34f6cd35eea22e99b4affcd6e9af148ebaa8d8898397201d57f8d75044997697 895.5 MB
base-wkstn-05-memory.7z 9e5184194499c01eddee7538ad23f5a7c74533c427ea387f70a249394cb3a4c2 625.5 MB
base-wkstn-06-memory.7z ee7edd62c9960d855a8623d5d11506d1b74d40cec7f67e8ab108f81d92a1c5e5 549.2 MB
base-dc-cdrive.E01 e2b9cf0cb6759fd079f45fa903d80bde602160ff969c969c6f0cd704965b31b1 11.5 GB
base-file-cdrive.E01 ad9c85399fa8b2483f1d8a3684bc7e074b57d4c3ec88726cde271549bd742a18 15.3 GB
base-rd-01-cdrive.E01 12a622aa073dbbda3a4983014328a6085c8247ce93fe47fd6ba7483ed9d19aab 16.6 GB
base-rd-02-cdrive.E01 50ad43ff0e8a0cc478e0e68f418b9f752fb440fd5020ca4fe55680292ac834bc 16.0 GB
base-wkstn-01-c-drive.E01 ede47a0733203134f92c8ae46df4f5106b78a2c357fdb1d3c84301261076429f 15.8 GB
base-wkstn-05-cdrive.E01 a94f2a866e2e562c58c3fbcd3a94882f2d3c3db3c66a5e5eedf16a4b1c0a65e0 13.8 GB
dmz-ftp-cdrive.E01 d19754685d75aecb1fe18c3d75516dc0a965754335d981f3925e0e1b767ca8f8 11.9 GB

Background

This report documents the forensic investigation of a multi-system intrusion at Stark Research Labs (SRL), designated case SRL-2018. The investigation was initiated in response to suspected network compromise of the shieldbase.lan Active Directory domain. Digital forensic evidence was collected from multiple systems spanning the corporate server infrastructure, R&D workstations, and a DMZ-facing FTP server.

The evidence inventory comprised memory dumps from thirteen hosts across multiple network subnets, disk images from key systems including the file server (BASE-FILE), an R&D workstation (base-rd-02), a DMZ FTP server, and additional endpoints. The investigation indexed 18 distinct evidence sources using 1508 tool invocations across eleven extractor categories including Volatility 3 memory forensics, Sleuth Kit disk analysis, EZ Tools Windows artifact parsing, EVTX event log analysis, bulk_extractor IOC carving, YARA signature scanning, Chainsaw Sigma rule detection, and registry parsing. A total of 55 findings were submitted, of which 43 are corroborated by two or more independent sources and 12 represent single-source inferences requiring further validation. 46 distinct MITRE ATT&CK techniques were mapped across the investigation.

The Stark Research Labs environment operates a Windows Active Directory domain (shieldbase.lan) with infrastructure servers on the 172.16.4.x subnet (domain controller BASE-DC at 172.16.4.4, file server BASE-FILE at 172.16.4.5, Exchange server base-mail at 172.16.4.6, SharePoint server base-sp at 172.16.4.7), a management subnet at 172.16.5.x (forensic workstation base-hunt at 172.16.5.25, a key lateral movement convergence host at 172.16.5.21, and admin workstation at 172.16.5.26), R&D systems on the 172.16.6.x and 172.16.7.x subnets, and a DMZ FTP server at 172.16.10.12. A SoftEther VPN gateway at 172.16.1.20 provides external remote access. All internal systems route web traffic through an organizational HTTP proxy at 172.16.4.10:8080. McAfee endpoint protection suites were deployed across the environment but failed to detect the intrusion. Sysmon was running on at least one compromised host (base-wkstn-05) and similarly did not prevent compromise.

Incident Timeline

The investigation reconstructed an intrusion spanning from at least mid-2017 through early September 2018, characterized by two distinct but operationally linked campaigns. The timeline is organized into five phases reflecting the attack's progression from initial persistent access through active offensive operations.

Phase 1 — Persistent Backdoor Deployment (December 2017 – June 2018)

The earliest evidence of attacker activity is the creation of the msadvapi2 installer binary (install_msadvapi2_32.exe, 14,183,796 bytes) at C:\ProgramData\staging\install_wormhole\ on 2017-12-20 at 14:52:51 UTC. ShimCache records confirm this installer was executed on 2018-05-08 at 21:07:43, deploying the msadvapi2 backdoor suite. Both 32-bit and 64-bit variants were installed as Windows services under fabricated directory names ("C:\Program Files (x86)\Microsoft Advanced API 32\" and "Microsoft Advanced API 64\"), designed to mimic the legitimate Windows advapi32.dll library. A companion uninstaller (unins000.exe) was registered in the ShimCache at 2018-05-08 21:07:27, confirming a professionally packaged deployment. Memory forensics confirmed msadvapi2 processes running as children of services.exe across three systems: BASE-DC (172.16.4.4, PID 1072/1240), base-wkstn-03 (172.16.6.13, PIDs 2288/2304 since boot on 2018-08-17), and 172.16.6.15 (msadvapi2_64.exe). DLL analysis revealed the malware loads wpcap.dll (WinPcap packet capture library), IPHLPAPI.DLL, and network-related libraries, indicating network interception and packet capture capabilities. The backdoor persisted through reboots, confirmed by its presence in three independent memory captures spanning June through September 2018.

Phase 2 — Possible Early Detection and Triage (August 15, 2018)

On 2018-08-15 at approximately 16:32–16:36 UTC, the cbarton-a account conducted remote PowerShell reconnaissance against base-rd-02 (172.16.6.11) via WinRM. The commands executed — process enumeration via WMI, network adapter information gathering, and directory listing with the -Force flag — are consistent with incident response triage rather than attacker activity. On the same date, Autorunsc.exe (a Sysinternals persistence-auditing tool) was executed on 172.16.6.15, further supporting the interpretation that IT staff detected anomalous indicators and began preliminary investigation approximately two weeks before the main offensive operations escalated. Whether this early triage was triggered by the msadvapi2 backdoor's presence or other indicators remains undetermined.

Phase 3 — Active Offensive Operations (August 27 – September 1, 2018)

Beginning on 2018-08-27, the threat actor launched an aggressive lateral movement campaign using a uniform, automated attack chain deployed via Windows Management Instrumentation (WMI). The canonical attack sequence, observed identically across seven or more hosts, proceeds as follows: WmiPrvSE.exe (Session 0, non-interactive) spawns a 64-bit powershell.exe with no visible command-line arguments, which immediately spawns a 32-bit (SysWOW64) powershell.exe with stealth flags (-nop -w hidden -encodedcommand or -Version 5.1 -s -NoLogo -NoProfile), which then injects shellcode into one or more rundll32.exe child processes. The architecture downgrade from 64-bit to 32-bit PowerShell is a hallmark of Metasploit-framework shellcode compatibility requirements.

On 2018-08-27 at 21:25:58, base-wkstn-04 (172.16.6.14) received the earliest confirmed Metasploit implant via an interactive PowerShell session (PID 2664) launched from explorer.exe in the user's desktop session (Session 11). This was the only system showing an interactive-session compromise rather than WMI-based remote delivery, suggesting it may have been compromised through a user-initiated action such as a phishing payload. Over the following three days, PID 2664 spawned over twenty short-lived rundll32.exe injection targets (2–4 second lifetimes each) and established a localhost listener on port 18278, consistent with a SOCKS proxy or C2 relay. A persistent rundll32.exe implant (PID 8856, spawned 2018-08-27 23:39:56) remained running for over ten days until memory capture.

On 2018-08-28 at 22:08:25, WMI remote execution was used to deploy the PowerShell C2 chain on BASE-FILE (172.16.4.5). WmiPrvSE.exe (PID 1196) spawned powershell.exe (PID 4072, 64-bit), which in turn spawned powershell.exe (PID 3164, 32-bit), which then spawned over thirty rundll32.exe child processes between August 30 and September 6. Both PowerShell processes maintained ESTABLISHED connections to 172.16.4.10:8080, tunneling C2 traffic through the organizational web proxy. The powershell.exe processes operated under the compromised service account shieldbase\spsql.

On 2018-08-30 at 16:43:36, base-rd-02 (172.16.6.11) received the same WMI-based attack chain. PID 8712 (64-bit PowerShell) spawned PID 5848 (32-bit), which deployed multiple rundll32.exe injection targets and additionally dropped a second-stage implant, p.exe, at c:\windows\temp\perfmon\p.exe (executed via cmd.exe /C at 22:15:18). Malfind detected a large PAGE_EXECUTE_READWRITE allocation (CommitCharge=481) in p.exe (PID 8260), consistent with injected shellcode. The p.exe binary was subsequently deleted from the filesystem (absent from MFT) but continued running in memory, spawning its own rundll32.exe instances through September 6. An additional tool reference ("sd.") was identified in ShimCache entries for the same staging directory, confirming multiple attacker tools were present.

On 2018-08-31, the offensive tempo intensified. Three parallel WMI attack chains were established on base-wkstn-05 (172.16.7.15, user: mhill) within a 17-minute window beginning at 01:14:44, suggesting the attacker experienced connectivity issues or the first two stagers failed to initialize. The third chain (PID 1332) became the active C2 session, spawning five or more rundll32.exe injection targets. A persistent rundll32.exe implant (PID 7100, 5 threads, 337 handles) remained running at memory capture. On the same date at 01:00:30, an encoded Metasploit PowerShell stager was deployed on 172.16.6.15, and base-wkstn-01 (172.16.7.11) received a WMI-based stager with subsequent WinRM encoded command delivery on September 6.

On 2018-08-31 between 22:16 and 22:52 UTC, the attacker executed the full PowerView/PowerSploit reconnaissance toolkit from base-file.shieldbase.lan using the compromised spsql service account. PowerShell Operational event logs (Event ID 4104 ScriptBlock logging) captured the complete script content, which included Invoke-UserHunter, Invoke-ShareFinder, Invoke-CheckLocalAdminAccess, Get-NetDomain, Get-NetForest, Invoke-MapDomainTrust, Get-ForeignGroup, Get-DNSRecord, Invoke-EnumerateLocalAdmin, Find-LocalAdminAccess, Get-Keystrokes, and Invoke-ACLScanner. References to both Metasploit and PowerShell Empire GitHub repositories were embedded in the script code. The Find-UserField function was used to search Active Directory user description fields for plaintext passwords, a common technique for harvesting credentials stored by administrators in AD attributes.

On 2018-09-06, a second wave of WMI stagers was deployed on base-wkstn-04 (172.16.6.14, a fresh WMI chain alongside the pre-existing interactive implant) and base-wkstn-03 (172.16.6.13, Invoke-WmiMethod targeting "BASE-WKSTN-03" at 17:01:50). On base-wkstn-03, the WMI chain deployed an encoded Metasploit stager alongside the already-running msadvapi2 backdoor services, demonstrating the overlap between the two intrusion campaigns on the same host.

Phase 4 — Data Staging and Potential Exfiltration (September 5, 2018)

On 2018-09-05 at 14:43:11, Rar.exe (PID 2524) was executed on BASE-FILE from an interactive command prompt (cmd.exe PID 6352, spawned from explorer.exe PID 6452). The compression process ran for approximately ten minutes, exiting at 14:52:56, with 67 active threads observed during execution — indicating a significant volume of data being archived. This activity pattern is consistent with data staging for exfiltration. The file server contained substantial business data evidenced by SMB connections from multiple hosts across the environment. No direct evidence of exfiltration of the archived data was recovered, though this does not preclude exfiltration through the attacker's C2 channel.

Phase 5 — Incident Response and Evidence Collection (September 6–7, 2018)

Beginning approximately September 6, 2018, the incident response team deployed F-Response forensic remote acquisition agents (subject_srv.exe) across compromised systems. The F-Response management suite ran on the forensic workstation base-hunt (172.16.5.25), with license_ctrl.exe listening on port 5682 and subject agents connecting back from each target system on port 3262 to the evidence collection endpoint at 172.16.5.50. FTK Imager was launched on the forensic workstation at 2018-09-06 18:48:20 for imaging operations. Memory dumps were collected from thirteen systems, and disk images were acquired from key hosts. The attacker's C2 chains remained active in memory during evidence collection, providing rich forensic artifacts.

Key Findings

Dual Intrusion Campaigns with Operational Overlap

The investigation identified two distinct but operationally linked intrusion campaigns. The first campaign deployed the msadvapi2 persistent backdoor, installed as Windows services masquerading as "Microsoft Advanced API" with both 32-bit and 64-bit variants. The installer was staged as early as December 2017, with confirmed execution in May 2018 and persistence across reboots confirmed through September 2018. The msadvapi2 malware loaded packet capture libraries (wpcap.dll), indicating network interception capabilities. This backdoor was confirmed on at least three systems: the domain controller (BASE-DC), base-wkstn-03 (172.16.6.13), and 172.16.6.15.

The second campaign, active from late August through early September 2018, employed Metasploit-framework PowerShell stagers delivered via WMI remote execution. The uniform attack chain — WmiPrvSE → PowerShell (64-bit) → PowerShell (32-bit/SysWOW64) → rundll32.exe injection — was deployed identically across seven or more systems. The co-existence of both msadvapi2 and Metasploit implants on shared hosts (base-wkstn-03, 172.16.6.15) suggests either a single threat actor with evolving capabilities or a coordinated handoff between persistent access and active operations.

C2 Infrastructure and Proxy Tunneling

All confirmed C2 communications from compromised systems were tunneled through the organizational web proxy at 172.16.4.10:8080. This technique leverages legitimate infrastructure to blend malicious traffic with normal web browsing, making network-based detection significantly more difficult. The C2 distinction was established through process attribution: injected processes (SearchUI.exe PID 9316 on base-wkstn-04, PowerShell processes with confirmed malfind shellcode, persistent rundll32.exe implants) connecting to the proxy constitute confirmed C2, whereas browser processes (Chrome, Edge) connecting to the same proxy represent expected behavior. Five systems showed confirmed C2 via process attribution to attacker-controlled processes.

WinRM Lateral Movement Hub at 172.16.5.21

Network analysis identified 172.16.5.21 as the primary convergence point for WinRM-based lateral movement. Active ESTABLISHED WinRM sessions from base-wkstn-01 (172.16.7.11), the domain controller (172.16.4.4), and BASE-FILE (172.16.4.5) were captured at the time of memory acquisition, with additional CLOSED sessions from 172.16.7.16, 172.16.6.14, and 172.16.7.15. The attacker used WinRM from every compromised pivot point to access this system, which also hosted msadvapi2 backdoor services and maintained SMB connectivity to the file server.

Compromised Service Account and Active Directory Reconnaissance

The domain service account spsql (SID S-1-5-21-3445421715-2530590580-3149308974-1193) was weaponized for domain-wide reconnaissance. MFT entries show the spsql user profile being created on 2018-08-31 at 21:54:13, contemporaneous with the PowerView execution window. The attacker leveraged this SQL service account — which by convention holds elevated domain privileges — to enumerate users, shares, domain trusts, DNS records, and local administrators across the entire forest.

Process Injection Techniques

Malfind analysis confirmed code injection across multiple processes and systems. On base-wkstn-04 (172.16.6.14), SearchUI.exe (PID 9316) contained injected x64 shellcode with the Metasploit block_api prologue (\xfc\xe8\x04\x00\x00\x00, CLD; CALL $+4) and maintained active C2 connections. PowerShell PID 5452 on the same system contained identical Metasploit decoder stub shellcode. On base-rd-02, p.exe (PID 8260) exhibited a large PAGE_EXECUTE_READWRITE allocation consistent with injected shellcode. Multiple PowerShell processes across the environment showed VadS regions with RWX protection containing injected code.

Attacker Staging Directories

The attacker established staging directories designed to blend with legitimate Windows components. The c:\windows\temp\perfmon\ directory on multiple systems hosted the p.exe implant and an additional tool ("sd."), with the "perfmon" name mimicking Windows Performance Monitor paths. The C:\ProgramData\staging\install_wormhole\ directory contained the msadvapi2 installer. Both locations demonstrate deliberate masquerading to evade cursory inspection.

DMZ FTP Server Exposure and Log Deletion

The DMZ FTP server (172.16.10.12) was targeted by brute force credential attacks from multiple external IP addresses including 221.151.127.218 (targeting "administrator"), 95.47.155.87 (targeting "stark-r"), and 138.197.213.41 (rapid-fire automated credential stuffing against rsydow-a). All external brute force attempts appear to have failed. However, two FTP log files (u_ex180805.log and u_ex180823.log) were selectively deleted, creating gaps on August 5 and August 23 in an otherwise complete daily log sequence — suggesting intentional evidence destruction targeting specific dates of activity. The FTP server also exposed cleartext credentials: the rsydow-f account authenticated with the password "mprsydow@mail.com" in logs, representing poor credential hygiene that could enable credential reuse attacks.

False Positive YARA Detections

Several YARA detections were conclusively assessed as false positives. The APT6_Malware_Sample_Gen rule produced 233 match windows across memory dumps, but all matched strings were generic Windows artifacts ("shellcode," "synflood," common system paths). The APT_MAL_RU_WIN_Snake_Malware_May23_1 rule matched format string specifiers ("%s#1", "%s#2") common in Windows binaries. These detections do not indicate the presence of APT6 or Snake/Uroburos malware.

Corrected Assessments

Several initial findings were corrected through counter-analysis. The subject_srv.exe binary, originally flagged as a suspicious backdoor, was conclusively identified as the F-Response forensic remote acquisition agent based on its command-line parameters (-v "F-Response Subject" -k "155522845" -s "base-hunt.shieldbase.lan:5682"). Shadow copy PowerShell activity originally characterized as ransomware preparation was re-assessed as administrative enumeration (Get-CimInstance query with display output, not deletion) performed by the rsydow-a account via WinRM. The sub-win-x64_base-hunt_5682_3262.exe file on the DMZ FTP server was re-assessed as likely an F-Response agent binary based on filename correlation to confirmed F-Response port parameters (5682 license controller, 3262 subject agent).

Threat Intelligence and Attribution

YARA memory scanning detected signatures associated with Codoso/Deep Panda tooling on the domain controller. The Codoso_CustomTCP_4 rule matched the string "varus_service_x86.dll" — a specific malware component name — along with service manipulation commands ("net start %%1", "net stop %%1") and delay techniques ("ping 127.1 > nul"). The DeepPanda_htran_exe rule matched htran-specific syntax ("-slave ConnectHost ConnectPort TransmitHost TransmitPort") and debug messages ("[+] OK! I Closed The Two Socket."). These signatures confirm the presence of specific offensive tools in domain controller memory that have historically been associated with Chinese APT groups.

However, attribution to Codoso/Deep Panda or any specific threat group remains at the "inference" confidence level. The YARA detections represent a single detection tool with no independent corroboration from network IOCs, domain registrations, or infrastructure overlap with known campaigns. The htran network relay tool is publicly available and used by multiple threat groups. No C2 domain or external IP was linked to known Codoso/Deep Panda infrastructure. The co-existence of msadvapi2 (a persistent backdoor with packet capture capabilities deployed months before active operations) alongside Metasploit-framework stagers is consistent with known APT operational patterns — establishing quiet persistent access before conducting louder operational activity — but this pattern is not unique to any single group.

The attack tradecraft demonstrates a sophisticated threat actor with capabilities including: custom malware development (msadvapi2 with WinPcap integration), operational security awareness (proxy tunneling, Living-off-the-Land techniques, memory-resident tools), Active Directory domain expertise (service account compromise, PowerView enumeration, trust mapping), and multi-month operational patience. The tooling mix — custom persistent backdoor plus commodity framework (Metasploit) — is consistent with well-resourced threat groups that develop bespoke persistence tools while leveraging widely available post-exploitation frameworks for operational flexibility.

Impact Assessment

The intrusion compromised at least seven systems across the Stark Research Labs network, spanning the server infrastructure, R&D, and workstation subnets. The domain controller (BASE-DC), file server (BASE-FILE), and multiple user workstations were under active attacker control for a minimum of ten days during the Metasploit campaign, with the msadvapi2 backdoor providing persistent access for approximately three months prior. The compromised systems include the organization's domain controller, granting the attacker effective control over the entire Active Directory environment, including all user credentials, group policies, and trust relationships.

The spsql SQL service account was compromised and used for domain-wide reconnaissance, indicating the attacker had at minimum service-account-level credentials. The PowerView execution confirmed the attacker enumerated all domain users, shares, trust relationships, DNS records, and local administrator access across the forest. Data staging via Rar.exe on the file server, with ten minutes of active compression involving 67 threads, suggests preparation for bulk data exfiltration. The file server's role as a central data repository serving SMB connections from multiple hosts places the organization's core intellectual property and business data at risk.

The credential exposure on the DMZ FTP server (rsydow-f password logged in cleartext) and the VPN infrastructure at 172.16.1.20 (SoftEther VPN with external connections from multiple IPs) represent additional risk vectors. Selective deletion of two FTP log files on dates of interest suggests the attacker was aware of and attempted to cover specific activities on those dates.

McAfee endpoint protection and Windows Defender were deployed across the environment but failed to detect either the msadvapi2 backdoor services or the Metasploit PowerShell stagers, despite the malware running continuously as Windows services for months.

Immediate Tactical Containment

  1. Isolate all confirmed compromised systems from the network immediately: BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), 172.16.6.15, and the WinRM hub at 172.16.5.21.

  2. Block all traffic to and from 172.16.4.10:8080 at the network perimeter and internal firewall until the proxy server can be audited for C2 relay artifacts. Implement emergency egress filtering on all proxy alternatives.

  3. Disable the spsql service account in Active Directory and force a double password reset (reset once, wait for replication, reset again) on all accounts identified in the PowerView enumeration scope, prioritizing domain administrator and service accounts.

  4. Terminate the following processes on any systems still accessible: msadvapi2_32.exe and msadvapi2_64.exe (all instances), any powershell.exe processes with the -nop -w hidden -encodedcommand flags, and all orphaned rundll32.exe processes running in Session 0 with no visible command line.

  5. Remove the msadvapi2 Windows services and delete the installation directories: "C:\Program Files (x86)\Microsoft Advanced API 32\" and "C:\Program Files (x86)\Microsoft Advanced API 64\" on all systems. Remove the staging directory C:\ProgramData\staging\install_wormhole.

  6. Delete attacker staging artifacts: c:\windows\temp\perfmon\p.exe and c:\windows\temp\perfmon\sd.* on base-rd-02 and base-wkstn-01.

  7. Disable the rsydow-f and rsydow-a FTP accounts on the DMZ FTP server (172.16.10.12). Disable external FTP access entirely until the service can be migrated to SFTP with certificate-based authentication.

  8. Block inbound connections from known FTP brute force source IPs at the perimeter firewall: 138.197.213.41, 221.151.127.218, 95.47.155.87, 146.185.222.48, 185.255.31.2, 58.62.55.130, 60.212.42.56, 164.52.24.165, and 61.153.54.38.

  9. Disable WinRM (port 5985) on all non-administrative systems to disrupt the attacker's lateral movement channel. Restrict WinRM access to dedicated jump servers with explicit firewall rules.

  10. Initiate a full Kerberos krbtgt password reset (double reset) to invalidate any Golden Tickets the attacker may have forged using the compromised domain controller.

Strategic Remediation

The msadvapi2 backdoor (findings f_e4c31c4b, f_5216d777, f_043b8857) operated as a Windows service for approximately three months without detection by the deployed McAfee endpoint protection or Windows Defender. The malware loaded WinPcap for packet capture and ran under fabricated service names. This failure indicates the organization's endpoint detection capability lacks behavioral monitoring for service-based persistence and library-loading anomalies. The remediation is to deploy an endpoint detection and response (EDR) solution with behavioral analytics capable of detecting anomalous service registrations, suspicious DLL loads (particularly packet capture libraries by non-network-monitoring processes), and service binaries installed under names mimicking legitimate Microsoft products. Application whitelisting on server-class systems would have prevented the msadvapi2 service from executing.

The attacker's entire Metasploit campaign (findings f_9cea16b7, f_340f9940, f_886de2e3, f_10899b93) leveraged WMI remote execution and WinRM for lateral movement, both protocols that were enabled by default across the environment with no access restrictions. The WinRM convergence on 172.16.5.21 from all compromised subnets (finding f_d1f3eb7f) demonstrates the absence of network segmentation enforcement between server, R&D, and workstation subnets. The remediation is to implement host-based firewall rules restricting WMI (TCP 135, dynamic RPC) and WinRM (TCP 5985/5986) to designated management workstations only, and to enforce inter-subnet traffic filtering that prevents workstation-to-workstation lateral movement across subnet boundaries.

The compromised spsql SQL service account (finding f_83e43c8d) was used for domain-wide PowerView reconnaissance, indicating the service account held excessive Active Directory privileges and was not monitored for anomalous interactive logon activity. Service accounts authenticated interactively from workstations should generate immediate alerts. The remediation is to implement the principle of least privilege for all service accounts, configure them as Managed Service Accounts (gMSA) with automatic password rotation, restrict their logon rights to specific service hosts via Group Policy, and deploy SIEM alerting for interactive or network logon events from service account principals.

The attacker tunneled all C2 traffic through the organizational web proxy at 172.16.4.10:8080 (finding f_6325de06), which passed attacker traffic without inspection or alerting. The proxy was configured as a transparent relay without TLS inspection, content categorization, or anomaly detection for command-and-control beaconing patterns. The remediation is to deploy TLS-intercepting proxy infrastructure with domain categorization that blocks uncategorized or newly registered domains, implement JA3/JA3S fingerprint monitoring to detect known C2 framework TLS signatures, and configure alerting for beaconing patterns (regular-interval connections from non-browser processes).

The DMZ FTP server (172.16.10.12) exposed cleartext FTP (port 21) to the internet with password-based authentication (findings f_5c84d8da, f_dc34d77c), resulting in sustained brute force attacks and cleartext password exposure in logs. The rsydow-f password ("mprsydow@mail.com") captured in FTP logs could enable credential reuse against VPN or other services. The remediation is to decommission the cleartext FTP service entirely and migrate to SFTP with key-based authentication, implement account lockout policies to prevent automated brute force, and conduct a credential audit to identify any reuse of the exposed password across other systems.

The selective deletion of two FTP log files on August 5 and August 23 (finding f_6f6465b3) succeeded in creating evidence gaps because log integrity monitoring was absent. The remediation is to implement centralized log collection with immutable storage (write-once, append-only) that forwards logs to a SIEM in real time, preventing an attacker with host-level access from destroying log evidence.

Conclusion

Q1. What systems were compromised?
Seven systems are confirmed compromised: BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), and 172.16.6.15. An eighth system, the WinRM hub at 172.16.5.21, hosted msadvapi2 backdoor services and received inbound WinRM from all compromised subnets. Base-wkstn-01 (172.16.7.11) and base-rd-06 (172.16.6.13) show strong indicators but lack full corroboration. The Exchange server (172.16.4.6) and SharePoint server (172.16.4.7) are on the same subnet as compromised systems and show suspicious indicators but no confirmed attack chains. The DMZ FTP server (172.16.10.12) shows evidence of log tampering but no confirmed code execution.

Q2. How did the attacker gain initial access?
The precise initial access vector was not definitively determined. The earliest confirmed attacker artifact is the msadvapi2 installer staged in December 2017, but the method of initial delivery is unknown. The base-wkstn-04 interactive PowerShell session (launched from explorer.exe in the user's desktop on 2018-08-27) is the only system showing a user-session-initiated compromise, suggesting possible phishing or social engineering for the Metasploit campaign phase. The SoftEther VPN gateway (172.16.1.20) and internet-exposed FTP server represent potential but unconfirmed entry points. The exposed FTP password (mprsydow@mail.com) could have enabled credential reuse against VPN services.

Q3. What lateral movement occurred?
Extensive lateral movement was conducted using WMI remote execution (T1047) for initial code deployment, WinRM (T1021.006) for sustained remote PowerShell access, RDP (T1021.001) between R&D systems, and SMB (T1021.002) for file server access. The system at 172.16.5.21 served as a cross-subnet WinRM convergence point receiving connections from all compromised subnets. The attacker's lateral movement was facilitated by the compromised spsql service account and the absence of inter-subnet access controls.

Q4. What persistence mechanisms were installed?
The primary persistence mechanism was the msadvapi2 Windows service (T1543.003), deployed in both 32-bit and 64-bit variants across at least three systems and surviving reboots for months. The Metasploit campaign relied on memory-resident implants (injected into rundll32.exe and SearchUI.exe processes) that would not survive a reboot but were continuously refreshed via WMI deployment. No additional persistence mechanisms such as scheduled tasks, registry autorun keys, or startup folder modifications were identified.

Q5. Was data exfiltrated, and if so, what and how much?
Data staging was confirmed: Rar.exe compressed data on the file server for approximately ten minutes on September 5, 2018, indicating significant data volume. However, no direct evidence of exfiltration (outbound data transfers to external infrastructure) was recovered from the available evidence. The attacker's C2 channel through the web proxy could have served as an exfiltration path. FTP data retrieval operations by the dblake account accessing /Users/ directories (including user nfury's files) on the DMZ FTP server were observed but may represent authorized activity. The deleted FTP logs may have contained evidence of additional data movement.

Q6. What is the full timeline of the incident?
The incident spans from at least December 2017 (msadvapi2 installer creation) through September 7, 2018 (final evidence collection). The msadvapi2 backdoor was deployed in May 2018. Active Metasploit operations began on August 27, 2018, with WMI-based lateral movement escalating through August 31 and a second deployment wave on September 6. Data staging occurred on September 5. Incident response activities began approximately September 6–7 with F-Response and FTK Imager deployment.

Q7. What is the total scope and business impact?
The attacker achieved domain administrator-equivalent access, compromising the domain controller and conducting full Active Directory reconnaissance. Seven to ten systems across server, R&D, and workstation subnets were compromised, spanning all major network segments. The file server containing organizational data was under active C2 control with confirmed data staging. All domain credentials should be considered compromised. The McAfee endpoint protection suite failed to detect any stage of the intrusion across all monitored systems.

Q8. What are the recommended remediation actions?
Immediate actions include isolating all compromised systems, performing a full krbtgt double reset, disabling compromised accounts (spsql, rsydow-a, rsydow-f), removing msadvapi2 services and staging directories, restricting WMI/WinRM to managed endpoints, and blocking attacker infrastructure. Strategic actions include deploying behavioral EDR with service monitoring, implementing network segmentation with inter-subnet access controls, migrating to managed service accounts with logon restrictions, deploying TLS-inspecting proxy with C2 detection, decommissioning cleartext FTP in favor of SFTP, and implementing centralized immutable log collection.

2017-12-20
2017-12-20T14:52:51 — 2018-09-06T17:26:35
Attacker Staging Directories with Malicious Tooling on base-rd-02
high confirmed
ez.mft, registry.system
2018-04-10
2018-04-10T19:29:48
subject_srv.exe Identified as F-Response Forensic Remote Acquisition Agent (Not Malicious)
info confirmed
volatility.psscan, volatility.netscan, registry.system, tsk.filelist
2018-06-04
2018-06-04T20:19:12
msadvapi2 Backdoor Malware Running as Services on Multiple Systems
critical confirmed
volatility.pslist, volatility.cmdline, volatility.dlllist, volatility.malfind
2018-06-04T20:19:30 — 2018-09-07T19:43:31
Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September)
critical confirmed
volatility.dlllist, volatility.cmdline, volatility.pstree, volatility.netscan, registry.system
2018-06-04T20:19:38 — 2018-09-06T21:02:43
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor
critical confirmed
volatility.pstree, volatility.netscan, volatility.cmdline, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
2018-07-16
2018-07-16T21:08:00 — 2018-09-05T18:47:48
External FTP User rsydow-f Authenticated with Cleartext Password Exposure
medium confirmed
bulk.domain
2018-07-16T21:08:00 — 2018-09-05T18:47:48
Interactive User Access via rsydow-a Account on DMZ FTP Server
medium confirmed
tsk.filelist, ez.mft, bulk.domain
2018-07-16T21:08:00
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs
medium confirmed
bulk.domain
2018-07-29
2018-07-29T12:55:18 — 2018-09-07T05:21:52
base-wkstn-06 (172.16.5.26) — Admin Workstation with Extensive Infrastructure Access, No Compromise Indicators
info confirmed
volatility.pstree, volatility.netscan, volatility.pslist
2018-08-02
2018-08-02T05:04:03 — 2018-09-06T10:11:41
base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Exposure
medium inference
volatility.netscan, volatility.pstree
2018-08-05
2018-08-05T00:00:01
FTP Log Files Deleted - Potential Evidence Destruction on DMZ FTP Server
medium inference
tsk.filelist
2018-08-07
2018-08-07T23:30:07 — 2018-08-07T23:36:45
FTP Data Exfiltration of User Profile Directories from DMZ FTP Server
medium inference
bulk.domain, bulk.email
2018-08-08
2018-08-08T00:00:01 — 2018-08-31T23:59:59
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs
medium confirmed
bulk.domain
2018-08-09
2018-08-09T17:42:39 — 2018-08-09T17:42:40
sub-win-x64_base-hunt_5682_3262.exe — Likely F-Response Subject Agent Binary, Not Cobalt Strike Stager
low inference
ez.mft, tsk.filelist, tsk.icat
2018-08-15
2018-08-15T16:32:11 — 2018-09-07T19:43:31
Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP
critical confirmed
volatility.netscan, volatility.psscan, volatility.pstree, volatility.cmdline, volatility.malfind, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, ez.mft, registry.system, yara.memory, bulk.domain
2018-08-15T16:32:11 — 2018-09-06T17:26:35
User Account tdungan Compromised — Active Session During Attack on base-rd-02
medium inference
volatility.cmdline, evtx.windows_system32_winevt_logs_microsoft-windows-terminalservices-localsessionmanager4operational, ez.mft
2018-08-15T16:36:39 — 2018-08-15T16:36:39
Remote PowerShell Reconnaissance by cbarton-a on base-rd-02
medium inference
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
2018-08-15T17:00:39
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All Compromised Subnets
high confirmed
volatility.netscan
2018-08-17
2018-08-17T13:46:31
base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection
high confirmed
volatility.pstree, volatility.netscan
2018-08-22
2018-08-22T04:50:38
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21
high confirmed
volatility.netscan, bulk.httplogs
2018-08-27
2018-08-27T21:25:58 — 2018-09-06T19:08:45
Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 with 20+ Rundll32 Injections and WMI Stager
critical confirmed
volatility.cmdline, volatility.malfind, volatility.netscan, volatility.pslist, volatility.pstree
2018-08-28
2018-08-28T20:40:22
Environment-Wide C2 Proxy Tunneling via 172.16.4.10:8080 Across 7+ Systems
critical confirmed
volatility.netscan, bulk.httplogs
2018-08-28T20:40:22
Chrome.exe C2 Proxy Connection and Code Injection on System 172.16.5.20
medium inference
volatility.netscan, volatility.malfind
2018-08-28T22:08:25 — 2018-09-06T22:11:15
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server
critical confirmed
volatility.psscan, volatility.netscan, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
2018-08-28T22:08:25 — 2018-09-06T22:11:15
YARA Signature Matches: Codoso/Deep Panda Tooling in DC Memory
high inference
yara.memory
2018-08-28T22:08:25
BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21)
high confirmed
volatility.netscan, volatility.pslist
2018-08-29
2018-08-29T22:01:00
SearchUI.exe Shellcode Injection with C2 Connection to 172.16.4.10:8080
high confirmed
volatility.malfind, volatility.netscan
2018-08-30
2018-08-30T13:52:22 — 2018-09-06T18:28:32
Extensive C2 and Lateral Movement Network Connections from base-rd-02
high confirmed
bulk.httplogs, volatility.netscan, volatility.psscan
2018-08-30T16:43:36 — 2018-09-06T17:26:35
WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)
critical confirmed
ez.mft, registry.system, volatility.cmdline, volatility.dlllist, volatility.malfind, volatility.pstree
2018-08-30T16:43:36 — 2018-09-06T17:26:35
C2 Network Connections from base-wkstn-01 to 172.16.4.10:8080
high confirmed
volatility.netscan, volatility.cmdline
2018-08-30T16:43:36
WMI-Based Remote Code Execution on base-wkstn-01
high confirmed
volatility.cmdline, volatility.pstree
2018-08-30T21:27:31
Exchange Server (172.16.4.6) Memory Dump - No C2 Indicators but Accessible to Attacker
info inference
volatility.netscan
2018-08-30T22:14:02
Malicious Executable Dropped and Executed: c:\windows\temp\perfmon\p.exe
high confirmed
volatility.cmdline, registry.system
2018-08-31
2018-08-31T01:00:30
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System
high confirmed
volatility.pstree, volatility.netscan
2018-08-31T01:14:44 — 2018-09-06T19:37:40
WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)
critical confirmed
volatility.netscan, volatility.psscan
2018-08-31T01:31:44 — 2018-09-06T19:37:40
Rundll32 Process Injection for Post-Exploitation on base-wkstn-05
high confirmed
volatility.cmdline, volatility.psscan
2018-08-31T19:47:10
Suspicious rundll32.exe on base-mail Exchange Server (PID 15116)
medium inference
volatility.pslist, volatility.dlllist, volatility.psscan, volatility.cmdline, volatility.malfind
2018-08-31T21:53:03
Shadow Copy Enumeration via PowerShell on File Server — Likely Administrative Activity, Not Ransomware Preparation
info confirmed
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
2018-08-31T21:54:13 — 2018-08-31T22:52:08
Compromised SQL Service Account (spsql) Used for Domain Reconnaissance
high confirmed
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, ez.mft
2018-08-31T22:16:12 — 2018-08-31T22:52:08
PowerView/PowerSploit Active Reconnaissance from Domain Controller
critical confirmed
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, volatility.psscan
2018-08-31T22:16:12
PowerView Active Directory Reconnaissance from Compromised Systems
high confirmed
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
2018-09-03
2018-09-03T13:51:03 — 2018-09-06T13:51:20
base-wkstn-02 (172.16.7.16) - Active Workstation with LARIAT but No Direct Compromise Indicators in Memory
low inference
volatility.netscan, volatility.pstree
2018-09-05
2018-09-05T14:06:04 — 2018-09-06T22:11:15
Cross-System Comparison: F-Response Agent (subject_srv.exe) Deployed Between Memory Captures — IR Activity, Not Attacker Persistence
info confirmed
volatility.psscan, volatility.netscan
2018-09-05T14:43:11 — 2018-09-05T14:52:56
Data Staging via Rar.exe on File Server
high inference
ez.mft, volatility.psscan
2018-09-06
2018-09-06T17:13:57
Encoded PowerShell Stager Delivered to base-wkstn-01 via WinRM
high confirmed
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, bulk.httplogs
2018-09-06T17:43:45 — 2018-09-07T19:43:31
Environment-Wide WMI→PowerShell(64→32)→Rundll32 Attack Chain Across 8+ Systems
critical confirmed
volatility.pstree, volatility.cmdline, volatility.malfind, volatility.netscan
2018-09-06T17:43:45
Process Injection in PowerShell on SearchUI System (172.16.6.14)
high confirmed
volatility.malfind
2018-09-07
2018-09-07T02:46:37 — 2018-09-07T05:21:52
WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation
high confirmed
bulk.domain, bulk.httplogs
critical confirmed PowerView/PowerSploit Active Reconnaissance from Domain Controller

PowerView (part of the PowerSploit framework) was loaded and executed on the domain controller BASE-DC on 2018-08-31 between 22:16 and 22:52 UTC. The PowerShell Operational event log (Event ID 4104 - ScriptBlock logging) captured the full script content, which includes the following PowerView functions:

  • Invoke-UserHunter: Finds logged-in users across the domain
  • Invoke-ShareFinder: Enumerates accessible network shares
  • Invoke-CheckLocalAdminAccess: Checks local admin access on domain hosts
  • Get-NetDomain/Get-NetForest: Domain and forest enumeration
  • Invoke-MapDomainTrust: Domain trust mapping
  • Get-ForeignGroup: Cross-domain group enumeration
  • Get-DNSRecord/Get-DNSZone: DNS record enumeration
  • Invoke-EnumerateLocalAdmin: Local admin enumeration across domain
  • Find-LocalAdminAccess: Automated local admin access discovery
  • Get-Keystrokes: Keystroke logging capability

The script was executed under user SID S-1-5-21-3445421715-2530590580-3149308974-1193 (spsql) on host base-file.shieldbase.lan. The PowerShell host application was C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe. References to both Metasploit and PowerShell Empire GitHub repositories were present in the script code, confirming the offensive tooling origin.

This represents full AD reconnaissance from a compromised domain controller using a service account (spsql), consistent with post-exploitation lateral movement and domain enumeration.

Evidence strength:
2 refs
evtx.windows_system32_winevt_logs_mic...volatility.psscan

Evidence Chain

tc_6d56b84a search 1959ms
tc_5e2b911e search 86ms
Time: 2018-08-31T22:16:12 — 2018-08-31T22:52:08
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, volatility.psscan
Evidence Refs: tc_6d56b84a, tc_5e2b911e
critical confirmed PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server

A multi-stage attack chain was detected on the file server (BASE-FILE, 172.16.4.5) involving remote WMI execution leading to PowerShell C2 activity and massive rundll32.exe spawning, consistent with a post-exploitation framework (e.g., Cobalt Strike, Empire, Metasploit).

Stage 1 - Remote WMI Execution:
- WmiPrvSE.exe (PID 1196) spawned powershell.exe (PID 4072)
- PID 4072: 64-bit, started 2018-08-28 22:08:25
- WMI remote execution indicates lateral movement from another host

Stage 2 - PowerShell Architecture Downgrade:
- PID 4072 spawned powershell.exe (PID 3164), 32-bit (Wow64=True), started 2018-08-28 22:08:26
- 32-bit PowerShell on a 64-bit host is a red flag commonly used by exploitation frameworks for shellcode compatibility
- Running under user shieldbase\spsql (service account)

Stage 3 - Rundll32 Process Spawning:
- PID 3164 spawned 30+ rundll32.exe child processes between 2018-08-30 and 2018-09-06
- Observed PIDs include: 3548 (08-30 02:52), 3260 (08-30 18:40), 300 (08-30 03:23), and many more
- Rundll32 spawning is a classic technique for code injection / reflective DLL loading

Network C2:
- Both PowerShell processes (PID 4072 and PID 3164) connected to 172.16.4.10:8080 (ESTABLISHED)
- 172.16.4.10 appears to be a web proxy; C2 traffic likely tunneled through the proxy

PowerShell Script Logging (Event ID 4104):
- Scripts executed by shieldbase\spsql included Win32_ShadowCopy manipulation and NetFirewallRule commands
- Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Evidence strength:
5 refs
volatility.psscanvolatility.netscanevtx.windows_system32_winevt_logs_mic...

Evidence Chain

tc_d9eff5a7 search 925ms
tc_ac657197 search 42ms
tc_18f35d85 search 472ms
tc_9a2617bb search 119ms
tc_049f2680 search 44ms
Time: 2018-08-28T22:08:25 — 2018-09-06T22:11:15
Sources: volatility.psscan, volatility.netscan, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
Evidence Refs: tc_d9eff5a7, tc_ac657197, tc_18f35d85, tc_9a2617bb, tc_049f2680
critical confirmed WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)

A multi-stage attack chain was established on base-rd-02 (172.16.6.11) via WMI, mirroring the pattern observed on the DC and file server.

Full Process Tree:
1. WmiPrvSE.exe (PID 2876, Session 0) → powershell.exe (PID 8712, 64-bit, started 2018-08-30 16:43:36, no visible command-line args)
2. PID 8712 → powershell.exe (PID 5848, 32-bit/SysWOW64, started 2018-08-30 16:43:42, args: "-Version 5.1 -s -NoLogo -NoProfile")
3. PID 5848 spawned multiple rundll32.exe processes for code injection:
- PID 6768: 2018-08-30 18:31:04 – 18:31:35 (SysWOW64)
- PID 5452: 2018-08-30 21:40:18 – 21:40:23
- PID 5588: 2018-08-30 21:40:42 – 21:40:54
- PID 2216: 2018-08-30 22:31:57 – 22:32:19 (SysWOW64)
- PID 4108: 2018-08-30 22:45:25 – 22:45:30
- PID 8148: 2018-08-31 00:56:14 – 00:56:30 (SysWOW64)
4. PID 5848 also spawned cmd.exe (PID 5948) which executed c:\windows\temp\perfmon\p.exe (PID 8260) at 2018-08-30 22:15:18

Second-Stage Implant (p.exe):
- p.exe (PID 8260) spawned its own rundll32.exe instances days later:
- PID 5768: 2018-09-05 12:01:32 – 12:01:40
- PID 1424: 2018-09-06 14:58:41 – 14:58:45
- PID 7552: 2018-09-06 17:26:32 – 17:26:35
- p.exe had a malfind hit: VadS PAGE_EXECUTE_READWRITE, CommitCharge=481 (large RWX allocation consistent with injected shellcode)
- The file at c:\windows\temp\perfmon\p.exe was not found in MFT, suggesting deletion after deployment

Malfind Detections:
- powershell.exe PID 8712: 3 VadS regions with PAGE_EXECUTE_READWRITE (injected code)
- p.exe PID 8260: VadS with PAGE_EXECUTE_READWRITE, 481 commit charge

Key Indicators:
- WMI-initiated execution in Session 0 (non-interactive, remote origin)
- 32-bit PowerShell downgrade on 64-bit OS (framework shellcode compatibility)
- No visible command-line args on initial PowerShell (anti-forensics)
- Stealth flags: -s -NoLogo -NoProfile on child PowerShell
- Short-lived rundll32.exe child processes spanning Aug 30 – Sep 6 (8+ days of sustained access)

This attack chain is identical to the one on the file server (BASE-FILE) and DC, confirming base-rd-02 was compromised via the same campaign using the same Metasploit/Cobalt Strike-style post-exploitation framework.

Affected Systems: ez.mft, registry.system, volatility.cmdline, volatility.dlllist, volatility.malfind, volatility.pstree

Evidence strength:
6 refs
ez.mftregistry.systemvolatility.cmdlinevolatility.dlllistvolatility.malfindvolatility.pstree

Evidence Chain

tc_3cce3174 search 54ms
tc_5a1b743e search 29ms
tc_b8b432ec get_raw_output 29053ms
tc_c4f12402 get_raw_output 409ms
tc_dd5b51dc search 37ms
tc_ec862127 get_raw_output 17346ms
Time: 2018-08-30T16:43:36 — 2018-09-06T17:26:35
Sources: ez.mft, registry.system, volatility.cmdline, volatility.dlllist, volatility.malfind, volatility.pstree
Evidence Refs: tc_3cce3174, tc_5a1b743e, tc_b8b432ec, tc_c4f12402, tc_dd5b51dc, tc_ec862127
critical confirmed WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)

Three parallel WMI-initiated PowerShell attack chains were established on base-wkstn-05 (172.16.7.15, user: mhill) within a 17-minute window on 2018-08-31, matching the exact pattern observed on other compromised systems (base-rd-02, file server, DC).

Attack Chain Details (from psscan source_id 232):

Chain 1: WmiPrvSE.exe (PID 2676, Session 0) → powershell.exe (PID 4328, 64-bit, 01:14:44) → powershell.exe (PID 1124, WoW64/32-bit, 01:14:45)

Chain 2: WmiPrvSE.exe (PID 2676) → powershell.exe (PID 4064, 64-bit, 01:23:24) → powershell.exe (PID 4072, WoW64/32-bit, 01:23:25)

Chain 3: WmiPrvSE.exe (PID 2676) → powershell.exe (PID 3920, 64-bit, 01:31:24) → powershell.exe (PID 1332, WoW64/32-bit, 01:31:25)

All three chains follow the identical pattern:
1. WMI Provider Host (Session 0, non-interactive) spawns 64-bit PowerShell
2. 64-bit PowerShell immediately spawns 32-bit (WoW64) child for shellcode compatibility
3. No visible command-line args on the 64-bit parent (anti-forensics)

Chain 3 was the active C2 session: PID 1332 (32-bit PowerShell) spawned 5+ rundll32.exe code injection targets:
- PID 5300: 2018-08-31 01:31:44 – 01:31:46 (2 sec)
- PID 3720: 2018-08-31 21:07:21 – 21:07:28 (7 sec)
- PID 5056: 2018-08-31 20:23:08 – 20:23:29 (21 sec)
- PID 4240: 2018-08-31 20:23:17 – 20:23:35 (18 sec)
- PID 1972: 2018-08-31 20:23:52 – 20:23:56 (4 sec)

A persistent rundll32.exe (PID 7100, PPID 7148) was still running at memory capture time with 5 threads and 337 handles, suggesting a long-running implant module.

Three simultaneous chains (vs one on other systems) suggests the attacker experienced connectivity issues or the first two stagers failed to fully initialize, requiring retry attempts.

System context:
- System boot: 2018-08-30 05:14:12
- User mhill connected via RDP (rdpclip.exe PID 4232 in Session 5)
- Active applications: Outlook, Chrome, GROOVE.EXE (OneDrive/SharePoint)
- Sysmon64.exe (PID 1892) was running but did not prevent the compromise
- McAfee AV suite fully deployed (masvc, mfefire, mcshield, HipMgmt)

Affected Systems: volatility.psscan

Affected Systems: volatility.netscan, volatility.psscan

Evidence strength:
8 refs
volatility.netscanvolatility.psscan

Evidence Chain

tc_1c1f42e1 search 91ms
tc_2c5eaec1 search 126ms
tc_3ec26e83 search 3588ms
tc_5449cb1b get_raw_output 9026ms
tc_a615ccff search 363ms
tc_b53f321a get_raw_output 10605ms
tc_b83a24d3 scan_hidden_processes 15ms
tc_ce81377a get_raw_output 9145ms
Time: 2018-08-31T01:14:44 — 2018-09-06T19:37:40
Sources: volatility.netscan, volatility.psscan
Evidence Refs: tc_1c1f42e1, tc_2c5eaec1, tc_3ec26e83, tc_5449cb1b, tc_a615ccff, tc_b53f321a, tc_b83a24d3, tc_ce81377a
critical confirmed Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP

COUNTER-ANALYSIS CORRECTIONS applied to comprehensive timeline:

IP Correction: BASE-DC is 172.16.4.4, not 172.16.4.1 as previously stated.

DMZ-FTP Reclassified: DMZ-FTP (172.16.10.12) is downgraded from "confirmed compromised" to "unconfirmed." The primary evidence (sub-win-x64_base-hunt_5682_3262.exe) has been re-assessed as likely an F-Response subject agent binary (see finding f_bec07e91). FTP brute force attempts all failed. FTP log deletion is suspicious but insufficient alone. No memory dump was available for this system, preventing WMI/PowerShell chain confirmation.

IR Activity Separation: subject_srv.exe deployments across all systems are F-Response forensic tooling deployed by incident responders starting ~2018-09-06, not attacker persistence. Autorunsc.exe execution on 2018-08-15 is consistent with IR triage rather than attacker activity.

CORRECTED Attack Timeline (Aug-Sep 2018):

  1. Pre-Existing Access (June+ 2018):
  2. msadvapi2 backdoor services deployed on 3+ systems (BASE-DC 172.16.4.4, base-wkstn-03 172.16.6.13, 172.16.6.15)
  3. Persistent packet capture capability via wpcap.dll

  4. Possible Early IR Triage (August 15, 2018):

  5. cbarton-a remote PowerShell reconnaissance on base-rd-02 (could be legitimate admin activity)
  6. Autorunsc.exe execution on 172.16.6.15

  7. Active Offensive Operations (August 27-September 6, 2018):

  8. WMI-based remote code execution deploying Metasploit PowerShell stagers across 7+ systems
  9. C2 tunneled through organizational web proxy at 172.16.4.10:8080
  10. PowerView AD reconnaissance from file server using spsql service account (Aug 31)
  11. Data staging via Rar.exe on BASE-FILE (Sep 5)
  12. WinRM lateral movement converging on 172.16.5.21

  13. Confirmed Compromised Systems (7):

  14. BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), 172.16.6.15

  15. Likely Compromised (insufficient evidence for full confirmation):

  16. base-wkstn-01 (172.16.7.11) — WMI chain observed but limited corroboration
  17. base-rd-06 (172.16.6.13) — msadvapi2 + C2 proxy connection

  18. Not Compromised:

  19. 172.16.5.25 (base-hunt) — Forensic workstation
  20. 172.16.5.26 — Admin workstation
  21. 172.16.7.16 (base-wkstn-02) — No compromise indicators
Evidence strength:
3 refs
volatility.netscanvolatility.psscanvolatility.pstreevolatility.cmdlinevolatility.malfindevtx.windows_system32_winevt_logs_mic...ez.mftregistry.systemyara.memorybulk.domain

Evidence Chain

tc_aeae3c99 get_raw_output 720ms
tc_94019da7 get_raw_output 748ms
tc_a99601d8 search 89ms
Time: 2018-08-15T16:32:11 — 2018-09-07T19:43:31
Sources: volatility.netscan, volatility.psscan, volatility.pstree, volatility.cmdline, volatility.malfind, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, ez.mft, registry.system, yara.memory, bulk.domain
Evidence Refs: tc_aeae3c99, tc_94019da7, tc_a99601d8
critical confirmed msadvapi2 Backdoor Malware Running as Services on Multiple Systems

Two malicious executables disguised as "Microsoft Advanced API" are running as persistent services on at least two compromised systems (memory captures with boot times 2018-06-04, 2018-08-17, and 2018-09-06):

  • msadvapi2_32.exe (PIDs 1072/2020, WoW64 32-bit) at "C:\Program Files (x86)\Microsoft Advanced API 32\msadvapi2_32.exe"
  • msadvapi2_64.exe (PIDs 1240/1256, 64-bit) at "C:\Program Files (x86)\Microsoft Advanced API 64\msadvapi2_64.exe"

Both processes run under services.exe (Session 0) as system services, indicating service-based persistence. The malware persists across reboots, confirmed by its presence in three separate memory captures spanning June through September 2018. Malfind detected PAGE_EXECUTE_READWRITE memory regions in msadvapi2_32.exe (PID 1072), indicating possible code injection or runtime unpacking. DLL analysis shows the malware loads wpcap.dll (WinPcap), IPHLPAPI.DLL, and network-related libraries, consistent with network packet capture or traffic manipulation capabilities.

The "Microsoft Advanced API" naming is a deliberate deception technique to blend with legitimate Microsoft software. There is no legitimate Microsoft product by this name. The installation under "Program Files (x86)" and registration as a Windows service demonstrates sophisticated persistence by the threat actor.

Evidence strength:
3 refs
volatility.pslistvolatility.cmdlinevolatility.dlllistvolatility.malfind

Evidence Chain

tc_59d084a3 search 107ms
tc_33400b38 search 122ms
tc_ca6a4a98 search 293ms
Time: 2018-06-04T20:19:12
Sources: volatility.pslist, volatility.cmdline, volatility.dlllist, volatility.malfind
Evidence Refs: tc_59d084a3, tc_33400b38, tc_ca6a4a98
critical confirmed base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor

Memory forensics of base-wkstn-03 (172.16.7.14, dual-homed 10.10.150.181) reveals multiple concurrent compromise mechanisms. System boot time: 2018-06-04 20:18:58.

1. WMI-Based Lateral Movement (T1047):
EVTX PowerShell operational logs captured the attacker executing Invoke-WmiMethod with ComputerName="BASE-WKSTN-03" and Class="win32_process" at 2018-09-06 17:01:50, confirming WMI remote code execution targeting this host.

2. Metasploit PowerShell Stager Chain:
- WmiPrvSE.exe (PID 3308, born 2018-06-04 20:19:47) spawned powershell.exe (PID 4340, born 2018-09-06 17:24:47) running: powershell.exe -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIA...
- Decoded payload: $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sI..."));IEX (New-Object IO.StreamReader(New-Object IO.Compression.GzipStream($s,[IO.Compression.CompressionMode]::Decompress))).ReadToEnd();
- Architecture downgrade: PID 4340 (64-bit) spawned PID 1288 (32-bit SysWOW64 powershell.exe, born 2018-09-06 17:24:49) for Metasploit shellcode compatibility

3. msadvapi2 Backdoor (Persistent Services):
- msadvapi2_32.exe (PID 2240, WoW64, born 2018-06-04 20:19:38) at "C:\Program Files (x86)\Microsoft Advanced API 32\"
- msadvapi2_64.exe (PID 2248, born 2018-06-04 20:19:38) at "C:\Program Files (x86)\Microsoft Advanced API 64\"
- Both run as children of services.exe (PID 736), indicating persistent service registration since system boot
- Backdoor has been present since at least 2018-06-04 (3+ months before incident response)

4. LARIAT Framework:
- prunsrv.exe (PID 2268) → java.exe (PID 324) running Lincoln Lab LARIAT c2 client
- LARIAT java connections to external IPs (closed state)

5. Network Indicators:
- SMB from file server: 172.16.4.5:59071 → 172.16.7.14:445 ESTABLISHED (2018-09-06 17:24:47)
- WinRM outbound: 172.16.7.14:54302 → 172.16.5.21:5985 CLOSED (2018-09-06 21:02:43)
- Puppet/MCO: 10.10.150.181:54120 → 10.10.254.1:61613 ESTABLISHED
- F-Response: subject_srv.exe (PID 6556) deployed 2018-09-06 20:55:26

6. Security Tools Deployed but Bypassed:
- McAfee VirusScan Enterprise, Host Intrusion Prevention, Agent
- SecurityHealthService (Windows Defender)
- Neither detected the msadvapi2 backdoor or PowerShell stager

Evidence strength:
4 refs
volatility.pstreevolatility.netscanvolatility.cmdlineevtx.windows_system32_winevt_logs_mic...

Evidence Chain

tc_7453df17 get_raw_output 817ms
tc_bc36392e get_raw_output 200ms
tc_39e0d78b search 190ms
tc_af127c6b get_raw_output 1210ms
Time: 2018-06-04T20:19:38 — 2018-09-06T21:02:43
Sources: volatility.pstree, volatility.netscan, volatility.cmdline, evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
Evidence Refs: tc_7453df17, tc_bc36392e, tc_39e0d78b, tc_af127c6b
critical confirmed Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 with 20+ Rundll32 Injections and WMI Stager

Memory forensics of base-wkstn-04 (172.16.6.14, boot 2018-08-06 16:38:49) reveals two distinct, concurrent attack chains operating in different security contexts.

Attack Chain 1 — Interactive User Session (Session 11):
PowerShell PID 2664 was launched from explorer.exe (PID 8392) in the user's interactive desktop session at 2018-08-27 21:25:58. This PowerShell process spawned 20+ short-lived rundll32.exe injection targets over a 3-day period:
- 2018-08-27: PIDs 9644, 4476, 6260, 2508, 9756, 12496, 6720, 1000, 12692 (9 instances, 2-4 second lifetimes each)
- 2018-08-28: PIDs 7696, 9476, 7680, 12208, 6320, 3816, 9784, 10196, 9292, 9824, 12328 (11 instances)
- 2018-08-30: PID 8436 (1 instance)
Additionally, PID 2664 spawned child PowerShell processes: PID 3924 (exited 08-30 04:55:24), PID 6804 (exited 09-06 17:40:12), PID 4520 (still running at capture time). PID 2664 maintained active network connections to C2 proxy at 172.16.4.10:8080 (ports 51278, 52483 CLOSED).

A long-running rundll32.exe PID 8856 (spawned by PID 8448 at 2018-08-27 23:39:56) was still running at memory capture — 10+ days of persistent execution, indicating a persistent implant module.

PID 2664 also opened a local listener on port 18278 (127.0.0.1:18278), consistent with a local C2 relay or socks proxy used by post-exploitation frameworks.

Attack Chain 2 — WMI Remote Execution (Session 0):
On 2018-09-06 17:43:45, WmiPrvSE.exe (PID 3156) spawned powershell.exe PID 4896 with encoded Metasploit stager: "powershell.exe -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIA..." decoding to the standard GZip-compressed shellcode loader ($s=New-Object IO.MemoryStream). PID 4896 spawned 32-bit child powershell.exe PID 5452 (WoW64 architecture downgrade). Malfind confirmed Metasploit shellcode (fc e8 04 00 00 00 — CLD; CALL $+4 decoder stub) in PID 5452's memory.

SearchUI.exe Injection (PID 9316):
SearchUI.exe contained injected x64 shellcode (PAGE_EXECUTE_READWRITE) and maintained 7+ CLOSE_WAIT connections to 172.16.4.10:8080 (ports 55897-55903, 49320-49323), establishing persistent C2 from 2018-08-29 22:01 through 2018-09-06.

Network Summary:
- 30+ connections to C2 proxy 172.16.4.10:8080 (via SearchUI.exe, powershell.exe, svchost.exe, ngen.exe, LogonUI.exe, MicrosoftEdge, software_reporter)
- 8+ WinRM sessions to 172.16.5.21:5985 (lateral movement pivot)
- SMB to file server (172.16.4.5:445), DC (172.16.4.4:445/49670), Exchange (172.16.4.6:443)
- Inbound SMB from file server: 172.16.4.5:59106 → 172.16.6.14:445 (timed with WMI stager delivery at 17:43:46)
- F-Response (subject_srv.exe PID 7140) deployed 2018-09-06 19:05:20

Significance:
Unlike other compromised systems that show only WMI-based remote attack chains, base-wkstn-04 had an INTERACTIVE PowerShell C2 session running from the user's own desktop (Session 11) for 10+ days. This suggests the attacker either had direct desktop access (RDP) or the initial compromise occurred through a user-initiated action (phishing, malicious link).

Affected Systems: volatility.cmdline, volatility.malfind, volatility.netscan, volatility.pslist, volatility.pstree

Evidence strength:
5 refs
volatility.cmdlinevolatility.malfindvolatility.netscanvolatility.pslistvolatility.pstree

Evidence Chain

tc_2fed88d5 search 115ms
tc_63b64e47 get_raw_output 700ms
tc_83e0936f get_raw_output 228ms
tc_c3c902c7 search 50ms
tc_f6c98bd4 search 248ms
Time: 2018-08-27T21:25:58 — 2018-09-06T19:08:45
Sources: volatility.cmdline, volatility.malfind, volatility.netscan, volatility.pslist, volatility.pstree
Evidence Refs: tc_2fed88d5, tc_63b64e47, tc_83e0936f, tc_c3c902c7, tc_f6c98bd4
critical confirmed Environment-Wide WMI→PowerShell(64→32)→Rundll32 Attack Chain Across 8+ Systems

COUNTER-ANALYSIS NOTE: IP correction — the original finding listed "BASE-DC (172.16.4.1)" but the domain controller is at 172.16.4.4.

Cross-system correlation reveals a uniform attack chain deployed across at least 7 confirmed hosts in the shieldbase.lan environment: WmiPrvSE.exe spawns 64-bit PowerShell with encoded command (-nop -w hidden -encodedcommand), which spawns 32-bit PowerShell (SysWOW64) performing a second stage decode, which injects into rundll32.exe via process hollowing.

Confirmed systems with this chain:
- base-wkstn-04 (172.16.6.14) — Interactive + WMI chains
- base-wkstn-05 (172.16.7.15) — 3 parallel WMI chains
- base-wkstn-03 (172.16.6.13) — WMI chain + msadvapi2
- base-rd-02 (172.16.6.11) — WMI chain + p.exe stager
- BASE-FILE (172.16.4.5) — WMI chain + data staging
- 172.16.6.15 — Encoded PowerShell stager
- base-wkstn-01 (172.16.7.11) — WMI chain

The uniformity of this chain—identical process hierarchy, identical PowerShell flags, identical 64→32-bit downgrade, identical rundll32 injection target—indicates automated deployment via WMI, consistent with a Metasploit-style framework. Multiple rundll32 instances per host (up to 20+ on base-wkstn-04) indicate repeated C2 callback injection.

LARIAT Consideration: The LARIAT (Lincoln Lab) testing framework is present on several affected systems but runs as Java processes under prunsrv.exe, completely distinct from the WMI→PowerShell→rundll32 chain. LARIAT cannot account for these artifacts.

Convergence: This finding is corroborated by independent sources—Volatility pstree (parent-child chains), cmdline (encoded commands), malfind (injected code in rundll32), and netscan (C2 connections from rundll32 PIDs).

Evidence strength:
2 refs
volatility.pstreevolatility.cmdlinevolatility.malfindvolatility.netscan

Evidence Chain

tc_782e4ed1 search 66ms
tc_66c827bb search 96ms
Time: 2018-09-06T17:43:45 — 2018-09-07T19:43:31
Sources: volatility.pstree, volatility.cmdline, volatility.malfind, volatility.netscan
Evidence Refs: tc_782e4ed1, tc_66c827bb
critical confirmed Environment-Wide C2 Proxy Tunneling via 172.16.4.10:8080 Across 7+ Systems

COUNTER-ANALYSIS NOTE: The proxy connections must be interpreted carefully. 172.16.4.10:8080 is the organizational web proxy used by ALL systems on this network for internet access. Systems connecting to this proxy include:
- Confirmed-clean forensic workstation (172.16.5.25) with 15+ connections
- Confirmed-clean admin workstation (172.16.5.26)
- Legitimate user workstations for web browsing

C2 Distinction:
Proxy connections alone do NOT prove C2. What distinguishes attacker C2 from legitimate browsing is the SOURCE PROCESS:
- SearchUI.exe (PID 9316 on 172.16.6.14) connecting to the proxy IS anomalous — Windows Search UI does not normally make HTTP proxy requests
- Injected PowerShell processes (with confirmed malfind shellcode) connecting to the proxy IS C2
- Chrome.exe, Edge, or svchost.exe connecting to the proxy is EXPECTED behavior

Corrected System List (confirmed C2 via process attribution):
- 172.16.6.11 (base-rd-02): PowerShell C2 chain with confirmed malfind
- 172.16.6.14 (base-wkstn-04): SearchUI.exe injection + 30+ connections
- 172.16.7.15 (base-wkstn-05): PowerShell C2 chain with confirmed malfind
- 172.16.4.5 (BASE-FILE): PowerShell PIDs 4072/3164 with confirmed C2 chain
- 172.16.6.13 (base-rd-06): CLOSE_WAIT connection + msadvapi2 present

Systems where proxy connections may be benign browsing:
- 172.16.5.25 (base-hunt): Forensic workstation — NOT compromised
- 172.16.5.26: Admin workstation — NOT compromised
- 172.16.5.20: Chrome browser — ambiguous without process injection evidence

The finding's core conclusion (C2 tunneled through legitimate proxy) remains valid for confirmed-compromised hosts where the connecting processes are attacker-controlled.

Evidence strength:
1 ref
volatility.netscanbulk.httplogs

Evidence Chain

tc_3b68cd88 search 152ms
Time: 2018-08-28T20:40:22
Sources: volatility.netscan, bulk.httplogs
Evidence Refs: tc_3b68cd88
ATT&CK: T1090, T1071.001
critical confirmed Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September)

COUNTER-ANALYSIS NOTE: IP address corrections applied. The original finding referenced "BASE-DC (172.16.4.1)" but the domain controller is at 172.16.4.4 per all other findings. Additionally, the claim of msadvapi2 on "base-wkstn-01 (172.16.7.16)" contains a hostname/IP mismatch — base-wkstn-01 is 172.16.7.11 in other findings, while 172.16.7.16 is identified as base-wkstn-02 in finding f_1c084ed7 (which shows NO msadvapi2 and NO compromise indicators).

Corrected Assessment:
Cross-system analysis reveals two distinct but potentially related intrusion campaigns:

Campaign 1 — msadvapi2 Backdoor (Pre-August 2018):
The msadvapi2_32.exe and msadvapi2_64.exe binaries (masquerading as "Microsoft Advanced API") deployed as Windows services across at least 3 confirmed systems:
- BASE-DC (172.16.4.4) — PID 1072, present since at least June 2018
- base-wkstn-03/base-rd-06 (172.16.6.13) — PIDs 2288/2304, since 2018-08-17 boot
- 172.16.6.15 — msadvapi2_64.exe running as service

DLL analysis shows wpcap.dll (packet capture) loading, consistent with network interception.

Campaign 2 — Metasploit/PowerShell (August-September 2018):
WMI→PowerShell→rundll32 attack chains deployed across 8+ systems using encoded commands with 64→32-bit process downgrade.

Assessment:
The co-existence on shared hosts suggests either a single actor with evolving TTPs, or a coordinated handoff. The msadvapi2 backdoor predates the Metasploit operations by 2+ months, establishing a persistent foothold before the more aggressive August-September lateral movement campaign.

Evidence strength:
2 refs
volatility.dlllistvolatility.cmdlinevolatility.pstreevolatility.netscanregistry.system

Evidence Chain

tc_57843b2b search 47ms
tc_66c827bb search 96ms
Time: 2018-06-04T20:19:30 — 2018-09-07T19:43:31
Sources: volatility.dlllist, volatility.cmdline, volatility.pstree, volatility.netscan, registry.system
Evidence Refs: tc_57843b2b, tc_66c827bb
high inference Data Staging via Rar.exe on File Server

Rar.exe (PID 2524) was observed executing on the file server (BASE-FILE) in a pattern consistent with data staging for exfiltration.

Process Details (from snapshot5 - earlier capture):
- PID 2524, PPID 6352 (cmd.exe, spawned from explorer.exe - interactive session)
- Started 2018-09-05 14:43:11
- 67 active threads in snapshot5, indicating active compression

Process Details (from base-file-memory - later capture):
- Same PID 2524, now showing ExitTime 2018-09-05 14:52:56
- Total runtime: approximately 10 minutes of compression activity

Context:
- The cmd.exe parent (PID 6352) was spawned from explorer.exe (PID 6452), indicating interactive user action during a logged-on session
- 10 minutes of active compression suggests a significant volume of data being archived
- File server contains substantial business data as evidenced by SMB connections from multiple hosts in the environment

This activity occurred within the broader attack timeline (Aug 28 - Sep 6, 2018) during which the PowerShell C2 chain and subject_srv.exe were active.

Affected Systems: ez.mft, volatility.psscan

Evidence strength:
4 refs
ez.mftvolatility.psscan

Evidence Chain

tc_2c193200 search 67ms
tc_37a409ca search 36ms
tc_ac657197 search 42ms
tc_ce81377a get_raw_output 9145ms
Time: 2018-09-05T14:43:11 — 2018-09-05T14:52:56
Sources: ez.mft, volatility.psscan
Evidence Refs: tc_2c193200, tc_37a409ca, tc_ac657197, tc_ce81377a
high confirmed Compromised SQL Service Account (spsql) Used for Domain Reconnaissance

The domain service account 'spsql' (SID S-1-5-21-3445421715-2530590580-3149308974-1193) was used to execute PowerView/PowerSploit reconnaissance scripts from base-file.shieldbase.lan on 2018-08-31.

Evidence of account compromise:
1. PowerShell Operational Event Log (Event ID 4104) shows ScriptBlock logging under spsql's SID executing PowerView functions including:
- Invoke-UserHunter (locating logged-in domain admins)
- Invoke-ShareFinder (enumerating accessible shares)
- Invoke-CheckLocalAdminAccess (identifying admin access on remote systems)
- Get-NetDomain, Get-NetForest (domain/forest enumeration)
- Invoke-MapDomainTrust, Get-ForeignGroup (trust mapping)
- Get-DNSRecord, Invoke-EnumerateLocalAdmin
- Invoke-ACLScanner (scanning for modifiable ACLs)

  1. MFT entries show Users\spsql profile directories being created/modified on 2018-08-31 21:54:13, contemporaneous with the PowerView execution (22:16-22:52)

  2. The spsql account is a SQL service account (suggested by name convention), which was weaponized for lateral reconnaissance — typical of attackers leveraging highly-privileged service accounts.

  3. Execution originated from base-file.shieldbase.lan, not the DC itself, indicating the attacker moved laterally to the file server and used the spsql account for domain-wide enumeration.

Evidence strength:
2 refs
evtx.windows_system32_winevt_logs_mic...ez.mft

Evidence Chain

tc_765d81e1 search 67ms
tc_492eb01e search 151ms
Time: 2018-08-31T21:54:13 — 2018-08-31T22:52:08
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, ez.mft
Evidence Refs: tc_765d81e1, tc_492eb01e
high inference YARA Signature Matches: Codoso/Deep Panda Tooling in DC Memory

COUNTER-ANALYSIS ASSESSMENT: The Codoso/Deep Panda YARA matches warrant careful evaluation. The "inference" confidence level is APPROPRIATE and should NOT be elevated to "confirmed."

Credible Detections (retained at inference):

Codoso_CustomTCP_4:
- "varus_service_x86.dll" at offset 0x6c6e4ce3 — a specific malware component name not found in legitimate software
- "net start %%1" / "net stop %%1" — service manipulation commands
- "ping 127.1 > nul" (3 instances) — delay technique
- Strings in close memory proximity suggest a single binary

DeepPanda_htran_exe:
- "-slave " — specific to htran tool syntax
- "[+] OK! I Closed The Two Socket." — htran-specific debug message

Why "inference" is correct, not "confirmed":
1. Attribution rests on a SINGLE detection tool (YARA) — no independent corroboration from network IOCs, domain registrations, or TTP-based attribution
2. htran is a publicly available tool used by multiple threat groups, not exclusively Codoso/Deep Panda
3. varus_service_x86.dll is more specific but a single string match doesn't constitute group attribution
4. The Tofu_Backdoor and IMPLANT_5_v3 matches lack detailed analysis of the matched byte sequences
5. No C2 domain or external IP has been linked to known Codoso/Deep Panda infrastructure

Assessment:
The YARA signatures confirm the PRESENCE of specific offensive tools (htran, a varus-named service DLL) in DC memory. These tools have historically been associated with Chinese APT groups including Codoso/Deep Panda. However, tool presence ≠ group attribution. The evidence supports "tools consistent with Codoso/Deep Panda TTPs" but falls short of confirmed attribution to that specific group.

The co-existence of msadvapi2 (persistent backdoor since June) + Metasploit (August-September operations) is consistent with known APT operational patterns (establishing persistent access, then conducting operations), but this pattern is not unique to any single group.

Evidence strength:
2 refs
yara.memory

Evidence Chain

tc_8c475b87 get_raw_output 4370ms
tc_1e007ec4 search 34ms
Time: 2018-08-28T22:08:25 — 2018-09-06T22:11:15
Sources: yara.memory
Evidence Refs: tc_8c475b87, tc_1e007ec4
high confirmed Extensive C2 and Lateral Movement Network Connections from base-rd-02

Network analysis of the base-rd-02 memory dump (IP: 172.16.6.11) reveals extensive C2 communications and lateral movement activity.

C2 Proxy Connections to 172.16.4.10:8080 (14+ connections):
ESTABLISHED:
- 172.16.6.11:49788 → 172.16.4.10:8080
- 172.16.6.11:49787 → 172.16.4.10:8080
- 172.16.6.11:49786 → 172.16.4.10:8080

CLOSE_WAIT (7 connections — indicating sustained C2 session teardowns):
- Ports 52703, 50253, 50263, 50259, 49774, 50257, 50254, 50258

CLOSED:
- Ports 63931, 49790, 49735

172.16.4.10:8080 is the same C2 proxy observed in the DC and file server compromises, confirming base-rd-02 is part of the same intrusion campaign.

RDP Outbound to File Server (172.16.4.5:3389) — 7 CLOSED connections:
- Ports 63826, 63834, 63958, 63848, 63823, 63841, 63835
- All CLOSED status, indicating multiple completed RDP sessions from base-rd-02 to the file server

SMB/445 Activity:
- 172.16.6.11:49763 → 172.16.4.5:445 ESTABLISHED (file server)
- 172.16.6.11:59352 → 172.16.7.15:445 ESTABLISHED
- Inbound: 172.16.6.14:65368 → 172.16.6.11:445 ESTABLISHED

WinRM/5985 Outbound:
- 172.16.6.11:49791 → 172.16.5.21:5985 CLOSED (remote PowerShell execution)

LDAP to Domain Controller:
- 172.16.6.11:56345 → 172.16.4.4:389 CLOSED

subject_srv.exe (F-Response forensic tool, port 3262):
- Listening on 0.0.0.0:3262 (PID 1096)
- 172.16.6.11:3262 → 172.16.5.50:39372 ESTABLISHED (forensic collection session)

External Connections:
- 172.16.6.11:49782 → 13.89.220.65:443 CLOSED (Microsoft Azure IP)
- 172.16.6.11:49360 → 52.16.55.11:443 CLOSED (Microsoft/cloud IP)

The 14+ connections to 172.16.4.10:8080, combined with the multiple RDP sessions to the file server and WinRM to 172.16.5.21, demonstrate that base-rd-02 was used as an active lateral movement pivot point in the attack campaign.

Affected Systems: bulk.httplogs, volatility.netscan, volatility.psscan

Evidence strength:
7 refs
bulk.httplogsvolatility.netscanvolatility.psscan

Evidence Chain

tc_049f2680 search 44ms
tc_164e59be get_raw_output 499ms
tc_18f35d85 search 472ms
tc_2e46e9f9 search 655ms
tc_5449cb1b get_raw_output 9026ms
tc_71a308b5 search 308ms
tc_f91b8518 search 116ms
Time: 2018-08-30T13:52:22 — 2018-09-06T18:28:32
Sources: bulk.httplogs, volatility.netscan, volatility.psscan
Evidence Refs: tc_049f2680, tc_164e59be, tc_18f35d85, tc_2e46e9f9, tc_5449cb1b, tc_71a308b5, tc_f91b8518
high confirmed Attacker Staging Directories with Malicious Tooling on base-rd-02

Multiple attacker staging directories were identified on base-rd-01 containing malicious tools:

1. c:\windows\temp\perfmon\ — Active Attack Staging Directory:
The primary implant p.exe (PID 8260) was deployed at c:\windows\temp\perfmon\p.exe, confirmed by cmdline output from volatility. An additional tool reference "c:\windows\temp\perfmon\sd." was found in ShimCache entries across multiple registry.system sources (source_ids 182, 202), confirming additional attacker tools were present in this directory. The "sd" filename is consistent with a service deployment tool (e.g., sd.exe for service management or lateral movement).

ShimCache evidence (from registry.system windows 625700 and 634542):
- c:\windows\temp\perfmon\sd. (truncated entry)
- Appears alongside system utilities like ipconfig.exe, systeminfo.exe, wmic.exe, taskkill.exe in the ShimCache ordering

2. C:\ProgramData\staging\install_wormhole\ — Software Deployment Staging:
An executable named install_msadvapi2_32.exe (14,183,796 bytes / ~14MB) was found at ProgramData\staging\install_wormhole\ in the MFT:
- Created: 2017-12-20 14:52:51
- Modified: 2018-05-08 21:07:43
- The file name "msadvapi2" mimics the legitimate Windows advapi32.dll
- ShimCache records show execution on 2018-05-08 21:07:43
- A related "Microsoft Advanced API 64" entry in ShimCache at C:\Program Files (x86)\Microsoft Advanced API 64\unins000.exe (2018-05-08 21:07:27) suggests this installs under a pseudo-legitimate directory name

The attacker used directories designed to blend with legitimate Windows components (perfmon = Performance Monitor, staging/install_wormhole = software deployment).

Evidence strength:
2 refs
ez.mftregistry.system

Evidence Chain

tc_3cce3174 search 54ms
tc_dd5b51dc search 37ms
Time: 2017-12-20T14:52:51 — 2018-09-06T17:26:35
Sources: ez.mft, registry.system
Evidence Refs: tc_3cce3174, tc_dd5b51dc
high confirmed C2 Network Connections from base-wkstn-01 to 172.16.4.10:8080

Base-wkstn-01 (IP 172.16.7.11) established 7 TCP connections to the known C2 proxy at 172.16.4.10:8080. All connections were in CLOSED state at memory capture time, indicating completed communication sessions. Source ports: 60085, 59703, 59511, 60121, 60001, 60167, 60117. This is the same C2 proxy address used across multiple compromised systems in the domain (file server, base-rd-02), confirming base-wkstn-01 was part of the same intrusion campaign. The connection pattern (multiple high ephemeral ports to a single destination on port 8080) is consistent with a reverse HTTPS or HTTP proxy used for command-and-control.

Evidence strength:
2 refs
volatility.netscanvolatility.cmdline

Evidence Chain

tc_fc085250 search 336ms
tc_e368fb48 get_raw_output 14189ms
Time: 2018-08-30T16:43:36 — 2018-09-06T17:26:35
Sources: volatility.netscan, volatility.cmdline
Evidence Refs: tc_fc085250, tc_e368fb48
ATT&CK: T1071.001, T1090
high confirmed Malicious Executable Dropped and Executed: c:\windows\temp\perfmon\p.exe

A suspicious executable named p.exe was dropped to c:\windows\temp\perfmon\ and executed on base-wkstn-01. Evidence from two independent sources:

  1. Volatility cmdline (memory): cmd.exe (PID 5948) executing "C:\WINDOWS\system32\cmd.exe /C c:\windows\temp\perfmon\p.exe" with child process p.exe (PID 8260) running.

  2. Registry ShimCache: Entry for "c:\windows\temp\perfmon\p.exe" with timestamp 2018-08-30 22:14:02, confirming file existence and execution on the filesystem.

The file location (Windows\Temp subdirectory), single-character filename, and execution via cmd.exe /C are consistent with attacker-dropped tools. The perfmon subdirectory name appears designed to blend with legitimate Windows Performance Monitor paths. The file was not found in the TSK file listing, suggesting it may have been deleted after use (anti-forensics).

Evidence strength:
2 refs
volatility.cmdlineregistry.system

Evidence Chain

tc_e368fb48 get_raw_output 14189ms
tc_bf8833b3 search 78ms
Time: 2018-08-30T22:14:02
Sources: volatility.cmdline, registry.system
Evidence Refs: tc_e368fb48, tc_bf8833b3
high confirmed Encoded PowerShell Stager Delivered to base-wkstn-01 via WinRM

A GZip-compressed PowerShell stager was delivered to base-wkstn-01 (172.16.7.11) via WinRM remoting at 2018-09-06 17:13:57. Evidence from PowerShell Operational Event Log (Event ID 4103):

The encoded command targeted -ComputerName 172.16.7.11 with a UTF-16LE encoded payload (PowerShell -EncodedCommand). Decoded payload:

$s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sIAAAAAAAAA..."))

The "H4sI" prefix identifies GZip-compressed data. This is the classic pattern used by post-exploitation frameworks (Metasploit, Empire, Cobalt Strike) to deliver compressed shellcode or scripts: Base64 decode → GZip decompress → Execute decompressed script via IEX.

The ScriptBlockId was 70ccb2b2-3c03-4d83-8a9c-e04f90151437. Additionally, earlier WinRM access was identified at 2018-08-22 04:50:38 from 172.16.5.25 (HTTP POST /wsman?PSVersion=5.1.14393.1944).

Evidence strength:
3 refs
evtx.windows_system32_winevt_logs_mic...bulk.httplogs

Evidence Chain

tc_a8a9cc62 search 335ms
tc_66186a53 decode_payload 26ms
tc_41d39d5d search 1949ms
Time: 2018-09-06T17:13:57
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational, bulk.httplogs
Evidence Refs: tc_a8a9cc62, tc_66186a53, tc_41d39d5d
high confirmed WMI-Based Remote Code Execution on base-wkstn-01

Memory forensics reveals a WMI-based remote code execution chain on base-wkstn-01:

  1. WmiPrvSE.exe (PID 8840): Running from C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe with "-Embedding" flag. The use of the 32-bit (SysWOW64) WMI provider is suspicious since the system is 64-bit. Additionally, PID 4936 and PID 11948 WmiPrvSE instances were running from the 64-bit path.

  2. PowerShell spawned by WMI: PID 5848 powershell.exe running from c:\windows\syswow64\windowspowershell\v1.0\powershell.exe with flags "-Version 5.1 -s -NoLogo -NoProfile". The NoProfile and NoLogo flags are standard post-exploitation framework indicators (avoid loading user profiles, reduce output).

  3. rundll32 spawned by PowerShell: PID 6768 rundll32.exe (empty cmdline) is a child of the PowerShell process, representing shellcode injection.

This WmiPrvSE → PowerShell → rundll32 chain is the canonical execution pattern for WMI-based lateral movement used by Metasploit's wmi_exec and Cobalt Strike's WMI execution methods.

Evidence strength:
2 refs
volatility.cmdlinevolatility.pstree

Evidence Chain

tc_e368fb48 get_raw_output 14189ms
tc_afe3d00b search 95ms
Time: 2018-08-30T16:43:36
Sources: volatility.cmdline, volatility.pstree
Evidence Refs: tc_e368fb48, tc_afe3d00b
high confirmed Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21

Base-wkstn-01 (172.16.7.11) had an active ESTABLISHED WinRM connection to 172.16.5.21:5985 (port 56150) at the time of memory capture. Three additional CLOSED WinRM connections to the same destination were also present (ports 56149, 56137, 56148), indicating sustained WinRM session activity.

Additionally, inbound WinRM access from 172.16.5.25 was captured:
- 2018-08-22 04:50:38: HTTP POST /wsman?PSVersion=5.1.14393.1944 from 172.16.5.25:52783 to 172.16.7.11:5985

The workstation was both a recipient of WinRM-based attacks (receiving encoded PowerShell commands) AND an origin point for outbound WinRM lateral movement to 172.16.5.21. An RPC connection to the domain controller (172.16.4.4:135) was also observed (port 56133, CLOSED).

Evidence strength:
2 refs
volatility.netscanbulk.httplogs

Evidence Chain

tc_fc085250 search 336ms
tc_41d39d5d search 1949ms
Time: 2018-08-22T04:50:38
Sources: volatility.netscan, bulk.httplogs
Evidence Refs: tc_fc085250, tc_41d39d5d
ATT&CK: T1021.006, T1570
high confirmed PowerView Active Directory Reconnaissance from Compromised Systems

PowerShell Operational logs (Event ID 4103) captured PowerView reconnaissance script execution at 2018-08-31 22:16:12. The logged script blocks contain PowerView function signatures including:

  • "SearchTerm, Term to search for, default of 'pass'" - searching user descriptions for passwords
  • "SearchField, User field to search, default of 'description'" - targeting AD user description fields
  • "ADSpath, The LDAP source to search through, e.g. 'LDAP://OU=secret,DC=testlab,DC=local'" - LDAP enumeration

This is PowerView's Find-UserField function from the PowerSploit framework, commonly used by attackers to search Active Directory user account description fields for plaintext passwords - a common misconfiguration where administrators store passwords in the description field.

The timestamp (2018-08-31 22:16:12) falls within the attack window when multiple systems were compromised via WMI and WinRM lateral movement. This reconnaissance activity was captured across multiple PowerShell log sources (source IDs 74, 75, 81, 82, 86), confirming it was logged on multiple systems in the domain.

Evidence strength:
1 ref
evtx.windows_system32_winevt_logs_mic...

Evidence Chain

tc_b4fab9f2 search 80ms
Time: 2018-08-31T22:16:12
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
Evidence Refs: tc_b4fab9f2
high confirmed Rundll32 Process Injection for Post-Exploitation on base-wkstn-05

The active C2 PowerShell session (PID 1332, WoW64/32-bit) on base-wkstn-05 spawned multiple short-lived rundll32.exe processes consistent with Metasploit/Cobalt Strike process migration and module injection.

Short-lived rundll32.exe instances spawned by PowerShell PID 1332:
- PID 5300: 2018-08-31 01:31:44 – 01:31:46 (2 seconds lifetime)
- PID 5056: 2018-08-31 20:23:08 – 20:23:29 (21 seconds)
- PID 4240: 2018-08-31 20:23:17 – 20:23:35 (18 seconds)
- PID 1972: 2018-08-31 20:23:52 – 20:23:56 (4 seconds)
- PID 3720: 2018-08-31 21:07:21 – 21:07:28 (7 seconds)

Long-running persistent rundll32.exe:
- PID 7100 (PPID 7148): Started 2018-08-31 18:43:50, NO exit time — still running at memory capture. 5 threads, 337 handles.

The short-lived rundll32.exe instances (2-21 seconds) are characteristic of Metasploit's process injection technique where rundll32.exe is spawned as a sacrificial process, shellcode is injected into its address space, and it either completes its task or fails and exits. The long-running PID 7100 with 337 handles suggests a persistent implant module (e.g., keylogger, screenshot capture, or lateral movement module) that maintained execution throughout the investigation period.

This pattern — PowerShell downgrade → rundll32 injection — matches the Metasploit post/multi/manage/shell_to_meterpreter module behavior observed on other systems in this investigation.

Affected Systems: volatility.cmdline, volatility.psscan

Evidence strength:
3 refs
volatility.cmdlinevolatility.psscan

Evidence Chain

tc_2c5eaec1 search 126ms
tc_4e21d89f search 507ms
tc_e368fb48 get_raw_output 14189ms
Time: 2018-08-31T01:31:44 — 2018-09-06T19:37:40
Sources: volatility.cmdline, volatility.psscan
Evidence Refs: tc_2c5eaec1, tc_4e21d89f, tc_e368fb48
high confirmed WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation

HTTP logs on the DMZ FTP server (172.16.10.12) show WebDAV access from internal workstation 172.16.5.26 to administrative shares, indicating lateral movement or administrative file operations.

WebDAV Access Events:
1. 2018-09-07 02:46:37 - OPTIONS /c$ from 172.16.5.26 via Microsoft-WebDAV-MiniRedir/10.0.16299 (Windows 10 Fall Creators Update)
2. 2018-09-07 05:21:52 - OPTIONS /srl-ftp from 172.16.5.26 via Microsoft-WebDAV-MiniRedir/10.0.16299

Significance:
- The /c$ path is the hidden administrative share mapping to the C: drive, requiring administrator-level credentials
- WebDAV access to admin shares provides full filesystem access to the server from a remote machine
- The User-Agent string identifies a Windows 10 workstation (build 16299/Fall Creators Update)
- The srl-ftp directory contains the suspected Cobalt Strike stager (sub-win-x64_base-hunt_5682_3262.exe) and forensic response tools

Context: The same internal IP (172.16.5.26) also authenticated via FTP as dblake and performed RETR operations on /Users/ paths on 2018-08-07. This workstation appears to have been used for both legitimate FTP access and administrative operations against the DMZ FTP server.

Evidence strength:
2 refs
bulk.domainbulk.httplogs

Evidence Chain

tc_6fe1de22 search 548ms
tc_16188147 search 25ms
Time: 2018-09-07T02:46:37 — 2018-09-07T05:21:52
Sources: bulk.domain, bulk.httplogs
Evidence Refs: tc_6fe1de22, tc_16188147
high confirmed WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All Compromised Subnets

Network analysis of the 172.16.5.21 memory dump reveals this system was the convergence point for WinRM-based lateral movement from ALL compromised hosts in the environment. Inbound WinRM (port 5985) connections were observed from:

Active ESTABLISHED WinRM sessions at capture time:
- 172.16.7.11:55308 → 172.16.5.21:5985 (base-wkstn-01)
- 172.16.4.4:57252 → 172.16.5.21:5985 (Domain Controller)
- 172.16.4.5:61707 → 172.16.5.21:5985 (File Server / BASE-FILE)

CLOSED WinRM sessions (completed):
- 172.16.7.16:57202 → 172.16.5.21:5985
- 172.16.6.14:55115 → 172.16.5.21:5985
- 172.16.7.15:61537 → 172.16.5.21:5985 (base-wkstn-05)

Other network activity:
- subject_srv.exe (F-Response, PID 9908) listening on port 3262, deployed 2018-09-07 19:35:23
- 172.16.5.21:3262 → 172.16.5.50:51490 ESTABLISHED (F-Response evidence collection)
- 172.16.5.21:53384 → 172.16.4.5:445 ESTABLISHED (SMB to file server)
- 172.16.5.21:52018 → 172.16.5.20:443 CLOSED

Significance:
All six source IPs connecting via WinRM to this system are confirmed compromised hosts (base-wkstn-01, base-wkstn-05, DC, file server) or are in subnets with confirmed compromised systems (172.16.6.14, 172.16.7.16). The attacker used WinRM from every compromised pivot point to access 172.16.5.21, making it a primary target or management host in the attack campaign. The cbarton-a account was also observed conducting remote PowerShell reconnaissance against this system on 2018-08-15 17:00-17:07 via wsmprovhost.exe -Embedding.

Evidence strength:
2 refs
volatility.netscan

Evidence Chain

tc_aeae3c99 get_raw_output 720ms
tc_3808d8ea search 171ms
Time: 2018-08-15T17:00:39
Sources: volatility.netscan
Evidence Refs: tc_aeae3c99, tc_3808d8ea
ATT&CK: T1021.006, T1570
high confirmed Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System

A previously unreported compromised system at 172.16.6.15 was discovered during continued analysis. The system shows the identical Metasploit/post-exploitation attack pattern observed across other compromised hosts in the shieldbase.lan domain.

Compromise Evidence:
- powershell.exe (PID 20780) spawned by PID 17016 at 2018-08-31 01:00:30
- Running from SysWOW64 (32-bit architecture downgrade, T1059.001)
- Command: powershell.exe -nop -w hidden -encodedcommand [base64]
- Decoded payload follows Metasploit stager pattern: $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sI...")); IEX (New-Object IO.StreamReader(New-Object IO.Compression.GzipStream($s,[IO.Compression.CompressionMode]::Decompress))).ReadToEnd()
- This is the EXACT same GZip-compressed, base64-encoded PowerShell stager seen on other compromised systems (BASE-FILE, base-wkstn-01, base-wkstn-05, base-rd-02)

System Profile (172.16.6.15):
- Windows Server (boot: 2018-06-04 20:19:20)
- McAfee endpoint protection deployed (VirusScan Enterprise, Host Intrusion Prevention, ePO Agent)
- Puppet Labs agent (mcollective) communicating with 10.10.254.1:61613
- Nagios NCPA monitoring agent
- LARIAT (Lincoln Lab) java application with external connections (24.59.13.39, 104.96.34.39)
- RDP enabled (port 3389)
- Autorunsc.exe was run on 2018-08-15 (possible forensic triage)

Suspicious Binary:
- msadvapi2_64.exe running from C:\Program Files (x86)\Microsoft Advanced API 64\ as a service (child of services.exe PID 664)
- "Microsoft Advanced API" is NOT a legitimate Microsoft product name
- The binary name mimics Windows advapi32.dll (Advanced Windows 32 Base API)
- This warrants further malware analysis

Network Context:
- java.exe (PID 1736) connections to external IPs 24.59.13.39 and 104.96.34.39 (CLOSED state)
- McAfee management on port 8081
- No observed connection to C2 proxy 172.16.4.10:8080 in netscan data

Evidence strength:
2 refs
volatility.pstreevolatility.netscan

Evidence Chain

tc_0dcee2c9 search 381ms
tc_ed6dcd46 search 344ms
Time: 2018-08-31T01:00:30
Sources: volatility.pstree, volatility.netscan
Evidence Refs: tc_0dcee2c9, tc_ed6dcd46
high confirmed SearchUI.exe Shellcode Injection with C2 Connection to 172.16.4.10:8080

On the system at 172.16.6.14, SearchUI.exe (PID 9316) contains injected shellcode in a PAGE_EXECUTE_READWRITE memory region (VadS). The injected code contains x64 assembly prologue bytes (H\x89T$\x10H\x89L$\x08) and what appears to be a Metasploit-style shellcode decoder stub (\xfc\xe8\x04\x00\x00\x00), which is characteristic of the CLD; CALL $+4 pattern used by Metasploit's block_api and reverse_tcp payloads.

Network analysis confirms SearchUI.exe had an active connection to 172.16.4.10:8080 in CLOSE_WAIT state, consistent with a completed C2 communication session. This IP:port combination (172.16.4.10:8080) has been identified as C2/proxy infrastructure across multiple compromised systems in this investigation.

SearchUI.exe is a legitimate Windows Search UI process that should never contain executable shellcode or connect to internal web proxy infrastructure. The combination of malfind shellcode detection and active C2 network connection confirms process injection was used to establish a covert communication channel.

Evidence strength:
2 refs
volatility.malfindvolatility.netscan

Evidence Chain

tc_d6159c69 search 116ms
tc_bf72b446 search 1803ms
Time: 2018-08-29T22:01:00
Sources: volatility.malfind, volatility.netscan
Evidence Refs: tc_d6159c69, tc_bf72b446
high confirmed Process Injection in PowerShell on SearchUI System (172.16.6.14)

On the system at 172.16.6.14, in addition to the SearchUI.exe shellcode injection (separate finding), powershell.exe (PID 5452) contains injected Metasploit shellcode. Malfind analysis (source_id 398) shows the process has a VadS region with PAGE_EXECUTE_READWRITE protection containing the bytes: \xfc\xe8\x04\x00\x00\x00 - the classic Metasploit block_api shellcode prologue (CLD followed by CALL $+4 to find the return address on the stack).

The complete disassembly pattern shows: fc (CLD), e8 04 00 00 00 (CALL +4), 2c 95 (SUB AL, 0x95), 33 99 (XOR EBX, [ECX]), eb 27 (JMP +0x27), 5f (POP EDI) - this is a known Metasploit encoded payload decoder stub.

This confirms that the threat actor deployed Metasploit payloads on this system, injecting into both SearchUI.exe (PID 9316, with C2 to 172.16.4.10:8080) and PowerShell (PID 5452). The dual injection across processes suggests the attacker maintained redundant access channels.

Evidence strength:
2 refs
volatility.malfind

Evidence Chain

tc_6535f63e search 27374ms
tc_d6159c69 search 116ms
Time: 2018-09-06T17:43:45
Sources: volatility.malfind
Evidence Refs: tc_6535f63e, tc_d6159c69
high confirmed BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21)

Network analysis of BASE-FILE (172.16.4.5, source_id 7) reveals an outbound WinRM connection from 172.16.4.5:56281 to 172.16.5.21:5985 (CLOSED state), initiated by svchost.exe (PID 928). This demonstrates that the previously compromised BASE-FILE server was used as a pivot point to access the msadvapi2-infected system via Windows Remote Management.

This connection chain establishes lateral movement between the compromised file server infrastructure and the msadvapi2 backdoor system:
- BASE-FILE (172.16.4.5) → WinRM (5985) → 172.16.5.21 (msadvapi2 system)

Additionally, the msadvapi2 system (172.16.5.21) also received inbound WinRM from 172.16.7.16 (separate finding), indicating multiple systems were used to access this machine remotely.

BASE-FILE also shows SMB connections to multiple systems (172.16.5.20, 172.16.6.11, 172.16.7.12), consistent with its role in the attacker's lateral movement infrastructure. The WinRM-based lateral movement is consistent with the WMI/PowerShell attack patterns observed across this campaign.

Affected Systems: volatility.netscan, volatility.pslist

Evidence strength:
3 refs
volatility.netscanvolatility.pslist

Evidence Chain

tc_0b8ecc5e search 1996ms
tc_0d5ab1cf search 493ms
tc_59d084a3 search 107ms
Time: 2018-08-28T22:08:25
Sources: volatility.netscan, volatility.pslist
Evidence Refs: tc_0b8ecc5e, tc_0d5ab1cf, tc_59d084a3
high confirmed base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection

The system identified as base-rd-06 (IP 172.16.6.13, R&D subnet) shows confirmed compromise with multiple indicators:

Backdoor Installation:
- msadvapi2_32.exe (PID 2288) running as a service under services.exe (PID 764) since 2018-08-17 13:46:31 from C:\Program Files (x86)\Microsoft Advanced API 32\
- msadvapi2_64.exe (PID 2304) running as a service under services.exe (PID 764) since 2018-08-17 13:46:31 from C:\Program Files (x86)\Microsoft Advanced API 64\
- Both are masquerading as "Microsoft Advanced API" — a fabricated name designed to blend with legitimate Microsoft binaries

C2 Communication:
- CLOSE_WAIT connection from 172.16.6.13:50093 → 172.16.4.10:8080 (organizational web proxy used as C2 relay)
- This matches the same C2 infrastructure observed across other compromised systems

Lateral Movement Evidence:
- RDP connection FROM 172.16.6.14:50663 → 172.16.6.13:3389 (CLOSED) — the attacker moved between R&D systems
- SMB connection to BASE-FILE server: 172.16.6.13:49889 → 172.16.4.5:445 (ESTABLISHED) — possible data access/staging
- WinRM listening on port 5985 — enabled for remote management

System Context:
- Windows 10 VM (VMware Tools present), boot time 2018-08-17 13:46:17
- McAfee endpoint security suite running (AV did not detect the msadvapi2 backdoor)
- LARIAT test framework (Lincoln Lab) present: prunsrv.exe PID 2136 → java.exe PID 2844
- Puppet configuration management agent running
- F-Response forensic agent deployed 2018-09-06 19:03:59

System Identification Note: This system is identified as base-rd-06 based on its location in the R&D subnet (172.16.6.x), being one of the four target memory dumps, and the F-Response deployment for the same investigation. The hostname was not directly confirmed in indexed evidence.

Evidence strength:
2 refs
volatility.pstreevolatility.netscan

Evidence Chain

tc_5880fc44 get_raw_output 673ms
tc_9afbec68 get_raw_output 703ms
Time: 2018-08-17T13:46:31
Sources: volatility.pstree, volatility.netscan
Evidence Refs: tc_5880fc44, tc_9afbec68
medium inference Remote PowerShell Reconnaissance by cbarton-a on base-rd-02

COUNTER-ANALYSIS NOTE: The cbarton-a remote PowerShell session on 2018-08-15 should be evaluated in the context of concurrent IR indicators.

Evidence of Concurrent IR Activity on 2018-08-15:
- Autorunsc.exe was executed on 172.16.6.15 on the same date (2018-08-15), consistent with Sysinternals-based IR triage
- The commands executed by cbarton-a (process enumeration via WMI, network adapter info, directory listing) are exactly what an incident responder would run during initial triage
- cbarton-a is referenced in Kerberos principals alongside other admin accounts (VPN infrastructure), suggesting a legitimate admin role

Commands Executed (all consistent with IR triage):
- Get-ChildItem -Force -Path "C:\WINDOWS\..." (directory enumeration — checking for suspicious files)
- WMI queries against \\BASE-RD-01\root\cimv2:Win32_Process (process listing — checking for malicious processes)
- Add-Member operations querying Username and NT AUTHORITY\SYSTEM processes (identifying process owners)
- Network adapter information gathering about 172.16.6.11 (network configuration review)

Assessment:
The most likely interpretation is that cbarton-a is an IT administrator who conducted initial IR triage on 2018-08-15, approximately two weeks before the main Metasploit deployment wave (Aug 27-31). The alignment with Autorunsc execution and the nature of the commands strongly favor the "legitimate admin" interpretation over "attacker using compromised credentials." However, this cannot be confirmed without access to HR/IT records identifying cbarton-a's role.

If cbarton-a IS a legitimate admin, this suggests the organization was aware of potential compromise by August 15 — before the main offensive operations escalated in late August.

Evidence strength:
1 ref
evtx.windows_system32_winevt_logs_mic...

Evidence Chain

tc_eca43fd9 search 60ms
Time: 2018-08-15T16:36:39 — 2018-08-15T16:36:39
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
Evidence Refs: tc_eca43fd9
medium inference User Account tdungan Compromised — Active Session During Attack on base-rd-02

The primary user account on base-rd-01 is shieldbase\tdungan, who maintained an active interactive session during the entire attack period. The following user accounts were observed interacting with base-rd-01:

1. shieldbase\tdungan (Primary User):
- Active desktop session with rich application set: Outlook (PID 8128), OneDrive, Chrome, Dashlane password manager
- RDP sessions were LOCAL logons (console access)
- User profile paths confirm as primary workstation user
- The attack ran silently in Session 0 via WMI while tdungan's interactive session continued in a separate session — the user likely had no visibility into the compromise

2. shieldbase\Administrator:
- Multiple LOCAL RDP sessions recorded in Terminal Services logs
- Used for system administration tasks

3. shieldbase\cbarton-a:
- Remote PowerShell session via WinRM on 2018-08-15 16:32-16:36 UTC
- Performed system reconnaissance (process enumeration, directory listing, network info)
- User profile (MFT record 154919) exists with AppData under Users\cbarton-a
- This admin account warrants investigation for potential compromise

4. shieldbase\jpallen:
- Profile referenced in ShimCache entries (C:\Users\jpallen\AppData\Local\Microsoft...)
- Appears to be an additional user account that previously logged into this system

No evidence of unauthorized account creation was found in the indexed event logs. The Windows Security event log was not indexed for base-rd-01, limiting visibility into authentication events (logon type 3/10 from remote systems).

Evidence strength:
2 refs
volatility.cmdlineevtx.windows_system32_winevt_logs_mic...ez.mft

Evidence Chain

tc_2bb544be search 787ms
tc_294f8623 search 2210ms
Time: 2018-08-15T16:32:11 — 2018-09-06T17:26:35
Sources: volatility.cmdline, evtx.windows_system32_winevt_logs_microsoft-windows-terminalservices-localsessionmanager4operational, ez.mft
Evidence Refs: tc_2bb544be, tc_294f8623
ATT&CK: T1078
medium confirmed External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs

The DMZ FTP server (IIS FTPSVC2 on 172.16.10.12, port 21) was targeted by brute force credential attacks from multiple external IP addresses. All attempts resulted in 530 (authentication failure) responses.

Attacker IPs and Targeted Accounts:
- 221.151.127.218: Targeted "administrator" account - multiple 530 failures
- 95.47.155.87: Targeted "stark-r" account - multiple 530 failures
- 138.197.213.41: Targeted "rsydow-a" account on 2018-08-16 04:19-04:20 - rapid-fire brute force with dozens of attempts in seconds
- 146.185.222.48: FTP scanning on multiple dates
- 185.255.31.2: FTP scanning on 2018-08-31
- 58.62.55.130, 60.212.42.56, 164.52.24.165, 61.153.54.38: Additional brute force/scanning sources on 2018-08-08 through 2018-08-10

Pattern Analysis: The attack on 138.197.213.41 showed the most aggressive pattern - rapid repeated USER/PASS sequences targeting the rsydow-a account with sub-second intervals, characteristic of automated credential stuffing tools. The targeting of "stark-r" and specific user accounts suggests pre-enumeration of usernames.

Failed Internal Authentication: 172.16.7.11 attempted and failed to authenticate as "dblake" on 2018-08-08 13:24:09 (530 failure), which may indicate lateral movement attempts from a compromised internal host.

None of the external brute force attempts appear to have succeeded based on the available evidence.

Evidence strength:
2 refs
bulk.domain

Evidence Chain

tc_29561007 search 608ms
tc_16188147 search 25ms
Time: 2018-08-08T00:00:01 — 2018-08-31T23:59:59
Sources: bulk.domain
Evidence Refs: tc_29561007, tc_16188147
medium inference FTP Log Files Deleted - Potential Evidence Destruction on DMZ FTP Server

Two IIS FTP log files from the FTPSVC2 service on DMZ-FTP (172.16.10.12) were deleted, as identified by TSK file listing (deleted entries marked with *):

Deleted Logs:
- u_ex180805.log (August 5, 2018) - deleted, inode marked with * prefix
- u_ex180823.log (August 23, 2018) - deleted, inode marked with * prefix

Context: The FTP log directory (inetpub/logs/LogFiles/FTPSVC2/) contains daily logs spanning from u_ex180728.log through u_ex180907.log. The two deleted files create gaps in the logging timeline:
- Gap 1: August 5, 2018 - during the early investigation period
- Gap 2: August 23, 2018 - mid-incident window

All other daily log files in the sequence are intact. The selective deletion of only two log files, rather than all logs, suggests intentional evidence destruction targeting specific dates of interest rather than routine log rotation. IIS log rotation typically does not delete old files; it creates new ones daily.

These deleted logs may have contained evidence of unauthorized access or data exfiltration during the deleted time periods. The dates fall within the active brute force and scanning window (August 2018).

Evidence strength:
1 ref
tsk.filelist

Evidence Chain

tc_cfba6703 search 49ms
Time: 2018-08-05T00:00:01
Sources: tsk.filelist
Evidence Refs: tc_cfba6703
ATT&CK: T1070.002
medium inference FTP Data Exfiltration of User Profile Directories from DMZ FTP Server

FTP logs show data retrieval operations targeting user profile directories on the DMZ FTP server (172.16.10.12) from internal workstation 172.16.5.26.

Evidence from carved FTP logs:
- 2018-08-07 23:30:07 - RETR /Users/ operations from 172.16.5.26 with data channel activity (DataChannelOpened)
- Multiple DataChannel operations around 23:30-23:36 on 2018-08-07
- 2018-08-07 23:32:23 - dblake authenticated successfully (PASS *** 230) from 172.16.5.26
- Additional FTP operations continued through 23:36

Carved Email Reference: ftp--dblake@ftp.stark-research-labs.com-Users-nfury-Asg... suggests FTP path access into the Users/nfury/ directory structure, indicating user nfury's files were accessed.

Related Activity: The dblake account was also used from Azure IP 40.121.0.91 on 2018-08-10 for FTP operations (TYPE A, PORT commands).

Concern: The RETR operations on /Users/ directories, particularly targeting nfury's profile, indicate file downloads from user directories. This is consistent with either legitimate file retrieval or data staging/exfiltration, depending on whether these operations were authorized. The activity from an internal workstation during late evening hours (23:30 UTC) warrants investigation.

Evidence strength:
2 refs
bulk.domainbulk.email

Evidence Chain

tc_16188147 search 25ms
tc_29561007 search 608ms
Time: 2018-08-07T23:30:07 — 2018-08-07T23:36:45
Sources: bulk.domain, bulk.email
Evidence Refs: tc_16188147, tc_29561007
ATT&CK: T1039, T1005
medium confirmed External FTP User rsydow-f Authenticated with Cleartext Password Exposure

FTP logs reveal that user rsydow-f authenticated to the DMZ FTP server (172.16.10.12) from two external IP addresses, with the password captured in cleartext in the logs.

Authentication Events:
1. 2018-07-16 21:08 - rsydow-f authenticated from 108.79.235.64 with password "mprsydow@mail.com" (230 success)
- Followed by PORT and data channel operations at 21:09
- Password visible in cleartext in carved FTP log entry

  1. 2018-09-03 18:20:25 - Activity from 165.227.50.129 with password "asdfa" (response code in log)
  2. SYST command executed (215 response)
  3. Additional PORT and DataChannel operations at 18:21:35

  4. 2018-09-05 16:37:28-18:47:48 - rsydow-f authenticated from 165.227.50.129 as DMZ-FTP\rsydow-f

  5. Active data channel operations (DataChannelOpened/Closed)
  6. Session persisted for over 2 hours

User Profile: The rsydow-a user profile exists on the server at Users/rsydow-a/ with Downloads directory created 2018-08-07T19:05:25 and PowerShell ModuleAnalysisCache present (MFT entry 33601), indicating interactive logon activity.

Security Concern: The FTP password (mprsydow@mail.com) is logged in cleartext, violating credential protection best practices. The use of an email address as a password represents poor credential hygiene. The rsydow account accessed the server from multiple external IPs across multiple dates.

Evidence strength:
2 refs
bulk.domain

Evidence Chain

tc_ab2a13f3 search 208ms
tc_6492ef7f search 112ms
Time: 2018-07-16T21:08:00 — 2018-09-05T18:47:48
Sources: bulk.domain
Evidence Refs: tc_ab2a13f3, tc_6492ef7f
medium confirmed Interactive User Access via rsydow-a Account on DMZ FTP Server

The rsydow-a user account has an interactive local profile on the DMZ FTP server (172.16.10.12) with evidence of active system usage, suggesting interactive logon access beyond FTP.

User Profile Evidence (from tsk.filelist and ez.mft):
- Full user profile directory at Users/rsydow-a/ with standard AppData structure
- rsydow-a Downloads directory created: 2018-08-07T19:05:25 (MFT)
- PowerShell ModuleAnalysisCache present (MFT entry 33601) - generated only when PowerShell runs interactively
- AppData/Roaming/Microsoft/Protect/CREDHIST file present - credential protection history, populated during interactive logon
- Network Connections phonebook (rasphone.pbk) present

External FTP Access by rsydow Account:
- rsydow-f authenticated successfully from 108.79.235.64 on 2018-07-16 (password: mprsydow@mail.com)
- rsydow-f authenticated from 165.227.50.129 on 2018-09-03 through 2018-09-05
- 138.197.213.41 attempted brute force against rsydow-a on 2018-08-16 (all failed)

Significance: The presence of an interactive user profile (PowerShell cache, CREDHIST) for rsydow-a indicates this account was used for RDP, console, or other interactive logon sessions, not merely FTP access. The rsydow-a/rsydow-f accounts appear related (possibly the same person using different account names for local vs FTP access). The Downloads directory creation date (2018-08-07) aligns with the period of active attacker interest in this server.

Evidence strength:
2 refs
tsk.filelistez.mftbulk.domain

Evidence Chain

tc_cfba6703 search 49ms
tc_29561007 search 608ms
Time: 2018-07-16T21:08:00 — 2018-09-05T18:47:48
Sources: tsk.filelist, ez.mft, bulk.domain
Evidence Refs: tc_cfba6703, tc_29561007
ATT&CK: T1078.003
medium confirmed SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs

Bulk_extractor carved data reveals a SoftEther VPN Server running on 172.16.1.20, providing external remote access to the shieldbase.lan network. Multiple external IP addresses connected via VPN:

External VPN connections identified:
- 108.79.235.64: Connected via MSRASV5.20, associated with account rsydow-f (same IP used for FTP access to DMZ-FTP server)
- 144.121.9.222: Connected to SoftEther VPN Server
- 65.114.90.19: SoftEther VPN connection
- 107.107.185.201: SoftEther VPN connection
- 166.172.120.210: MSRASV connection
- 40.121.0.91: Azure IP associated with dblake FTP access (from DMZ FTP finding)

VPN User Accounts:
- NFury: VPN account (referenced as "NFury" in VPN logs at 172.16.1.20)
- rsydow: VPN account
- cbarton: Kerberos principal cbarton@SHIELDBASE.LAN

Security Implications:
The SoftEther VPN provides a legitimate pathway for external access that the attacker could leverage. The rsydow-f account accessing both FTP and VPN services from 108.79.235.64 suggests this may be a legitimate remote worker. However, the VPN infrastructure provides external entry that could have been used for initial access if credentials were compromised. The FTP brute force attempts against rsydow-a from 138.197.213.41 (separate from the VPN IP) suggest the attacker was aware of this account's existence.

Network Context:
The VPN server at 172.16.1.20 bridges external users into the 172.16.x.x corporate network, providing a potential initial access vector if VPN credentials were compromised through phishing, credential stuffing, or reuse from the FTP password exposure (mprsydow@mail.com).

Evidence strength:
1 ref
bulk.domain

Evidence Chain

tc_a99601d8 search 89ms
Time: 2018-07-16T21:08:00
Sources: bulk.domain
Evidence Refs: tc_a99601d8
ATT&CK: T1133, T1078
medium inference Suspicious rundll32.exe on base-mail Exchange Server (PID 15116)

On the base-mail Exchange server (172.16.4.6, boot 2018-08-30 21:27:22), a long-running rundll32.exe process (PID 15116) was identified running in Session 0 (system context) since 2018-08-31 19:47:10. The process runs as WoW64 (32-bit on 64-bit OS) and was spawned by an unknown parent (PPID 15896, which has exited).

DLL analysis (source_id 407) shows PID 15116 loads network-related libraries including rsaenh.dll (RSA encryption), napinsp.dll, mswsock.dll, GDI32.dll, and win32u.dll. This DLL combination is unusual for a legitimate rundll32.exe invocation. The command line for this process was not captured in the cmdline output, which may indicate it was launched with cleared command-line arguments.

Timeline context: This rundll32.exe started approximately 24 minutes after an RDP session began (2018-08-31 19:23:54, Session 2). The RDP session includes rdpclip.exe, explorer.exe, iexplore.exe, ServerManager, and PowerShell (PID 5144). The close temporal proximity suggests the rundll32.exe may have been deployed during this RDP session.

While base-mail does not show direct C2 connections to 172.16.4.10:8080, the pattern of a long-running Session 0 rundll32.exe with no visible command line is consistent with post-exploitation implant behavior seen on other compromised systems in this investigation.

Evidence strength:
1 ref
volatility.pslistvolatility.dlllistvolatility.psscanvolatility.cmdlinevolatility.malfind

Evidence Chain

tc_32e6cd38 search 119ms
Time: 2018-08-31T19:47:10
Sources: volatility.pslist, volatility.dlllist, volatility.psscan, volatility.cmdline, volatility.malfind
Evidence Refs: tc_32e6cd38
ATT&CK: T1218.011, T1055
medium inference Chrome.exe C2 Proxy Connection and Code Injection on System 172.16.5.20

COUNTER-ANALYSIS NOTE: This finding requires cautious interpretation.

Chrome.exe C2 Connections — Ambiguous:
Chrome.exe (PID 7300) connecting to 172.16.4.10:8080 and :80 is EXPECTED behavior on this network. The 172.16.4.10 system is the organizational web proxy used by ALL systems in the environment (including the confirmed-clean forensic workstation at 172.16.5.25 and admin workstation at 172.16.5.26). Chrome browser traffic through a web proxy is normal, not inherently a C2 indicator. Without evidence of Chrome being injected with malicious code or generating unusual traffic patterns (beaconing intervals, encoded payloads), Chrome's proxy connection alone does not confirm C2.

Malfind Detections — Require Scrutiny:
- MsDtsSrvr.exe (PID 1208): SQL Server Integration Services runtime. SSIS executes .NET code including dynamic compilation, which can legitimately produce RWX memory regions for JIT compilation. This detection is LIKELY a false positive without examination of the actual memory content.
- sqlceip.exe (PID 2184): SQL Server Customer Experience Improvement Program telemetry. .NET-based process with expected JIT RWX regions.
- explorer.exe (PID 1396): This detection is more concerning as explorer.exe does not typically require large RWX regions. However, without examining the hex dump for shellcode patterns (NOP sleds, call stubs), this remains ambiguous.

Assessment:
The finding remains at "inference" confidence. The Chrome proxy connection is NOT evidence of C2 by itself. The explorer.exe malfind is the strongest indicator but lacks corroboration from other sources (no PowerShell stager, no WMI chain observed on this system). This finding is individually weak but is noted as part of the broader pattern — the system is on the same subnet as confirmed compromised systems and had SMB connectivity from BASE-FILE.

Evidence strength:
2 refs
volatility.netscanvolatility.malfind

Evidence Chain

tc_bf72b446 search 1803ms
tc_6535f63e search 27374ms
Time: 2018-08-28T20:40:22
Sources: volatility.netscan, volatility.malfind
Evidence Refs: tc_bf72b446, tc_6535f63e
medium inference base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Exposure

Memory forensics of base-sp (172.16.4.7) reveals a Microsoft SharePoint Server with potentially suspicious PowerShell activity.

SharePoint Server Identification:
- IP: 172.16.4.7
- SharePoint service ports: 808 (SharePoint app server) and 22233 (SharePoint Search service) with multiple active local connections
- Multiple self-referential connections (172.16.4.7:808 ↔ 172.16.4.7:50xxx) are normal SharePoint inter-component communication
- plasrv.exe (PID 12636) running on port 58661 (Performance Logs & Alerts)

Suspicious PowerShell Activity:
- powershell.exe (PID 7520) created 2018-08-02 05:04:03 with active UDP connections (both IPv4 and IPv6)
- This PowerShell process was actively creating network connections, which could indicate:
a) Legitimate SharePoint administration via PowerShell
b) Post-exploitation activity (Metasploit/Empire stager)
- The timestamp (2018-08-02 05:04 UTC, early morning) warrants investigation for authorized activity

Network Exposure:
- WinRM (port 5985) LISTENING - accessible for remote management
- SMB (port 445) LISTENING
- No direct C2 connections to 172.16.4.10:8080 observed in available netscan data
- The server is on the same subnet (172.16.4.x) as the compromised file server (172.16.4.5), domain controller (172.16.4.4), and Exchange server (172.16.4.6)

Context:
- Admin workstation 172.16.5.26 RDP'd to "base-sp" at 2018-08-25 23:25:36 (from finding f_4cb0d525)
- Being on the 172.16.4.x server subnet, base-sp was within direct reach of the attacker who had compromised the DC and file server
- Without indexed EVTX Security logs from this server, authentication events and potential lateral movement TO this system cannot be fully assessed

Assessment:
The PowerShell process (PID 7520) on the SharePoint server at 2018-08-02 05:04 UTC is suspicious but without additional context (cmdline not captured, no EVTX), it cannot be confirmed as malicious. The server's WinRM exposure and subnet placement make it a high-value lateral movement target.

Evidence strength:
2 refs
volatility.netscanvolatility.pstree

Evidence Chain

tc_0eb9ba08 search 757ms
tc_85169414 search 1868ms
Time: 2018-08-02T05:04:03 — 2018-09-06T10:11:41
Sources: volatility.netscan, volatility.pstree
Evidence Refs: tc_0eb9ba08, tc_85169414
low inference sub-win-x64_base-hunt_5682_3262.exe — Likely F-Response Subject Agent Binary, Not Cobalt Strike Stager

COUNTER-ANALYSIS CORRECTION: The filename components strongly suggest this is an F-Response forensic tool binary, not a Cobalt Strike stager.

F-Response Interpretation (PREFERRED):
- "sub" = F-Response "Subject" agent (the subject_srv.exe binary deployed on target systems)
- "win-x64" = Windows x64 platform variant
- "base-hunt" = The F-Response management workstation hostname (confirmed at 172.16.5.25, running license_ctrl.exe on port 5682)
- "5682" = F-Response license controller port (confirmed: PID 1716 on base-hunt listening on port 5682)
- "3262" = F-Response subject agent port (confirmed: subject_srv.exe listens on port 3262 across all deployed systems)

The file resides in the srl-ftp directory alongside fresponse-agent.msi (the F-Response installer) and Mnemosyne.sys (a forensic driver), consistent with an IR tool staging location.

Remaining Concern — Timestamp Anomaly:
MFT analysis shows $SI Created (2013-08-22) predates $FN timestamps (2018-08-09) by 5 years. This could indicate:
a) Timestomping by an attacker who placed a malicious file alongside IR tools
b) The file was extracted from a signed/versioned installer package that preserved original build timestamps
c) Filesystem metadata inconsistency during file copy or extraction

At 4,246 bytes, the file size is consistent with both a small stager AND a minimal agent executable.

Assessment:
Given the strong filename correlation to F-Response port parameters (5682/3262 exactly match confirmed F-Response infrastructure), the co-location with other F-Response tools, and the absence of any evidence this file was executed maliciously, the Cobalt Strike interpretation is LESS likely than the F-Response interpretation. The timestamp anomaly prevents full dismissal but is not sufficient alone to override the naming evidence. Severity downgraded from high to low.

Original MITRE mappings removed: T1059.001 (no execution evidence), T1036.006, T1070.006 (timestamp anomaly preserved as a note).

Evidence strength:
2 refs
ez.mfttsk.filelisttsk.icat

Evidence Chain

tc_cfba6703 search 49ms
tc_d3126b8b extract_file_by_inode 328ms
Time: 2018-08-09T17:42:39 — 2018-08-09T17:42:40
Sources: ez.mft, tsk.filelist, tsk.icat
Evidence Refs: tc_cfba6703, tc_d3126b8b
low inference base-wkstn-02 (172.16.7.16) - Active Workstation with LARIAT but No Direct Compromise Indicators in Memory

Memory forensics of base-wkstn-02 (172.16.7.16, dual-homed 10.10.150.177) reveals an actively used Windows 10 workstation. System boot time: ~2018-09-03 13:51.

Legitimate User Activity:
- OUTLOOK.EXE (PID 3044): Multiple ESTABLISHED connections to Exchange server (172.16.4.6:80) - confirmed OWA/Exchange access
- firefox.exe (PID 3656): Active browser session with connections to 104.88.80.153:443 (SYN_SENT) and localhost loopback (port 7055, 49429)
- SMB to file server: 172.16.7.16:49236 → 172.16.4.5:445 ESTABLISHED

LARIAT Framework Present:
- java.exe (PID 1752/5040) running LARIAT with connections to 10.10.200.207:5672 (RabbitMQ AMQP)
- LARIAT java processes connected to multiple external IPs in CLOSED state: 24.139.91.27, 88.197.234.24, 104.201.158.26, 216.232.147.26, 248.86.12.27
- LARIAT ncpa_passive.exe (PID 2784) listening on localhost:49299

Infrastructure Services:
- McAfee Agent (masvc.exe PID 1824), macmnsvc.exe (PID 1744) on port 8081/8082
- Puppet Labs rubyw.exe (PID 5796) → 10.10.254.1:61613 ESTABLISHED
- subject_srv.exe (PID 488, F-Response) on port 3262 → 172.16.5.50:46980 ESTABLISHED

Assessment:
- No Metasploit/Empire PowerShell stager detected
- No msadvapi2 backdoor present
- No C2 connections to 172.16.4.10:8080 observed
- No WMI→PowerShell attack chain observed
- No malfind code injection detections specific to this system
- Previous WinRM connection from this IP to 172.16.5.21:5985 was observed (CLOSED state in 172.16.5.21's memory), but this could have been initiated by the attacker using compromised credentials rather than indicating this workstation itself was compromised

This system appears to be a legitimate workstation that was accessible to the attacker via WinRM but does not show active compromise at the time of memory capture.

Evidence strength:
2 refs
volatility.netscanvolatility.pstree

Evidence Chain

tc_d8c74751 search 675ms
tc_bc36392e get_raw_output 200ms
Time: 2018-09-03T13:51:03 — 2018-09-06T13:51:20
Sources: volatility.netscan, volatility.pstree
Evidence Refs: tc_d8c74751, tc_bc36392e
info confirmed subject_srv.exe Identified as F-Response Forensic Remote Acquisition Agent (Not Malicious)

CORRECTION: subject_srv.exe has been identified as the F-Response Subject agent, a legitimate forensic remote acquisition tool — NOT malicious activity.

Conclusive Evidence:
The command line for subject_srv.exe (PID 1096 on base-rd-02, PID 6160 on file server) reads:
C:\windows\subject_srv.exe -s "base-hunt.shieldbase.lan:5682" -l 3262 -v "F-Response Subject" -k "155522845"

The "-v F-Response Subject" parameter identifies this as the F-Response forensic acquisition agent. F-Response is a commercial forensic tool that provides remote access to systems for evidence collection. The "base-hunt.shieldbase.lan" server name suggests a forensic investigation workstation.

Expected Behavior Explained:
- Installed in C:\windows\ — F-Response deploys its agent to the Windows directory
- Running as WoW64 (32-bit) — F-Response Subject agent is a 32-bit binary
- Listening on non-standard port 3262 — this is the F-Response access port specified by -l flag
- Outbound to 172.16.5.50 — the forensic examiner's workstation conducting evidence collection
- Running as a service from services.exe — F-Response installs as a Windows service for persistence during evidence collection
- Present since 2018-04-10 — consistent with a previously deployed forensic investigation capability or an earlier investigation

Assessment:
All indicators previously assessed as suspicious are consistent with legitimate F-Response deployment. This finding supersedes the original assessment. The YARA Codoso/Deep Panda matches previously associated with subject_srv.exe should be evaluated independently of this binary.

Previous MITRE ATT&CK mappings (T1543.003, T1036) are removed as this is legitimate software.

Evidence strength:
3 refs
volatility.psscanvolatility.netscanregistry.systemtsk.filelist

Evidence Chain

tc_839221cf extract_file_by_inode 240ms
tc_b83a24d3 scan_hidden_processes 15ms
tc_9b859299 search 31ms
Time: 2018-04-10T19:29:48
Sources: volatility.psscan, volatility.netscan, registry.system, tsk.filelist
Evidence Refs: tc_839221cf, tc_b83a24d3, tc_9b859299
info confirmed YARA Memory Scan: APT6 Detections Assessed as False Positives

YARA memory scanning produced 233 windows of APT6_Malware_Sample_Gen matches across the memory dumps. Upon examination of the matched strings, these detections are assessed as FALSE POSITIVES rather than evidence of APT6 malware.

The matched strings are generic and commonly found in legitimate Windows binaries and system memory:
- "shellcode" - generic string found in many security tools and documentation
- "synflood", "udpflood" - networking terms found in system libraries
- "C:\WINDOWS\system32\" - common Windows system path prefix
- Other generic byte patterns common in system DLLs

These strings individually and collectively do not indicate the presence of APT6 malware. The YARA rule APT6_Malware_Sample_Gen appears to use overly broad signatures that match common system artifacts.

While the DC IS compromised (as evidenced by the C2 channel, PowerView execution, and Meterpreter-style code injection), the YARA matches do not provide attribution to APT6 or any specific threat actor. The attack TTPs (PowerView, WMI, Meterpreter, Rar.exe staging) are widely used across criminal and nation-state groups.

Evidence strength:
1 ref
yara.memory

Evidence Chain

tc_b83a24d3 scan_hidden_processes 15ms
Sources: yara.memory
Evidence Refs: tc_b83a24d3
info confirmed Shadow Copy Enumeration via PowerShell on File Server — Likely Administrative Activity, Not Ransomware Preparation

COUNTER-ANALYSIS CORRECTION: The Win32_ShadowCopy PowerShell activity originally characterized as "Shadow Copy Manipulation" and "ransomware preparation" has been re-assessed as shadow copy enumeration by an administrator or incident responder.

Corrected Evidence Analysis:
The PowerShell Operational Log (Event ID 4103, 2018-08-31 21:53:03) captures:
1. Get-CimInstance -ClassName win32_ShadowCopy — This is a READ/QUERY operation, NOT a deletion command. The Delete() method or Remove-CimInstance cmdlet are NOT present.
2. ForEach-Object { write "VSC created $($_.installdate) for host $($_.Servicemachine)" } — This simply DISPLAYS the creation date and service machine for each shadow copy. This is diagnostic output, not manipulation.
3. The user executing this was shieldbase\rsydow-a via WinRM (Host Application: wsmprovhost.exe -Embedding), NOT spsql as originally reported. rsydow-a appears to be an administrator or incident responder.

NetFirewallRule Module Loading:
The co-occurring NetFirewallRule module content (Export-ModuleMember for Show-NetFirewallRule, Rename-NetFirewallRule) is automatic PowerShell module loading, not explicit firewall manipulation.

Assessment:
This activity is consistent with routine administrative shadow copy auditing or incident response reconnaissance. The original T1490 (Inhibit System Recovery) mapping is removed as no evidence of shadow copy deletion exists. The original finding significantly overstated the threat level.

MITRE ATT&CK mapping removed: T1490 (no deletion evidence), T1562.004 (no firewall manipulation evidence). Retaining T1059.001 for PowerShell execution only.

Evidence strength:
2 refs
evtx.windows_system32_winevt_logs_mic...

Evidence Chain

tc_5df21172 search 56ms
tc_9a2617bb search 119ms
Time: 2018-08-31T21:53:03
Sources: evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational
Evidence Refs: tc_5df21172, tc_9a2617bb
ATT&CK: T1059.001
info confirmed Cross-System Comparison: F-Response Agent (subject_srv.exe) Deployed Between Memory Captures — IR Activity, Not Attacker Persistence

COUNTER-ANALYSIS CORRECTION: The original finding framed subject_srv.exe deployment as the attacker "installing a persistent backdoor service" as a final step in the attack chain. This is INCORRECT — finding f_5bcb1c4e conclusively identifies subject_srv.exe as the F-Response forensic remote acquisition agent deployed by incident responders.

Corrected Timeline:
The deployment of subject_srv.exe between Snapshot5 (~2018-09-05 15:03) and Base-file-memory (~2018-09-06 19:25) represents the IR team deploying F-Response for forensic evidence collection, NOT an attacker establishing persistence.

Valid Observations (Retained):
- Snapshot5 captured active attacker operations: Rar.exe data staging (PID 2524), PowerShell C2 chain (PIDs 4072/3164)
- Base-file-memory captured post-IR-deployment state with F-Response active and attacker artifacts still resident in memory
- The PowerShell C2 chain remained active across both captures, confirming sustained attacker presence
- Rar.exe completed execution between captures (exited 2018-09-05 14:52:56)

Impact on Attack Timeline:
The subject_srv.exe deployment milestone should be removed from the attacker kill chain. The actual attacker timeline on BASE-FILE remains: WMI C2 initiation (Aug 28) → rundll32 injection (Aug 30-Sep 6) → data staging via Rar.exe (Sep 5).

MITRE mapping corrected: T1543.003 removed (subject_srv.exe is IR tooling, not attacker persistence). T1560.001 retained for Rar.exe staging.

Evidence strength:
3 refs
volatility.psscanvolatility.netscan

Evidence Chain

tc_37a409ca search 36ms
tc_dd06c588 search 30ms
tc_d9eff5a7 search 925ms
Time: 2018-09-05T14:06:04 — 2018-09-06T22:11:15
Sources: volatility.psscan, volatility.netscan
Evidence Refs: tc_37a409ca, tc_dd06c588, tc_d9eff5a7
ATT&CK: T1560.001
info confirmed Network IOC Summary: Internal C2 Infrastructure and Lateral Movement Targets

Analysis of network connections from memory dumps and disk artifacts reveals the following IOCs and network architecture:

Compromised Hosts (10+ systems):
- 172.16.4.5 (BASE-FILE) - Active C2 implant, data staging, Rar.exe exfil prep
- 172.16.4.4 (BASE-DC) - Domain controller, YARA Codoso/Deep Panda tool signatures
- 172.16.5.21 - WinRM convergence point, msadvapi2 backdoor, cross-subnet pivot
- 172.16.5.20 - Web/DB server, Chrome C2 proxy connections, process injection
- 172.16.6.11 (base-rd-02) - Metasploit stager, p.exe implant, C2 via proxy
- 172.16.6.13 (base-wkstn-03/base-rd-06) - msadvapi2 + Metasploit dual compromise
- 172.16.6.14 (base-wkstn-04) - Interactive C2, SearchUI.exe injection, 30+ proxy connections
- 172.16.6.15 - msadvapi2_64 + Metasploit stager
- 172.16.7.15 (base-wkstn-05) - 3 WMI attack chains, rundll32 injection
- 172.16.7.16 (base-wkstn-01) - WMI stager, WinRM encoded command delivery

C2/Proxy Infrastructure:
- 172.16.4.10:8080 - Web proxy used for C2 tunneling (7+ compromised hosts connect)

Lateral Movement Hub:
- 172.16.5.21:5985 - WinRM convergence from all compromised subnets

Legitimate Infrastructure (Not Compromised):
- 172.16.5.25 (base-hunt) - F-Response forensic workstation
- 172.16.5.50 - F-Response evidence collection endpoint
- 172.16.5.26 (admin workstation) - SSH/RDP admin access, no compromise indicators
- 172.16.4.6 (base-mail) - Exchange server, suspicious rundll32 but no confirmed C2
- 172.16.4.7 (base-sp) - SharePoint, suspicious PowerShell but unconfirmed

External IOCs:
- 108.79.235.64 - rsydow-f FTP/VPN access (likely legitimate remote worker)
- 138.197.213.41 - Aggressive brute force against rsydow-a FTP account
- 221.151.127.218, 95.47.155.87, 146.185.222.48, 185.255.31.2 - FTP scanning/brute force
- 172.16.1.20 - SoftEther VPN server (external access gateway)

Evidence strength:
4 refs
volatility.netscanvolatility.psscantsk.filelist

Evidence Chain

tc_18f35d85 search 472ms
tc_fc7bb189 search 26ms
tc_f91b8518 search 116ms
tc_65ace770 extract_file_by_inode 219ms
Sources: volatility.netscan, volatility.psscan, tsk.filelist
Evidence Refs: tc_18f35d85, tc_fc7bb189, tc_f91b8518, tc_65ace770
ATT&CK: T1071, T1090, T1021
info confirmed Timestomping Analysis: No Malicious Timestamp Manipulation Detected

Analysis of $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT data detected only 2 timestomping entries across both disk images. Both were root directory entries (likely OS installation artifacts) and showed no indicators of malicious timestamp manipulation.

Forensic Note:
Despite the absence of timestomping detections, the attacker used other defense evasion techniques:
- Placing subject_srv.exe in C:\windows\ to blend with legitimate system files
- Using legitimate tools (PowerShell, rundll32, WMI) for attack operations (Living off the Land)
- Tunneling C2 traffic through the web proxy at 172.16.4.10:8080
- Shadow Copy manipulation to prevent recovery

The lack of timestomping may indicate that the attacker did not attempt to modify file timestamps, or that the tools used (which are primarily memory-resident) didn't require timestamp manipulation for persistence.

Evidence strength:
1 ref
ez.mft

Evidence Chain

tc_1cb6496c search 29ms
Sources: ez.mft
Evidence Refs: tc_1cb6496c
ATT&CK: T1070.006
info confirmed YARA Disk Scan: Snake Malware Detection Assessed as False Positive on base-rd-02

YARA scanning of the base-rd-02 disk image (base-rd-02-cdrive.E01) produced a single rule match: APT_MAL_RU_WIN_Snake_Malware_May23_1. Upon examination of the matched strings, this detection is assessed as a FALSE POSITIVE.

Matched Strings:
- $a: 25 73 23 31 → hex for "%s#1" (a generic format specifier)
- $b: 25 73 23 32 → hex for "%s#2" (a generic format specifier)

Multiple offset matches were found across the disk image at various locations. These format strings ("%s#1", "%s#2") are extremely common in Windows binaries and are used for string formatting operations. They do not indicate the presence of Snake/Uroburos malware.

Context:
- The same false positive occurred on the base-rd-01 disk image with identical matched strings
- No other YARA rules triggered on the base-rd-02 disk image
- The real compromise on base-rd-02 was identified through memory forensics (PowerShell C2 chain, p.exe implant, malfind hits) rather than disk-based signatures
- The attacker's tools on base-rd-02 were primarily memory-resident, explaining the limited disk-based signature matches

Assessment:
The Snake Malware YARA rule uses overly broad format string signatures that match common Windows binary patterns. No evidence of Snake/Uroburos malware was found on base-rd-02.

Evidence strength:
1 ref
yara.files

Evidence Chain

tc_ad6b5e9b search 44ms
Sources: yara.files
Evidence Refs: tc_ad6b5e9b
info confirmed DMZ FTP Server Configuration - IIS FTPSVC2 on Windows Server 2012 R2

The DMZ FTP server is identified as:

System Identity:
- Hostname: DMZ-FTP
- IP Address: 172.16.10.12
- Domain: shieldbase.lan (Stark Research Labs)
- Operating System: Windows Server 2012 R2 (kernel version 6.3.x per MFT entries)

FTP Service Configuration:
- Software: Microsoft IIS FTP Service (FTPSVC2, version 8.5.0.0 per carved package data)
- Log Directory: inetpub/logs/LogFiles/FTPSVC2/
- FTP Logs: Daily rotation files from u_ex180728.log through u_ex180907.log
- IIS HTTP (W3SVC1): Also running with logs at inetpub/logs/LogFiles/W3SVC1/
- Web Root: inetpub/wwwroot/ with default IIS content (iisstart.htm, iis-85.png)

FTP User Accounts Identified:
- dblake (DMZ-FTP\dblake): Legitimate user, accessed from Azure (40.121.0.91) and internal (172.16.5.26)
- rsydow-f (DMZ-FTP\rsydow-f): External user, accessed from 108.79.235.64 and 165.227.50.129
- rsydow-a: User profile exists at Users/rsydow-a/ with interactive session evidence (PowerShell cache, Downloads directory created 2018-08-07)
- anonymous: Attempted from 172.16.5.26, authentication failed

FTP Content Directory (srl-ftp):
- fresponse-agent.msi: Forensic response tool, created 2018-09-07T20:57:23
- Mnemosyne.sys: Likely forensic driver/tool
- sub-win-x64_base-hunt_5682_3262.exe: Suspicious executable (see separate finding)
- test.txt: Test file

Network Exposure: The FTP server on port 21 was accessible from external internet addresses, with brute force attempts observed from multiple countries.

Evidence strength:
3 refs
tsk.filelistez.mftbulk.domain

Evidence Chain

tc_cfba6703 search 49ms
tc_16188147 search 25ms
tc_ab2a13f3 search 208ms
Sources: tsk.filelist, ez.mft, bulk.domain
Evidence Refs: tc_cfba6703, tc_16188147, tc_ab2a13f3
info confirmed Unindexed EVTX Event Logs on DMZ FTP Server - Analysis Gap

The DMZ FTP server disk image contains Windows Event Log files that were not extracted or indexed during the initial processing phase. This creates an analysis gap for several investigation questions.

Event Logs Present on Disk (from TSK file listing):
- Archive-Security-2018-08-08-08-57-05-737.evtx
- Archive-Security-2018-08-20-00-56-16-595.evtx
- Archive-Security-2018-08-23-23-18-50-784.evtx
- Additional Security archive files
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Multiple other Microsoft-Windows-* operational and admin logs
- PowerShell operational logs

Impact on Investigation:
Without these logs indexed, the following questions cannot be fully answered for the DMZ FTP server:
- Unauthorized account creation or privilege escalation
- Detailed authentication events (logon types, source workstation names)
- Event log clearing/tampering (Event IDs 1102, 104)
- Scheduled task creation or modification (persistence)
- PowerShell execution history
- Service installation events

Recommendation: Run EVTX extraction (run_evtx_parser) on /evidence/dmz-ftp-cdrive.E01 and index the Security, System, PowerShell, and TaskScheduler logs to complete the investigation.

Evidence strength:
1 ref
tsk.filelist

Evidence Chain

tc_7a5f7db9 search 2461ms
Sources: tsk.filelist
Evidence Refs: tc_7a5f7db9
info confirmed 172.16.5.25 Identified as Forensic Workstation (base-hunt) with 15+ C2 Proxy Connections

Memory analysis confirms 172.16.5.25 is the forensic investigation workstation "base-hunt.shieldbase.lan", running the F-Response management suite and AccessData FTK Imager. However, the system shows 15+ connections to the C2 proxy at 172.16.4.10:8080 which warrant documentation.

Forensic Tool Processes:
- license_ctrl.exe (PID 1716): F-Response license controller, listening on port 5682
- subject_ctrl.exe (PID 7076): F-Response subject controller
- connector_ctrl.exe (PID 6868): F-Response connector controller
- imager_ctrl.exe (PID 3324): F-Response imager controller
- license_monitor (PID 4272): F-Response license monitor
- main_console.exe (PID 6960): F-Response main console
- FTK Imager.exe (PID 928): AccessData forensic imager, started 2018-09-06 18:48:20
- ftusbsrvc.exe (PID 4916): FTK USB service on port 33001
- ruby.exe (PIDs 2240, 6780, 8116): F-Response backend (Ruby-based)

Network Connections to C2 Proxy 172.16.4.10:8080:
6 CLOSE_WAIT connections (ports 63084, 63082, 63039, 63036, 64358, 62946)
3 CLOSED connections (ports 58926, 58928, 58917, 58927, 58932, 58937, 58938, 58939, 58940)
Total: 15+ connections

External Connection:
- 172.16.5.25:64720 → 108.79.235.64:33000 ESTABLISHED

Assessment:
While the C2 proxy connections COULD represent legitimate web browsing through the organizational proxy by the forensic examiner, the CLOSE_WAIT state on 6 connections is notable (indicating the remote side closed but local cleanup didn't complete). The connection to 108.79.235.64:33000 is likely related to the F-Response USB service (port 33001 vs 33000) or remote evidence collection. Given this is the forensic workstation, these connections are assessed as likely benign but should be verified with the incident response team.

Evidence strength:
2 refs
volatility.psscanvolatility.netscan

Evidence Chain

tc_94019da7 get_raw_output 748ms
tc_aeae3c99 get_raw_output 720ms
Sources: volatility.psscan, volatility.netscan
Evidence Refs: tc_94019da7, tc_aeae3c99
info inference Exchange Server (172.16.4.6) Memory Dump - No C2 Indicators but Accessible to Attacker

A Microsoft Exchange Server at 172.16.4.6 was captured in memory during the investigation. While no direct C2 indicators (connections to 172.16.4.10:8080) or WMI→PowerShell attack chains were found, the server is on the same subnet as compromised systems and accessible to the attacker.

Exchange Server Configuration:
- IP: 172.16.4.6 (also 10.10.4.6 dual-homed)
- Services: MSExchangeFrontend, EdgeTransport, MSExchangeSubmission, MSExchangeDelivery, MSExchangeMailboxAssistants, MSExchangeRepl, MSExchangeHMHost, MSExchangeHMWorker, ForefrontActive (anti-spam)
- Multiple w3wp.exe IIS worker processes serving OWA/EWS
- noderunner.exe (Exchange search indexing)
- hostcontroller process
- Boot time: 2018-08-30 21:27:31

Network Connections:
- Multiple LDAP connections to DC (172.16.4.4:389 and :3268) - expected Exchange behavior
- SMB connection to DC (172.16.4.4:445) - expected
- HTTP (port 80) ESTABLISHED from 172.16.7.16 - OWA web access
- powershell.exe (PID 5144) connected to DC LDAP and localhost:890 - likely Exchange Management Shell
- subject_srv.exe (F-Response, PID 17880) on port 3262 → 172.16.5.50 (forensic collection)

Assessment:
The Exchange server does not show the characteristic WMI→PowerShell→rundll32 attack chain or C2 proxy connections observed on other compromised systems. However, with domain admin credentials compromised and the attacker having full AD control, the Exchange server's email contents would have been accessible. The powershell.exe process (PID 5144) warrants further investigation but may be legitimate Exchange Management Shell. No Security EVTX logs were indexed for this system.

Evidence strength:
1 ref
volatility.netscan

Evidence Chain

tc_14375e22 get_raw_output 776ms
Time: 2018-08-30T21:27:31
Sources: volatility.netscan
Evidence Refs: tc_14375e22
info confirmed base-wkstn-06 (172.16.5.26) — Admin Workstation with Extensive Infrastructure Access, No Compromise Indicators

Memory forensics of base-wkstn-06 (172.16.5.26, boot 2018-07-29 12:55:18) identifies a Windows 10 administrative workstation in the 172.16.5.x management subnet. Despite extensive access to critical infrastructure, no indicators of compromise were found.

System Profile:
- Active user session with PuTTY SSH sessions to multiple infrastructure hosts:
- @base-elk (ELK stack), @onion-master (3 sessions), @proxy, @dmz-smtp, @dmz-dns
- RDP sessions via mstsc.exe to:
- /v:"base-sp" (SharePoint server, 2018-08-25 23:25:36)
- /v:"base-dc" (Domain Controller, 2018-09-01 17:23:44)
- Puppet configuration management agent (rubyw.exe PID 3800 → 10.10.254.1:61613 ActiveMQ)
- SMB to file server 172.16.4.5:445 ESTABLISHED (since 2018-08-09)
- notepad++ and MicrosoftEdge present in process tree

Negative Findings (No Compromise):
- No Metasploit/Empire PowerShell stagers or encoded commands detected
- No msadvapi2 backdoor present
- No WMI → PowerShell → rundll32 attack chain observed
- No connections to C2 proxy 172.16.4.10:8080
- No malfind code injection detections
- No suspicious rundll32.exe processes with empty command lines

WebDAV Activity to DMZ FTP Server:
Previously documented (finding f_954b7adf): this IP accessed /c$ and /srl-ftp via WebDAV on DMZ-FTP (172.16.10.12) on 2018-09-07. The dblake account from this IP also performed FTP operations including file retrieval from /Users/ directories.

Assessment:
base-wkstn-06 is a legitimate IT administrator workstation with broad infrastructure access (DC, ELK, DNS, SMTP, proxy, SharePoint) that was NOT compromised during the attack campaign. Its proximity to compromised systems in the domain and its elevated access privileges would have made it a high-value target. The absence of compromise indicators, despite the attacker having domain admin access and the ability to deploy WMI/WinRM attacks to any system, may indicate the attacker either did not target this specific workstation or had not yet reached it before incident response began.

Evidence strength:
2 refs
volatility.pstreevolatility.netscanvolatility.pslist

Evidence Chain

tc_c3c902c7 search 50ms
tc_ca6adb56 search 28ms
Time: 2018-07-29T12:55:18 — 2018-09-07T05:21:52
Sources: volatility.pstree, volatility.netscan, volatility.pslist
Evidence Refs: tc_c3c902c7, tc_ca6adb56
0
Techniques
0
Tactics
0
Findings Mapped
Reconnaissance
Resource Development
Initial Access5
Execution5
Persistence6
Privilege Escalation8
Defense Evasion15
Credential Access3
Discovery7
Lateral Movement6
Collection4
Command and Control4
Exfiltration
Impact
Inhibit Response Function
Evasion
Impair Process Control
Initial Access
Valid Accounts
2F
Default Accounts
1F
Domain Accounts
2F
Local Accounts
1F
External Remote Services
1F
Execution
Windows Management Instrumentation
10F
Command and Scripting Interpreter
2F
PowerShell
17F
Windows Command Shell
2F
Native API
1F
Persistence
Valid Accounts
2F
Default Accounts
1F
Domain Accounts
2F
Local Accounts
1F
External Remote Services
1F
Windows Service
4F
Privilege Escalation
Process Injection
3F
Dynamic-link Library Injection
3F
Process Hollowing
8F
Valid Accounts
2F
Default Accounts
1F
Domain Accounts
2F
Local Accounts
1F
Windows Service
4F
Defense Evasion
Obfuscated Files or Information
5F
Masquerading
1F
Match Legitimate Resource Name or Location
7F
Process Injection
3F
Dynamic-link Library Injection
3F
Process Hollowing
8F
Clear Linux or Mac System Logs
1F
Timestomp
1F
Valid Accounts
2F
Default Accounts
1F
Domain Accounts
2F
Local Accounts
1F
Deobfuscate/Decode Files or Information
2F
Rundll32
8F
Hide Artifacts
1F
Credential Access
Password Guessing
1F
Password Spraying
1F
Credentials In Files
1F
Discovery
System Network Configuration Discovery
1F
Remote System Discovery
1F
Process Discovery
1F
Domain Groups
2F
Domain Account
4F
Network Share Discovery
1F
Domain Trust Discovery
1F
Lateral Movement
Remote Services
1F
Remote Desktop Protocol
2F
SMB/Windows Admin Shares
3F
Windows Remote Management
12F
Exploitation of Remote Services
1F
Lateral Tool Transfer
3F
Collection
Data from Local System
1F
Data from Network Shared Drive
1F
Local Data Staging
4F
Archive via Utility
3F
Command and Control
Application Layer Protocol
2F
Web Protocols
7F
Proxy
10F
Internal Proxy
1F
0
Total IOCs
0
External IPs
0
File IOCs
0
Emails
Network IOCs (89)
TypeValueEnrichmentContextActions
Internal IP 172.16.4.10 PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser VT
Port TCP 8080 PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser
Internal IP 172.16.4.5 PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser VT
Internal IP 172.16.6.11 WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11) VT
Port TCP 49788 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49787 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49786 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 3389 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49763 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 445 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 59352 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Internal IP 172.16.7.15 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Internal IP 172.16.6.14 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Port TCP 65368 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49791 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Internal IP 172.16.5.21 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Port TCP 5985 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 56345 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Internal IP 172.16.4.4 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Port TCP 389 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 3262 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Internal IP 172.16.5.50 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Port TCP 39372 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49782 Extensive C2 and Lateral Movement Network Connections from base-rd-02
External IP 13.89.220.65 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Port TCP 443 Extensive C2 and Lateral Movement Network Connections from base-rd-02
Port TCP 49360 Extensive C2 and Lateral Movement Network Connections from base-rd-02
External IP 52.16.55.11 Extensive C2 and Lateral Movement Network Connections from base-rd-02 VT
Internal IP 172.16.6.15 Remote PowerShell Reconnaissance by cbarton-a on base-rd-02 VT
Internal IP 172.16.7.11 C2 Network Connections from base-wkstn-01 to 172.16.4.10:8080 VT
Internal IP 172.16.5.25 Encoded PowerShell Stager Delivered to base-wkstn-01 via WinRM VT
Port TCP 52783 Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21
Port TCP 135 Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21
Port TCP 56150 Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21
Port TCP 56133 Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21
Internal IP 172.16.10.12 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 221.151.127.218 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 95.47.155.87 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 138.197.213.41 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 146.185.222.48 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 185.255.31.2 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 58.62.55.130 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 60.212.42.56 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 164.52.24.165 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
External IP 61.153.54.38 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs VT
Port TCP 21 External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs
Internal IP 172.16.5.26 WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation VT
External IP 40.121.0.91 FTP Data Exfiltration of User Profile Directories from DMZ FTP Server VT
External IP 108.79.235.64 External FTP User rsydow-f Authenticated with Cleartext Password Exposure VT
External IP 165.227.50.129 External FTP User rsydow-f Authenticated with Cleartext Password Exposure VT
Port TCP 55308 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 57252 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 61707 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Internal IP 172.16.7.16 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C VT
Port TCP 57202 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 55115 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 61537 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 51490 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 53384 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Port TCP 52018 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C
Internal IP 172.16.5.20 WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C VT
Internal IP 172.16.1.20 SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs VT
External IP 144.121.9.222 SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs VT
External IP 65.114.90.19 SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs VT
External IP 107.107.185.201 SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs VT
External IP 166.172.120.210 SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs VT
Internal IP 172.16.4.1 Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TT VT
Internal IP 172.16.6.13 Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TT VT
Internal IP 10.10.254.1 Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System VT
Port TCP 61613 Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System
External IP 24.59.13.39 Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System VT
External IP 104.96.34.39 Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System VT
Port TCP 8081 Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System
Internal IP 172.16.4.6 Suspicious rundll32.exe on base-mail Exchange Server (PID 15116) VT
Port TCP 56281 BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21)
Internal IP 172.16.7.12 BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21) VT
Port TCP 59071 base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me
Internal IP 172.16.7.14 base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me VT
Port TCP 54302 base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me
Internal IP 10.10.150.181 base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me VT
Port TCP 54120 base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me
Internal IP 172.16.4.7 base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo VT
Port TCP 808 base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo
Port TCP 58661 base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo
Port TCP 50093 base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection
Port TCP 50663 base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection
Port TCP 49889 base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection
Port TCP 59106 Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 wit
Port TCP 18278 Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 wit
File IOCs (6)
TypeValueEnrichmentContextActions
Path C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerView/PowerSploit Active Reconnaissance from Domain Controller
Path C:\ProgramData\staging\install_wormhole\ Attacker Staging Directories with Malicious Tooling on base-rd-02
Path C:\Program Attacker Staging Directories with Malicious Tooling on base-rd-02
Path C:\Users\jpallen\AppData\Local\Microsoft User Account tdungan Compromised — Active Session During Attack on base-rd-02
Path C:\WINDOWS\system32\cmd.exe Malicious Executable Dropped and Executed: c:\windows\temp\perfmon\p.exe
Path C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe WMI-Based Remote Code Execution on base-wkstn-01
Email IOCs (3)
TypeValueEnrichmentContextActions
Email ftp--dblake@ftp.stark-research-labs.com FTP Data Exfiltration of User Profile Directories from DMZ FTP Server
Email mprsydow@mail.com External FTP User rsydow-f Authenticated with Cleartext Password Exposure
Email cbarton@shieldbase.lan SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs
Select a source
Select a source from the tree to view raw evidence output.
Source Name Extractor Lines Hash Referenced By
tsk.filelist sleuthkit 245104 blake2b:eceaf772... 7 findings
volatility.psscan volatility3 125 blake2b:9ac8a4aa... 12 findings
volatility.modscan volatility3 218 blake2b:38bd04f0...
tsk.filelist sleuthkit 159142 blake2b:6609e2ab... 7 findings
bulk.domain bulk_extractor 1897533 blake2b:950b8f8f... 8 findings
volatility.netscan volatility3 146 blake2b:b50ecd53... 25 findings
volatility.netscan volatility3 125 blake2b:89e7a8f2... 25 findings
volatility.psscan volatility3 102 blake2b:e79f8559... 12 findings
volatility.psscan volatility3 93 blake2b:e3947cf4... 12 findings
bulk.email bulk_extractor 1044028 blake2b:e21446f5... 1 finding
bulk.ether bulk_extractor 6 blake2b:8e1aca4c...
bulk.ip bulk_extractor 31 blake2b:7dfb22e2...
bulk.packets bulk_extractor 165 blake2b:beb2e58a...
bulk.rfc822 bulk_extractor 1075 blake2b:be12cf1d...
bulk.tcp bulk_extractor 14 blake2b:58383280...
bulk.url bulk_extractor 585039 blake2b:dcb0526f...
bulk.url_facebook-address bulk_extractor 8 blake2b:f386d751...
bulk.url_searches bulk_extractor 15 blake2b:6b63ad98...
bulk.url_services bulk_extractor 6781 blake2b:f8995f79...
volatility.modscan volatility3 146 blake2b:77b90c7b...
volatility.modscan volatility3 145 blake2b:efc97b70...
chainsaw.hunt chainsaw 2 blake2b:fb984047...
ez.amcache eztools 639 blake2b:af51025f...
bulk.domain bulk_extractor 1484914 blake2b:cff4769d... 8 findings
ez.mft eztools 236796 blake2b:c72c2739... 10 findings
registry.system regripper 416 blake2b:ac48168a... 6 findings
tsk.timeline sleuthkit 895935 blake2b:cfec4b20...
evtx.manifest evtx-extract 530 blake2b:24c88435...
registry.system regripper 128 blake2b:962c680e... 6 findings
bulk.email bulk_extractor 32275 blake2b:7482b775... 1 finding
bulk.ether bulk_extractor 33024 blake2b:d5c052e7...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
bulk.httplogs bulk_extractor 11 blake2b:3efea4cc... 5 findings
bulk.ip bulk_extractor 35 blake2b:b41fa333...
bulk.packets bulk_extractor 162 blake2b:36977342...
bulk.rfc822 bulk_extractor 3852 blake2b:a7107fc5...
bulk.tcp bulk_extractor 15 blake2b:20d9f3a2...
bulk.url bulk_extractor 881789 blake2b:8ade7620...
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 75 blake2b:a1fb63af... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 283 blake2b:cd06251b... 6 findings
registry.system regripper 283 blake2b:d16cdfb5... 6 findings
registry.system regripper 7606 blake2b:20f6f6ae... 6 findings
registry.system regripper 199 blake2b:66848027... 6 findings
bulk.url_facebook-address bulk_extractor 1858 blake2b:702c2be7...
bulk.url_searches bulk_extractor 14 blake2b:d80de1ed...
bulk.url_services bulk_extractor 22845 blake2b:511d4800...
registry.system regripper 41219 blake2b:f52d805b... 6 findings
registry.system regripper 199 blake2b:e976fc92... 6 findings
registry.system regripper 128 blake2b:83d92a46... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 41219 blake2b:8eea8bdf... 6 findings
registry.system regripper 283 blake2b:cd06251b... 6 findings
registry.system regripper 283 blake2b:f64043cb... 6 findings
registry.system regripper 7606 blake2b:94ce7482... 6 findings
registry.system regripper 199 blake2b:e976fc92... 6 findings
registry.system regripper 199 blake2b:66848027... 6 findings
ez.mft eztools 150265 blake2b:f14ef02a... 10 findings
registry.system regripper 75 blake2b:a1fb63af... 6 findings
evtx.manifest evtx-extract 522 blake2b:84552457...
registry.system regripper 381 blake2b:518e5438... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
chainsaw.hunt chainsaw 2 blake2b:281919b7...
evtx.windows_system32_winevt_logs_security eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
composite.persistence composite 5768 blake2b:c08b905b...
forensic.timestomping timestomp_detector 2 blake2b:a14e1272...
composite.persistence composite 5768 blake2b:c08b905b...
evtx.windows_system32_winevt_logs_security eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
evtx.windows_system32_winevt_logs_windows-powershell eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2822 blake2b:13024986... 9 findings
forensic.timestomping timestomp_detector 2 blake2b:a14e1272...
volatility.pslist volatility3 130 blake2b:4b07c368... 5 findings
volatility.pstree volatility3 130 blake2b:2a892aed... 12 findings
tsk.filelist sleuthkit 324108 blake2b:766e8fb0... 7 findings
volatility.cmdline volatility3 130 blake2b:7ea77b2a... 13 findings
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
volatility.netscan volatility3 130 blake2b:a70bb8f7... 25 findings
volatility.malfind volatility3 8 blake2b:2a7258b8... 9 findings
volatility.psscan volatility3 143 blake2b:da8f63d7... 12 findings
volatility.dlllist volatility3 7122 blake2b:0f623da1... 4 findings
volatility.svcscan volatility3 1324 blake2b:2a307a65...
tsk.filelist sleuthkit 318263 blake2b:e1724920... 7 findings
volatility.netscan volatility3 131 blake2b:63bead3b... 25 findings
volatility.psscan volatility3 139 blake2b:39fce9af... 12 findings
volatility.modscan volatility3 286 blake2b:f4af9511...
bulk.domain bulk_extractor 1022097 blake2b:ddf6e161... 8 findings
bulk.email bulk_extractor 23492 blake2b:6cc43a0d... 1 finding
bulk.ether bulk_extractor 44489 blake2b:d904371b...
bulk.ip bulk_extractor 2357 blake2b:73ca7c10...
bulk.packets bulk_extractor 5654 blake2b:dac41046...
bulk.rfc822 bulk_extractor 16425 blake2b:d92185db...
bulk.tcp bulk_extractor 1169 blake2b:6cbeeff2...
bulk.url bulk_extractor 888145 blake2b:89230a92...
bulk.url_facebook-address bulk_extractor 27 blake2b:c98beb41...
bulk.url_facebook-id bulk_extractor 53 blake2b:271ecc9f...
bulk.url_searches bulk_extractor 206 blake2b:952e7ba5...
bulk.url_services bulk_extractor 5311 blake2b:11e2a57f...
chainsaw.hunt chainsaw 2 blake2b:6b347e31...
ez.amcache eztools 881 blake2b:d30980e8...
registry.sam regripper 205 blake2b:b4cd789f...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.system regripper 75 blake2b:1545fee0... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 283 blake2b:77c52ba6... 6 findings
registry.system regripper 283 blake2b:99c57c1d... 6 findings
registry.system regripper 8152 blake2b:5689a1f4... 6 findings
registry.system regripper 199 blake2b:d3bd07a5... 6 findings
evtx.manifest evtx-extract 853 blake2b:aee4c47c...
registry.system regripper 47350 blake2b:55660a4c... 6 findings
registry.system regripper 199 blake2b:a0719339... 6 findings
registry.sam regripper 205 blake2b:7d48d9f1...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 47350 blake2b:8fc42b11... 6 findings
registry.system regripper 283 blake2b:adc51ab1... 6 findings
registry.system regripper 283 blake2b:df437ac3... 6 findings
registry.system regripper 8152 blake2b:3eb69fc9... 6 findings
registry.system regripper 199 blake2b:a0719339... 6 findings
registry.system regripper 199 blake2b:d3bd07a5... 6 findings
registry.system regripper 75 blake2b:1545fee0... 6 findings
registry.sam regripper 205 blake2b:59967bbe...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.system regripper 75 blake2b:1545fee0... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 453 blake2b:918bae9f... 6 findings
registry.system regripper 47350 blake2b:e1bd5614... 6 findings
registry.system regripper 283 blake2b:af8a3590... 6 findings
registry.system regripper 283 blake2b:df437ac3... 6 findings
registry.system regripper 8152 blake2b:79ca9a91... 6 findings
registry.system regripper 199 blake2b:a0719339... 6 findings
ez.mft eztools 303750 blake2b:97571ad8... 10 findings
registry.system regripper 199 blake2b:d3bd07a5... 6 findings
bulk.domain bulk_extractor 1045808 blake2b:7e7b0cfe... 8 findings
bulk.email bulk_extractor 35797 blake2b:dcd00193... 1 finding
bulk.ether bulk_extractor 2473 blake2b:8a2e1ce0...
bulk.httplogs bulk_extractor 7 blake2b:95e32a7d... 5 findings
bulk.ip bulk_extractor 1529 blake2b:a2202681...
bulk.packets bulk_extractor 9937 blake2b:08c16172...
bulk.rfc822 bulk_extractor 28799 blake2b:99dd53ce...
bulk.tcp bulk_extractor 758 blake2b:96e8f070...
bulk.url bulk_extractor 1134727 blake2b:f41c8a2f...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
chainsaw.hunt chainsaw 2 blake2b:dbe7d3a7...
ez.mft eztools 303841 blake2b:a3b55e76... 10 findings
yara.files yara 35 blake2b:af20e0cf... 1 finding
evtx.manifest evtx-extract 846 blake2b:418ab17e...
registry.system regripper 204 blake2b:3b63a953... 6 findings
bulk.url_facebook-address bulk_extractor 27 blake2b:0420b825...
bulk.url_facebook-id bulk_extractor 16 blake2b:fc7cb5f0...
bulk.url_searches bulk_extractor 262 blake2b:228eb8aa...
bulk.url_services bulk_extractor 10131 blake2b:5063290c...
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 75 blake2b:72184472... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 283 blake2b:99eba833... 6 findings
registry.system regripper 283 blake2b:182b80d6... 6 findings
registry.system regripper 7766 blake2b:98c1908a... 6 findings
registry.system regripper 199 blake2b:d2f17585... 6 findings
registry.system regripper 46189 blake2b:7bcf55e2... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-taskscheduler4operational eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-terminalservices-localsessionmanager4operational eztools 136 blake2b:a6701752... 1 finding
registry.system regripper 199 blake2b:3e017d72... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin eztools 2 blake2b:a4a04fb8...
registry.system regripper 438 blake2b:e8fbdef3... 6 findings
evtx.windows_system32_winevt_logs_system eztools 1310 blake2b:3fb72c08...
registry.system regripper 204 blake2b:da002209... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 6584 blake2b:6ce86725... 9 findings
registry.system regripper 46189 blake2b:495d9a32... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 7306 blake2b:7ca6c55a... 9 findings
registry.system regripper 283 blake2b:b450fa64... 6 findings
registry.system regripper 283 blake2b:c7e28ab8... 6 findings
registry.system regripper 7766 blake2b:3f252fb5... 6 findings
registry.system regripper 199 blake2b:3e017d72... 6 findings
registry.system regripper 199 blake2b:d2f17585... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 7306 blake2b:7ca6c55a... 9 findings
registry.system regripper 75 blake2b:72184472... 6 findings
registry.system regripper 204 blake2b:ca052d7a... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 7 blake2b:e4c6f012... 6 findings
yara.files yara 27 blake2b:1bbb4e6c... 1 finding
registry.system regripper 75 blake2b:72184472... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 411 blake2b:db3a86ce... 6 findings
registry.system regripper 46189 blake2b:42955550... 6 findings
registry.system regripper 283 blake2b:c3db5198... 6 findings
registry.system regripper 283 blake2b:6edd34fe... 6 findings
registry.system regripper 7766 blake2b:761f2427... 6 findings
registry.system regripper 199 blake2b:3e017d72... 6 findings
registry.system regripper 199 blake2b:d2f17585... 6 findings
composite.suspicious_processes composite 142 blake2b:5ddbd02e...
volatility.cmdline volatility3 164 blake2b:46a775f3... 13 findings
tsk.filelist sleuthkit 318752 blake2b:63145ecc... 7 findings
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
volatility.netscan volatility3 149 blake2b:35037597... 25 findings
volatility.netscan volatility3 140 blake2b:6d1c9d08... 25 findings
volatility.psscan volatility3 132 blake2b:715b3401... 12 findings
volatility.psscan volatility3 170 blake2b:d7e00cb4... 12 findings
tsk.filelist sleuthkit 186467 blake2b:0e902a10... 7 findings
volatility.netscan volatility3 113 blake2b:73d6af24... 25 findings
volatility.svcscan volatility3 1310 blake2b:ba6f4dac...
volatility.psscan volatility3 97 blake2b:9bbea4ab... 12 findings
volatility.modscan volatility3 257 blake2b:87857bfc...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
bulk.domain bulk_extractor 754889 blake2b:0ce83aed... 8 findings
volatility.modscan volatility3 169 blake2b:648bc1d6...
bulk.email bulk_extractor 12487 blake2b:f73512de... 1 finding
bulk.ether bulk_extractor 3638 blake2b:c08527b0...
bulk.httplogs bulk_extractor 60 blake2b:928d66b1... 5 findings
bulk.ip bulk_extractor 3573 blake2b:abb904db...
bulk.packets bulk_extractor 5650 blake2b:23052f40...
bulk.rfc822 bulk_extractor 26959 blake2b:9d857c0c...
bulk.tcp bulk_extractor 1777 blake2b:3b63f7cf...
bulk.url bulk_extractor 947653 blake2b:17250be0...
bulk.url_facebook-address bulk_extractor 47 blake2b:50457483...
bulk.url_facebook-id bulk_extractor 21 blake2b:e81cbf6c...
bulk.url_searches bulk_extractor 172 blake2b:86c34ed1...
bulk.url_services bulk_extractor 10040 blake2b:a0ce4fce...
chainsaw.hunt chainsaw 2 blake2b:f7106a96...
ez.mft eztools 301603 blake2b:d23d0d5b... 10 findings
evtx.manifest evtx-extract 1147 blake2b:7f785e4e...
registry.sam regripper 206 blake2b:a5d57544...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.security regripper 75 blake2b:4f10a278...
registry.security regripper 8 blake2b:3c5e87f4...
registry.security regripper 8 blake2b:3c5e87f4...
registry.software regripper 47526 blake2b:9c4ce7e6...
registry.software regripper 283 blake2b:3ccb45b5...
registry.software regripper 283 blake2b:583eaefd...
registry.system regripper 7496 blake2b:c3774b12... 6 findings
registry.system regripper 199 blake2b:8977f42c... 6 findings
registry.system regripper 199 blake2b:aa53bf0a... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
registry.default regripper 461 blake2b:f490c13a...
registry.sam regripper 206 blake2b:b15004b8...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.security regripper 75 blake2b:4f10a278...
registry.security regripper 8 blake2b:3c5e87f4...
registry.security regripper 8 blake2b:3c5e87f4...
registry.software regripper 283 blake2b:74a3df51...
registry.software regripper 283 blake2b:75099375...
registry.system regripper 7496 blake2b:6100209e... 6 findings
registry.system regripper 199 blake2b:aa53bf0a... 6 findings
registry.software regripper 47526 blake2b:c3c4c550...
registry.system regripper 199 blake2b:8977f42c... 6 findings
registry.default regripper 461 blake2b:f490c13a...
registry.sam regripper 206 blake2b:012419a7...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
registry.security regripper 8 blake2b:3c5e87f4...
registry.security regripper 8 blake2b:3c5e87f4...
registry.software regripper 47526 blake2b:c0b8da2c...
registry.software regripper 283 blake2b:277591f7...
registry.software regripper 283 blake2b:ab173c9e...
registry.system regripper 7496 blake2b:052cdd00... 6 findings
bulk.domain bulk_extractor 1343401 blake2b:6d6051fd... 8 findings
registry.system regripper 199 blake2b:8977f42c... 6 findings
registry.system regripper 199 blake2b:aa53bf0a... 6 findings
registry.security regripper 75 blake2b:4f10a278...
registry.sam regripper 206 blake2b:86beba80...
registry.sam regripper 7 blake2b:e4c6f012...
registry.sam regripper 7 blake2b:e4c6f012...
bulk.email bulk_extractor 15775 blake2b:9081f60c... 1 finding
registry.security regripper 75 blake2b:4f10a278...
registry.security regripper 8 blake2b:3c5e87f4...
bulk.ether bulk_extractor 2775 blake2b:81bfa0c0...
bulk.httplogs bulk_extractor 55 blake2b:ae5a38a8... 5 findings
registry.security regripper 8 blake2b:3c5e87f4...
bulk.ip bulk_extractor 395 blake2b:de8ccf66...
bulk.packets bulk_extractor 2867 blake2b:948278c7...
bulk.rfc822 bulk_extractor 29201 blake2b:5b0d4901...
bulk.tcp bulk_extractor 198 blake2b:5421db0a...
bulk.url bulk_extractor 1100611 blake2b:cf8df8b1...
registry.software regripper 47526 blake2b:46d8fa60...
registry.software regripper 283 blake2b:665cc4f2...
registry.software regripper 283 blake2b:64da67d2...
registry.system regripper 7496 blake2b:ab1be7a5... 6 findings
registry.system regripper 199 blake2b:8977f42c... 6 findings
registry.system regripper 199 blake2b:aa53bf0a... 6 findings
bulk.url_facebook-address bulk_extractor 17 blake2b:1363b2d4...
bulk.url_facebook-id bulk_extractor 21 blake2b:1526c1a0...
bulk.url_searches bulk_extractor 177 blake2b:343464ff...
bulk.url_services bulk_extractor 7342 blake2b:4d28d7b0...
chainsaw.hunt chainsaw 2 blake2b:f7106a96...
ez.mft eztools 170131 blake2b:c44ae450... 10 findings
evtx.manifest evtx-extract 1086 blake2b:724fc04a...
registry.system regripper 7 blake2b:e4c6f012... 6 findings
registry.system regripper 8 blake2b:3c5e87f4... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin eztools 2 blake2b:a4a04fb8...
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2 blake2b:a4a04fb8... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2 blake2b:a4a04fb8... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational eztools 2 blake2b:a4a04fb8... 9 findings
evtx.windows_system32_winevt_logs_microsoft-windows-sysmon4operational eztools 2 blake2b:a4a04fb8...
composite.suspicious_processes composite 242 blake2b:a76fb9c2...
composite.suspicious_processes composite 242 blake2b:a76fb9c2...
tsk.filelist sleuthkit 298456 blake2b:edcd0278... 7 findings
bulk.domain bulk_extractor 2049009 blake2b:bb089b69... 8 findings
bulk.email bulk_extractor 12143 blake2b:2a700bce... 1 finding
bulk.ether bulk_extractor 28881 blake2b:14fcb108...
bulk.httplogs bulk_extractor 40 blake2b:4d7aa640... 5 findings
bulk.ip bulk_extractor 51 blake2b:621165ac...
bulk.packets bulk_extractor 156 blake2b:706a51a9...
bulk.rfc822 bulk_extractor 1972 blake2b:f991205c...
bulk.tcp bulk_extractor 22 blake2b:296fbe5b...
bulk.url bulk_extractor 934664 blake2b:578f4b68...
bulk.url_facebook-address bulk_extractor 6 blake2b:87861f76...
bulk.url_searches bulk_extractor 14 blake2b:222b33cc...
bulk.url_services bulk_extractor 2922 blake2b:9138842e...
ez.mft eztools 283801 blake2b:bac30d71... 10 findings
volatility.pslist volatility3 233 blake2b:2645759b... 5 findings
volatility.pslist volatility3 111 blake2b:155c4124... 5 findings
volatility.pstree volatility3 111 blake2b:2f53a7cc... 12 findings
volatility.pstree volatility3 233 blake2b:c11e5cdd... 12 findings
volatility.cmdline volatility3 111 blake2b:712e7412... 13 findings
evtx.manifest evtx-extract 1281 blake2b:1d036de1...
volatility.cmdline volatility3 233 blake2b:3d8af26e... 13 findings
registry.system regripper 381 blake2b:518e5438... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
registry.system regripper 381 blake2b:518e5438... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
registry.system regripper 255 blake2b:0d77cf74... 6 findings
volatility.netscan volatility3 206 blake2b:6b8964d1... 25 findings
volatility.netscan volatility3 127 blake2b:7315125b... 25 findings
volatility.malfind volatility3 43 blake2b:9a251476... 9 findings
chainsaw.hunt chainsaw 2 blake2b:e0a65ed1...
volatility.netscan volatility3 154 blake2b:2f43aa1d... 25 findings
volatility.psscan volatility3 115 blake2b:00dc1052... 12 findings
volatility.dlllist volatility3 5586 blake2b:cbe3d803... 4 findings
volatility.psscan volatility3 98 blake2b:cf1caac5... 12 findings
volatility.svcscan volatility3 913 blake2b:77edf96c...
volatility.netscan volatility3 171 blake2b:33f98d24... 25 findings
forensic.timestomping timestomp_detector 7 blake2b:6f80f559...
volatility.malfind volatility3 31 blake2b:8e4dd810... 9 findings
volatility.psscan volatility3 92 blake2b:d351d701... 12 findings
volatility.modscan volatility3 229 blake2b:75f99d42...
binary.triage rabin2 30 blake2b:bcc741fe...
volatility.psscan volatility3 245 blake2b:b23af332... 12 findings
volatility.dlllist volatility3 9419 blake2b:cb55e58d... 4 findings
volatility.svcscan volatility3 1286 blake2b:b07bdef9...
volatility.modscan volatility3 248 blake2b:bf5f18d4...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
volatility.pslist volatility3 118 blake2b:d934d1a0... 5 findings
volatility.pslist volatility3 154 blake2b:89fa6a52... 5 findings
volatility.pslist volatility3 67 blake2b:98c3b901... 5 findings
volatility.pslist volatility3 135 blake2b:7fb6bbc7... 5 findings
volatility.pstree volatility3 67 blake2b:ba272194... 12 findings
volatility.pstree volatility3 118 blake2b:fbdfc669... 12 findings
volatility.pstree volatility3 154 blake2b:1b049bf4... 12 findings
volatility.pstree volatility3 135 blake2b:a297ca8c... 12 findings
volatility.cmdline volatility3 67 blake2b:8f0d1d12... 13 findings
volatility.cmdline volatility3 135 blake2b:5fa78570... 13 findings
volatility.cmdline volatility3 154 blake2b:becf274a... 13 findings
volatility.cmdline volatility3 118 blake2b:c51f4930... 13 findings
volatility.netscan volatility3 129 blake2b:6957d1b7... 25 findings
volatility.malfind volatility3 27 blake2b:c11f2eb4... 9 findings
volatility.psscan volatility3 98 blake2b:2c163c46... 12 findings
volatility.dlllist volatility3 3647 blake2b:a0fbbf49... 4 findings
volatility.svcscan volatility3 916 blake2b:1cf52994...
volatility.netscan volatility3 1017 blake2b:2aced46a... 25 findings
volatility.netscan volatility3 138 blake2b:08c45b22... 25 findings
volatility.netscan volatility3 250 blake2b:efa8afac... 25 findings
volatility.malfind volatility3 4 blake2b:f4ea7371... 9 findings
volatility.malfind volatility3 17 blake2b:37d567a2... 9 findings
volatility.malfind volatility3 313 blake2b:0444dc6f... 9 findings
volatility.psscan volatility3 132 blake2b:91e525a7... 12 findings
volatility.dlllist volatility3 7051 blake2b:1f73727f... 4 findings
volatility.psscan volatility3 202 blake2b:ac687953... 12 findings
volatility.psscan volatility3 139 blake2b:bdf1e97a... 12 findings
volatility.dlllist volatility3 6116 blake2b:7ebccf44... 4 findings
volatility.svcscan volatility3 1336 blake2b:cf6ec1b0...
volatility.svcscan volatility3 1290 blake2b:f337f9db...
volatility.dlllist volatility3 15349 blake2b:151b3641... 4 findings
volatility.svcscan volatility3 1364 blake2b:4c8cb470...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
volatility.pslist volatility3 59 blake2b:2fd2499f... 5 findings
volatility.pstree volatility3 59 blake2b:1e40bd20... 12 findings
volatility.cmdline volatility3 59 blake2b:5ae17d2d... 13 findings
volatility.netscan volatility3 112 blake2b:0bfe276f... 25 findings
volatility.netscan volatility3 280 blake2b:dc129b3c... 25 findings
volatility.malfind volatility3 4 blake2b:52ef31a6... 9 findings
volatility.psscan volatility3 67 blake2b:0b10e60c... 12 findings
volatility.dlllist volatility3 3176 blake2b:2cd76fac... 4 findings
volatility.psscan volatility3 92 blake2b:e0f38056... 12 findings
volatility.svcscan volatility3 913 blake2b:7c2d1cb2...
volatility.netscan volatility3 120 blake2b:616c3ccf... 25 findings
volatility.modscan volatility3 149 blake2b:e5c0dbf1...
volatility.psscan volatility3 129 blake2b:d531035a... 12 findings
volatility.psscan volatility3 155 blake2b:c943e0f0... 12 findings
volatility.pslist volatility3 77 blake2b:0713186c... 5 findings
volatility.pstree volatility3 77 blake2b:b5407860... 12 findings
volatility.cmdline volatility3 77 blake2b:d5fb83ee... 13 findings
volatility.netscan volatility3 134 blake2b:efafec82... 25 findings
volatility.psscan volatility3 79 blake2b:aee3e6bf... 12 findings
volatility.modscan volatility3 255 blake2b:4468f27a...
volatility.modscan volatility3 255 blake2b:61aa9578...
volatility.modscan volatility3 162 blake2b:363a5a60...
volatility.netscan volatility3 132 blake2b:2ac0a43c... 25 findings
volatility.malfind volatility3 12 blake2b:4391a57d... 9 findings
volatility.psscan volatility3 85 blake2b:3adb059b... 12 findings
volatility.dlllist volatility3 3934 blake2b:b58fc03a... 4 findings
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
volatility.svcscan volatility3 1286 blake2b:28b2e791...
composite.suspicious_processes composite 1585 blake2b:67146af5...
yara.memory yara 9206 blake2b:f475b9fd... 3 findings
composite.correlation composite 1 blake2b:ccbe0b82...
composite.correlation composite 1 blake2b:f77109d9...
composite.correlation composite 1 blake2b:b462e39c...
composite.correlation composite 1 blake2b:e094365f...
composite.correlation composite 1 blake2b:f0e571f1...
composite.persistence composite 37508 blake2b:e69d7f75...
composite.exfil composite 467160 blake2b:6bf3d9f3...
composite.exfil composite 467160 blake2b:6bf3d9f3...
composite.defense_evasion composite 277 blake2b:a90e661d...
composite.suspicious_processes composite 1585 blake2b:67146af5...
composite.execution composite 558 blake2b:cbc462e6...
composite.timeline composite 418 blake2b:5ffdc2cb...
composite.file_staging composite 32672 blake2b:afe37fd0...
composite.exfil composite 467160 blake2b:6bf3d9f3...
composite.recovery composite 7 blake2b:c5fcd372...
composite.correlation composite 1 blake2b:01c33aa5...
composite.correlation composite 1 blake2b:c9353f0f...
composite.correlation composite 1 blake2b:cac63622...
0
Tool Calls
0
Unique Tools
47849.4s
Processing Time
698,366
Tokens
876
Tokens/min
Tool Distribution
Token Breakdown
Input Tokens159,989
Output Tokens538,377
Total Tokens698,366
Per-Model Breakdown
claude-haiku-4-5@202510011,678
claude-opus-4-6696,688
Model Usage Comparison
ModelInputOutputTotalShare
claude-haiku-4-5@20251001 34 1,644 1,678
0%
claude-opus-4-6 159,955 536,733 696,688
99%
Token Throughput Over Time
Estimated token consumption by model over time. Each bar represents a 5-minute window.
ID Tool Duration Timestamp Actions
tc_c4910a21 scan_evidence 164829ms 2026-06-06T06:19:22
tc_54036483 extract_archive 5ms 2026-06-06T06:19:38
tc_56a0812b extract_archive 4ms 2026-06-06T06:19:38
tc_55e920e9 extract_archive 5ms 2026-06-06T06:19:38
tc_903f3ab8 extract_archive 8ms 2026-06-06T06:19:38
tc_759371d2 extract_archive 2ms 2026-06-06T06:19:38
tc_a06c0128 extract_archive 0ms 2026-06-06T06:19:38
tc_9a6bb776 start_extraction_batch 10ms 2026-06-06T06:19:38
tc_ff45b070 extract_archive 2ms 2026-06-06T06:19:38
tc_b7c2a225 extract_archive 1ms 2026-06-06T06:19:38
tc_4692938f extract_archive 1ms 2026-06-06T06:19:38
tc_75e8324d extract_archive 1ms 2026-06-06T06:19:38
tc_bc1abeac extract_archive 1ms 2026-06-06T06:19:38
tc_b7ad57de extract_archive 0ms 2026-06-06T06:19:38
tc_1c68bb4c extract_archive 1ms 2026-06-06T06:19:38
tc_011fb101 extract_archive 0ms 2026-06-06T06:19:38
tc_9a75d6ae extract_archive 1ms 2026-06-06T06:19:38
tc_3de9b9e3 extract_archive 0ms 2026-06-06T06:19:38
tc_ef86902e extract_archive 0ms 2026-06-06T06:19:38
tc_9f994a54 extract_archive 0ms 2026-06-06T06:19:38
tc_c63723ab extract_archive 0ms 2026-06-06T06:19:38
tc_49dbff40 extract_archive 1ms 2026-06-06T06:19:38
tc_4016f0e6 extract_archive 1ms 2026-06-06T06:19:38
tc_184972fb extract_archive 1ms 2026-06-06T06:19:38
tc_b9a74ed0 list_directory 16ms 2026-06-06T06:19:53
tc_efd2fb79 start_extraction_batch 3ms 2026-06-06T06:20:10
tc_15b549e1 extract_archive 45790ms 2026-06-06T06:20:56
tc_6f8b059f extract_archive 90799ms 2026-06-06T06:21:41
tc_77aab7b3 extract_archive 145963ms 2026-06-06T06:22:36
tc_d96bf91b extract_archive 154003ms 2026-06-06T06:22:44
tc_479b5e6e extract_archive 163726ms 2026-06-06T06:22:54
tc_b01c1d15 extract_archive 165832ms 2026-06-06T06:22:56
tc_1b7e83b8 extract_archive 130902ms 2026-06-06T06:23:07
tc_71c1fa45 extract_archive 110857ms 2026-06-06T06:23:32
tc_116d4733 extract_archive 61004ms 2026-06-06T06:23:45
tc_a93ba578 extract_archive 70157ms 2026-06-06T06:24:04
tc_c997b34d extract_archive 93486ms 2026-06-06T06:24:10
tc_f2bc8c24 extract_archive 84845ms 2026-06-06T06:24:21
tc_cbbcaef1 extract_archive 276641ms 2026-06-06T06:24:47
tc_9f37abc4 extract_archive 82874ms 2026-06-06T06:24:55
tc_b2793ec3 extract_archive 88073ms 2026-06-06T06:25:13
tc_fc5c9daa extract_archive 138688ms 2026-06-06T06:25:26
tc_a00763a5 extract_archive 77316ms 2026-06-06T06:25:27
tc_74f5756b extract_archive 83532ms 2026-06-06T06:25:28
tc_338c4860 extract_archive 78433ms 2026-06-06T06:25:39
tc_e8c451b8 extract_archive 47126ms 2026-06-06T06:25:42
tc_04ba7b51 extract_archive 58689ms 2026-06-06T06:25:46
tc_f2dac528 extract_archive 360956ms 2026-06-06T06:26:11
tc_7f561869 get_completed_results 0ms 2026-06-06T06:26:18
tc_6cfe5147 list_sources 11ms 2026-06-06T06:26:18
tc_1d522a3b get_source_stats 8ms 2026-06-06T06:26:40
tc_aa3ba350 scan_evidence 46ms 2026-06-06T06:27:31
tc_2e26f5ff open_case 14ms 2026-06-06T06:27:43
tc_869844cb scan_evidence 43ms 2026-06-06T06:27:59
tc_42cada6e open_case 14ms 2026-06-06T06:28:06
tc_831d6827 open_case 14ms 2026-06-06T06:28:33
tc_d024e222 start_extraction_batch 17ms 2026-06-06T06:28:43
tc_c918de37 run_mmls 0ms 2026-06-06T06:28:43
tc_fdd97a56 yara_scan_memory 114ms 2026-06-06T06:28:43
tc_df7e7c41 run_fls 66246ms 2026-06-06T06:29:49
tc_84af7e1e run_volatility_batch 599876ms 2026-06-06T06:38:43
tc_51a0a4e7 open_case 47ms 2026-06-06T06:38:57
tc_612ed1c9 start_extraction_batch 15ms 2026-06-06T06:40:08
tc_2d7e3668 run_mmls 0ms 2026-06-06T06:40:13
tc_b9b9d476 run_fls 78194ms 2026-06-06T06:41:26
tc_12cc4415 run_bulk_extractor 1113578ms 2026-06-06T06:47:16
tc_38824169 run_volatility_batch 644873ms 2026-06-06T06:50:53
tc_08d052bf run_volatility_batch 647977ms 2026-06-06T06:51:01
tc_a7fdec67 get_completed_results 0ms 2026-06-06T06:51:14
tc_7eca21a7 start_extraction_batch 44ms 2026-06-06T06:51:25
tc_622f5fa1 run_chainsaw 59ms 2026-06-06T06:51:25
tc_25ef9b73 run_hayabusa 122ms 2026-06-06T06:51:30
tc_c52851b0 run_amcache_parser 6170ms 2026-06-06T06:51:31
tc_12289789 run_prefetch_parser 4650ms 2026-06-06T06:51:34
tc_2aea2c96 run_shimcache_parser 42658ms 2026-06-06T06:52:12
tc_f23e3af7 run_evtx_parser 122064ms 2026-06-06T06:53:27
tc_33fdf72a run_mft_parser 144670ms 2026-06-06T06:53:49
tc_095fc50a yara_scan_memory 139947ms 2026-06-06T06:53:50
tc_d742062b yara_scan_files 162974ms 2026-06-06T06:54:13
tc_efc72383 run_mactime 199315ms 2026-06-06T06:54:50
tc_4bc77756 run_bulk_extractor 905793ms 2026-06-06T06:55:19
tc_a9c26a8d get_completed_results 0ms 2026-06-06T06:55:24
tc_de036d4a start_extraction_batch 35ms 2026-06-06T06:55:32
tc_644ee896 run_amcache_parser 20023ms 2026-06-06T06:55:52
tc_967f6cd7 run_prefetch_parser 20904ms 2026-06-06T06:55:53
tc_9ba64aa2 run_registry_parser 274101ms 2026-06-06T06:56:04
tc_2493c6cf run_mft_parser 35274ms 2026-06-06T06:56:07
tc_07dfd450 get_completed_results 0ms 2026-06-06T06:56:09
tc_4be32638 run_shimcache_parser 41685ms 2026-06-06T06:56:14
tc_96b05e4e start_extraction_batch 2ms 2026-06-06T06:56:14
tc_f84b9100 run_prefetch_parser 3665ms 2026-06-06T06:56:18
tc_9bd2c4de run_evtx_parser 59436ms 2026-06-06T06:56:32
tc_ecad047f run_shimcache_parser 25387ms 2026-06-06T06:56:40
tc_c78a8b72 run_registry_parser 83210ms 2026-06-06T06:56:55
tc_e2750a0b open_case 26ms 2026-06-06T06:57:03
tc_0c120b66 wait_all 0ms 2026-06-06T06:57:08
tc_d62ddf63 open_case 6ms 2026-06-06T06:57:32
tc_d9874c14 yara_scan_memory 120004ms 2026-06-06T06:57:32
tc_3018d820 get_investigation_summary 14ms 2026-06-06T06:57:36
tc_aa45124a get_completed_results 0ms 2026-06-06T06:57:38
tc_3782567c start_extraction_batch 2ms 2026-06-06T06:57:44
tc_ce238c87 get_source_stats 9599ms 2026-06-06T06:57:45
tc_1188a5e7 run_amcache_parser 2920ms 2026-06-06T06:57:47
tc_8c57f05f run_prefetch_parser 3478ms 2026-06-06T06:57:47
tc_d62ac10c get_process_tree 5ms 2026-06-06T06:57:55
tc_f99e5054 list_processes_from_memory 3ms 2026-06-06T06:57:55
tc_5449cb1b get_raw_output 9026ms 2026-06-06T06:58:05
tc_9a9c872a run_shimcache_parser 24287ms 2026-06-06T06:58:08
tc_383a719e get_raw_output 6921ms 2026-06-06T06:58:12
tc_33fa3e8f start_extraction_batch 15ms 2026-06-06T06:58:15
tc_5c3d5c75 run_hayabusa 18ms 2026-06-06T06:58:15
tc_ffd7f758 run_chainsaw 40ms 2026-06-06T06:58:15
tc_8bf36a1e get_completed_results 0ms 2026-06-06T06:58:23
tc_26580fc9 get_raw_output 9083ms 2026-06-06T06:58:24
tc_5c617e91 open_case 32ms 2026-06-06T06:58:47
tc_3e0b64d1 wait_all 0ms 2026-06-06T06:58:53
tc_ce81377a get_raw_output 9145ms 2026-06-06T06:58:54
tc_5f05ef36 get_raw_output 9062ms 2026-06-06T06:59:03
tc_c8d6c6ae get_raw_output 9037ms 2026-06-06T06:59:12
tc_ce96bc23 open_case 18ms 2026-06-06T06:59:15
tc_731b09fd get_investigation_summary 20ms 2026-06-06T06:59:20
tc_dee3a6a2 list_sources 6ms 2026-06-06T06:59:20
tc_24110a42 get_raw_output 11207ms 2026-06-06T06:59:24
tc_a504c8d6 search 275ms 2026-06-06T06:59:26
tc_0ee445b8 get_source_stats 11327ms 2026-06-06T06:59:31
tc_066c0c53 get_process_tree 6ms 2026-06-06T06:59:42
tc_1ccba11a find_suspicious_processes._query(volatility.malfind) 230ms 2026-06-06T06:59:42
tc_485bc27f find_suspicious_processes._query(volatility.cmdline) 95ms 2026-06-06T06:59:42
tc_1febf15a find_suspicious_processes._query(volatility.netscan) 90ms 2026-06-06T06:59:42
tc_32315682 find_suspicious_processes._query(volatility.pstree) 97ms 2026-06-06T06:59:42
tc_351fca78 find_suspicious_processes._query(volatility.psscan) 94ms 2026-06-06T06:59:42
tc_69112dee find_suspicious_processes._query(volatility.pslist) 91ms 2026-06-06T06:59:42
tc_7822e3e0 find_suspicious_processes 701ms 2026-06-06T06:59:42
tc_dbd40ca6 search 29ms 2026-06-06T06:59:43
tc_be132a92 search 23ms 2026-06-06T06:59:43
tc_6f9991c9 search 1042ms 2026-06-06T06:59:55
tc_2c193200 search 67ms 2026-06-06T06:59:55
tc_db8b2247 search 56ms 2026-06-06T06:59:55
tc_f5909f44 search 33ms 2026-06-06T06:59:55
tc_d4f16b49 get_raw_output 8946ms 2026-06-06T07:00:02
tc_dbe921be get_raw_output 8838ms 2026-06-06T07:00:11
tc_157acb25 get_raw_output 6680ms 2026-06-06T07:00:18
tc_96d71730 get_raw_output 9270ms 2026-06-06T07:00:29
tc_8bd00bf1 get_raw_output 9382ms 2026-06-06T07:00:39
tc_1df9b5ca index_evtx_file 23803ms 2026-06-06T07:00:40
tc_03e34a3f search 33ms 2026-06-06T07:00:40
tc_f38b5b31 search 1189ms 2026-06-06T07:00:42
tc_01419099 find_persistence_mechanisms._query(registry.system) 379ms 2026-06-06T07:00:42
tc_45af65fd find_persistence_mechanisms._query(registry.software) 96ms 2026-06-06T07:00:42
tc_068ad67e find_persistence_mechanisms._query(volatility.svcscan) 90ms 2026-06-06T07:00:42
tc_78405528 find_persistence_mechanisms._search(all) 32ms 2026-06-06T07:00:42
tc_0693ff51 find_persistence_mechanisms._search(all) 24ms 2026-06-06T07:00:42
tc_8a86fd62 find_persistence_mechanisms._query(ez.amcache) 98ms 2026-06-06T07:00:42
tc_7a22b531 find_persistence_mechanisms._search(all) 29ms 2026-06-06T07:00:42
tc_0dbdff21 find_persistence_mechanisms._query(tsk.filelist) 259ms 2026-06-06T07:00:43
tc_3adfda9e find_persistence_mechanisms 1083ms 2026-06-06T07:00:43
tc_9a940650 search 69ms 2026-06-06T07:01:03
tc_7fedefbb search 1754ms 2026-06-06T07:01:06
tc_2c56204c search 68ms 2026-06-06T07:01:06
tc_61e163bd get_raw_output 11258ms 2026-06-06T07:01:10
tc_6d56b84a search 1959ms 2026-06-06T07:01:12
tc_0a2d549e search 173ms 2026-06-06T07:01:12
tc_f4cb513a search 49ms 2026-06-06T07:01:12
tc_42fee88d get_raw_output 11675ms 2026-06-06T07:01:17
tc_03e40ce0 search 90ms 2026-06-06T07:01:39
tc_5e2b911e search 86ms 2026-06-06T07:01:40
tc_430ba9c3 search 146ms 2026-06-06T07:01:41
tc_3b14a8b3 search 19ms 2026-06-06T07:01:41
tc_7668da1f search 194ms 2026-06-06T07:01:42
tc_233bc7a9 search 1006ms 2026-06-06T07:01:42
tc_53223348 search 54ms 2026-06-06T07:01:42
tc_174eda4c search 438ms 2026-06-06T07:01:43
tc_0e91e644 detect_timestomping 1761ms 2026-06-06T07:01:45
tc_6ce6a9f9 get_raw_output 8151ms 2026-06-06T07:02:07
tc_7b489cf1 search 33ms 2026-06-06T07:02:07
tc_5cf3818c search 23ms 2026-06-06T07:02:07
tc_71623731 find_persistence_mechanisms._query(registry.system) 291ms 2026-06-06T07:02:07
tc_2d9ff6c4 find_persistence_mechanisms._query(registry.software) 92ms 2026-06-06T07:02:07
tc_cce5b8f7 find_persistence_mechanisms._query(volatility.svcscan) 90ms 2026-06-06T07:02:07
tc_2d539659 find_persistence_mechanisms._search(all) 33ms 2026-06-06T07:02:07
tc_189b4519 find_persistence_mechanisms._search(all) 26ms 2026-06-06T07:02:07
tc_a4ed0d4c find_persistence_mechanisms._query(ez.amcache) 94ms 2026-06-06T07:02:07
tc_ad38f677 find_persistence_mechanisms._search(all) 37ms 2026-06-06T07:02:07
tc_bc0123ed find_persistence_mechanisms._query(tsk.filelist) 250ms 2026-06-06T07:02:08
tc_654af30c find_persistence_mechanisms 994ms 2026-06-06T07:02:08
tc_b9e0603a submit_finding 16ms 2026-06-06T07:02:17
tc_0d956c30 search 24ms 2026-06-06T07:02:26
tc_c89cd899 search 82ms 2026-06-06T07:02:27
tc_1772186a submit_finding 13ms 2026-06-06T07:02:36
tc_3f7c0a29 index_evtx_file 12284ms 2026-06-06T07:02:42
tc_2fb9bdc4 index_evtx_file 372ms 2026-06-06T07:02:42
tc_3d0707d9 submit_finding 19ms 2026-06-06T07:02:51
tc_ac837510 search 589ms 2026-06-06T07:03:03
tc_b0c1a819 search 127ms 2026-06-06T07:03:03
tc_b11ae175 search 459ms 2026-06-06T07:03:04
tc_1431c1b4 submit_finding 18ms 2026-06-06T07:03:08
tc_fcf6ff23 search 4538ms 2026-06-06T07:03:09
tc_acc3892a search 113ms 2026-06-06T07:03:22
tc_5846ce2f search 51ms 2026-06-06T07:03:23
tc_a2e5cbb9 scan_hidden_processes 9ms 2026-06-06T07:03:24
tc_8fded848 submit_finding 11ms 2026-06-06T07:03:25
tc_4d6e3bdc submit_finding 13ms 2026-06-06T07:03:55
tc_99fd42de index_evtx_file 13065ms 2026-06-06T07:05:35
tc_132ca3e2 search 437ms 2026-06-06T07:05:35
tc_34a710e3 detect_timestomping 1439ms 2026-06-06T07:05:37
tc_66383a7b get_raw_output 7662ms 2026-06-06T07:05:52
tc_78870068 search 102ms 2026-06-06T07:05:53
tc_12cd035f search 31ms 2026-06-06T07:05:53
tc_e8cb79b2 search 98ms 2026-06-06T07:06:06
tc_adeee493 search 910ms 2026-06-06T07:06:07
tc_15cfa05e submit_finding 0ms 2026-06-06T07:06:12
tc_1cb6496c search 29ms 2026-06-06T07:06:19
tc_b83a24d3 scan_hidden_processes 15ms 2026-06-06T07:06:19
tc_d9eff5a7 search 925ms 2026-06-06T07:06:20
tc_929bb36b search 24ms 2026-06-06T07:06:20
tc_571b63ae search 525ms 2026-06-06T07:06:22
tc_492eb01e search 151ms 2026-06-06T07:06:22
tc_18f35d85 search 472ms 2026-06-06T07:06:25
tc_37a409ca search 36ms 2026-06-06T07:06:26
tc_ac657197 search 42ms 2026-06-06T07:06:26
tc_9a2617bb search 119ms 2026-06-06T07:06:33
tc_049f2680 search 44ms 2026-06-06T07:06:34
tc_f91b8518 search 116ms 2026-06-06T07:06:34
tc_9acf695f get_carved_iocs 2297ms 2026-06-06T07:06:39
tc_7823e1f4 search 150ms 2026-06-06T07:06:39
tc_19d26c14 update_finding 8ms 2026-06-06T07:06:52
tc_765d81e1 search 67ms 2026-06-06T07:06:52
tc_9b859299 search 31ms 2026-06-06T07:06:52
tc_f23d00d5 search 29ms 2026-06-06T07:07:04
tc_a615ccff search 363ms 2026-06-06T07:07:05
tc_85604c9b submit_finding 19ms 2026-06-06T07:07:08
tc_2cc6b105 submit_finding 14ms 2026-06-06T07:07:18
tc_55b9fa13 submit_finding 16ms 2026-06-06T07:07:26
tc_5df21172 search 56ms 2026-06-06T07:07:34
tc_1e007ec4 search 34ms 2026-06-06T07:07:35
tc_dd06c588 search 30ms 2026-06-06T07:07:36
tc_65920a52 submit_finding 10ms 2026-06-06T07:07:42
tc_8c475b87 get_raw_output 4370ms 2026-06-06T07:07:48
tc_fc7bb189 search 26ms 2026-06-06T07:07:48
tc_567ba7bb submit_finding 15ms 2026-06-06T07:07:54
tc_a88af352 submit_finding 14ms 2026-06-06T07:08:08
tc_6d1e338e submit_finding 14ms 2026-06-06T07:08:17
tc_839221cf extract_file_by_inode 240ms 2026-06-06T07:08:24
tc_3a5dd6c1 submit_finding 17ms 2026-06-06T07:08:32
tc_f32cd0ee update_finding 20ms 2026-06-06T07:08:41
tc_34aa4eb0 submit_finding 12ms 2026-06-06T07:08:44
tc_65ace770 extract_file_by_inode 219ms 2026-06-06T07:08:51
tc_1b5613db search 22ms 2026-06-06T07:08:51
tc_51a3cc65 triage_binary 0ms 2026-06-06T07:08:59
tc_6b7975af search 23ms 2026-06-06T07:08:59
tc_12d392c3 track_progress 15ms 2026-06-06T07:09:03
tc_7a1d45e9 update_finding 17ms 2026-06-06T07:09:27
tc_131c6b04 get_investigation_summary 10ms 2026-06-06T07:09:27
tc_17230d98 submit_finding 15ms 2026-06-06T07:09:42
tc_fec62523 scan_evidence 45ms 2026-06-06T07:09:43
tc_207f8349 open_case 20ms 2026-06-06T07:09:51
tc_24e3ced6 list_sources 11ms 2026-06-06T07:09:55
tc_c75997a9 submit_finding 14ms 2026-06-06T07:10:01
tc_786efb43 submit_finding 15ms 2026-06-06T07:10:12
tc_aad5dbb4 search 785ms 2026-06-06T07:10:19
tc_869e320b search 21ms 2026-06-06T07:10:19
tc_13623596 get_findings 3ms 2026-06-06T07:10:19
tc_97d35469 submit_finding 17ms 2026-06-06T07:10:38
tc_0ad4a865 track_progress 16ms 2026-06-06T07:10:51
tc_736035a3 open_case 16ms 2026-06-06T07:10:57
tc_8351c0c2 extract_archive 1ms 2026-06-06T07:11:02
tc_0f60fa26 list_directory 8ms 2026-06-06T07:11:08
tc_733a9902 get_investigation_summary 10ms 2026-06-06T07:11:10
tc_e6851326 list_directory 5ms 2026-06-06T07:11:12
tc_0eb6fcce list_directory 8ms 2026-06-06T07:11:16
tc_94f1c026 list_directory 10ms 2026-06-06T07:11:22
tc_2f688ebd list_directory 6ms 2026-06-06T07:11:26
tc_9a2b2881 list_sources 11ms 2026-06-06T07:11:31
tc_351a0c94 scan_evidence 37ms 2026-06-06T07:11:31
tc_c51c1ce6 open_case 11ms 2026-06-06T07:11:38
tc_e982ab92 run_mmls 0ms 2026-06-06T07:11:45
tc_a4dbb75e start_extraction_batch 15ms 2026-06-06T07:11:54
tc_26a4b9ab run_fls 120849ms 2026-06-06T07:13:54
tc_04873e99 yara_scan_memory 174460ms 2026-06-06T07:14:48
tc_da1e30ab run_volatility_batch 563563ms 2026-06-06T07:21:17
tc_70ea556a open_case 45ms 2026-06-06T07:22:34
tc_9e224c76 run_mmls 0ms 2026-06-06T07:24:10
tc_2f90888e start_extraction_batch 39ms 2026-06-06T07:24:10
tc_94e90243 run_fls 185321ms 2026-06-06T07:27:15
tc_7e099bff get_completed_results 0ms 2026-06-06T07:31:43
tc_ec318e20 run_volatility_batch 755591ms 2026-06-06T07:36:45
tc_9c4093f1 start_extraction_batch 32ms 2026-06-06T07:36:58
tc_0132ac8a start_extraction_batch 102ms 2026-06-06T07:42:12
tc_14476796 run_bulk_extractor 1332458ms 2026-06-06T07:46:22
tc_077a44df run_hayabusa 92ms 2026-06-06T07:47:15
tc_0e2ff9cc run_chainsaw 132ms 2026-06-06T07:47:15
tc_69fa8522 run_amcache_parser 27041ms 2026-06-06T07:47:42
tc_349b0dff run_prefetch_parser 72560ms 2026-06-06T07:48:27
tc_44cccbf2 run_shimcache_parser 88096ms 2026-06-06T07:48:43
tc_90490fa1 run_evtx_parser 126110ms 2026-06-06T07:49:21
tc_19262983 get_completed_results 0ms 2026-06-06T07:50:59
tc_aa452396 run_mft_parser 66786ms 2026-06-06T07:52:08
tc_61fc080e run_registry_parser 302019ms 2026-06-06T07:52:17
tc_4619939b yara_scan_memory 130774ms 2026-06-06T07:53:10
tc_5e17dbc3 start_extraction_batch 41ms 2026-06-06T07:53:34
tc_bc5ff211 run_chainsaw 9628ms 2026-06-06T07:53:43
tc_fad23b3f run_amcache_parser 64973ms 2026-06-06T07:54:39
tc_681da70a yara_scan_files 231184ms 2026-06-06T07:54:52
tc_8f8a42d2 run_prefetch_parser 90442ms 2026-06-06T07:55:10
tc_49b6cad0 run_hayabusa 97190ms 2026-06-06T07:55:17
tc_cf4d956c run_shimcache_parser 110807ms 2026-06-06T07:55:24
tc_cfbb1cd8 run_evtx_parser 124827ms 2026-06-06T07:55:38
tc_d3715b14 run_bulk_extractor 1074862ms 2026-06-06T07:55:53
tc_f83d2940 run_mft_parser 140012ms 2026-06-06T07:55:54
tc_5716c34a wait_all 516413ms 2026-06-06T07:55:57
tc_ddef9a22 get_completed_results 0ms 2026-06-06T07:56:03
tc_d6a8a4a6 get_completed_results 0ms 2026-06-06T07:56:04
tc_e3e4d2b3 start_extraction_batch 2ms 2026-06-06T07:56:16
tc_79e3ad9f start_extraction_batch 1ms 2026-06-06T07:56:21
tc_926f02a4 index_evtx_file 0ms 2026-06-06T07:56:21
tc_23b9b7dd index_evtx_file 532ms 2026-06-06T07:56:21
tc_e6098ebc index_evtx_file 919ms 2026-06-06T07:56:22
tc_2493d7e7 index_evtx_file 2162ms 2026-06-06T07:56:23
tc_107b349a index_evtx_file 8509ms 2026-06-06T07:56:29
tc_7e7d9309 index_evtx_file 22826ms 2026-06-06T07:56:44
tc_c7f3a745 run_prefetch_parser 33978ms 2026-06-06T07:56:50
tc_ad7860ff yara_scan_files 192908ms 2026-06-06T07:56:56
tc_54f9949d run_shimcache_parser 41988ms 2026-06-06T07:56:58
tc_949300c1 wait_all 35012ms 2026-06-06T07:57:01
tc_ff6f4eb5 get_completed_results 0ms 2026-06-06T07:57:09
tc_200687a5 open_case 29ms 2026-06-06T07:57:38
tc_c424d938 wait_all 0ms 2026-06-06T07:57:38
tc_74f1aa64 run_registry_parser 254948ms 2026-06-06T07:57:55
tc_cd871425 open_case 18ms 2026-06-06T07:58:00
tc_acc49fd0 get_completed_results 0ms 2026-06-06T07:58:04
tc_b37744eb get_investigation_summary 31ms 2026-06-06T07:58:06
tc_0e52f953 start_extraction_batch 5ms 2026-06-06T07:58:11
tc_17adfcb9 get_source_stats 18239ms 2026-06-06T07:58:25
tc_e9724578 list_processes_from_memory 6ms 2026-06-06T07:58:25
tc_15ff72ef get_process_tree 4ms 2026-06-06T07:58:25
tc_d8f20c69 run_amcache_parser 13874ms 2026-06-06T07:58:25
tc_b3553a3e get_findings 3ms 2026-06-06T07:58:36
tc_843ebb83 search 26ms 2026-06-06T07:58:36
tc_31423290 search 29ms 2026-06-06T07:58:37
tc_faa26eae search 69ms 2026-06-06T07:58:39
tc_eae5e395 run_prefetch_parser 35260ms 2026-06-06T07:58:46
tc_7735dfee run_shimcache_parser 42114ms 2026-06-06T07:58:53
tc_6193313e search 507ms 2026-06-06T07:58:56
tc_c43dec86 search 55ms 2026-06-06T07:58:56
tc_ec862127 get_raw_output 17346ms 2026-06-06T07:59:13
tc_3fb49fa5 search 90ms 2026-06-06T07:59:31
tc_776f6314 search 69ms 2026-06-06T07:59:32
tc_3ebf6520 open_case 18ms 2026-06-06T07:59:33
tc_f81e7890 get_investigation_summary 30ms 2026-06-06T07:59:38
tc_b8b432ec get_raw_output 29053ms 2026-06-06T08:00:02
tc_3e148e1b get_source_stats 23526ms 2026-06-06T08:00:02
tc_fccb7f85 list_sources 9ms 2026-06-06T08:00:02
tc_bc449d8d search 56ms 2026-06-06T08:00:02
tc_f33f86fd get_findings 4ms 2026-06-06T08:00:12
tc_387959f2 get_process_tree 7ms 2026-06-06T08:00:13
tc_b309e502 find_suspicious_processes._query(volatility.malfind) 566ms 2026-06-06T08:00:13
tc_80366d87 find_suspicious_processes._query(volatility.cmdline) 164ms 2026-06-06T08:00:13
tc_bc79a051 find_suspicious_processes._query(volatility.netscan) 171ms 2026-06-06T08:00:14
tc_60dc0a55 find_suspicious_processes._query(volatility.pstree) 161ms 2026-06-06T08:00:14
tc_42106ca0 find_suspicious_processes._query(volatility.psscan) 166ms 2026-06-06T08:00:14
tc_be2e17a1 find_suspicious_processes._query(volatility.pslist) 164ms 2026-06-06T08:00:14
tc_6a8a6b38 find_suspicious_processes._query(volatility.dlllist) 178ms 2026-06-06T08:00:14
tc_a6337c2e find_suspicious_processes 1577ms 2026-06-06T08:00:14
tc_dc48ae34 search 59ms 2026-06-06T08:00:22
tc_2a4f3c66 search 70ms 2026-06-06T08:00:23
tc_164e59be get_raw_output 499ms 2026-06-06T08:00:24
tc_b2b6a298 search 111ms 2026-06-06T08:00:24
tc_43c5be6b search 214ms 2026-06-06T08:00:28
tc_ae5d200c search 165ms 2026-06-06T08:00:29
tc_0365387f search 70ms 2026-06-06T08:00:29
tc_14a2773c search 78ms 2026-06-06T08:00:46
tc_fdd44c03 search 144ms 2026-06-06T08:00:52
tc_9e6ee71e search 2638ms 2026-06-06T08:00:55
tc_05460dde search 2869ms 2026-06-06T08:00:58
tc_ba83b29d get_raw_output 18482ms 2026-06-06T08:01:04
tc_a65f39e7 search 82ms 2026-06-06T08:01:11
tc_e401b5bd search 755ms 2026-06-06T08:01:13
tc_a4e96dec search 449ms 2026-06-06T08:01:13
tc_aeaea42b search 78ms 2026-06-06T08:01:17
tc_2229c88a search 58ms 2026-06-06T08:01:18
tc_a3430288 search 62ms 2026-06-06T08:01:18
tc_0a1336c6 list_directory 9ms 2026-06-06T08:01:23
tc_c4f12402 get_raw_output 409ms 2026-06-06T08:01:26
tc_43e6f0f8 get_raw_output 155ms 2026-06-06T08:01:29
tc_b59a0c0c search 36ms 2026-06-06T08:01:29
tc_ae4a459d list_directory 10ms 2026-06-06T08:01:38
tc_957b132a list_directory 8ms 2026-06-06T08:01:39
tc_c9bf9959 list_directory 8ms 2026-06-06T08:01:53
tc_ea5a3740 search 707ms 2026-06-06T08:01:59
tc_2f7a0a15 search 31ms 2026-06-06T08:01:59
tc_dbfab581 search 25ms 2026-06-06T08:02:00
tc_f93001ec search 52ms 2026-06-06T08:02:01
tc_7749bf6a search 42ms 2026-06-06T08:02:01
tc_6a33fc05 search 42ms 2026-06-06T08:02:02
tc_27fb59ed get_raw_output 7097ms 2026-06-06T08:02:21
tc_9490b109 get_raw_output 7167ms 2026-06-06T08:02:28
tc_4a21d712 get_raw_output 7250ms 2026-06-06T08:02:36
tc_739b3134 submit_finding 33ms 2026-06-06T08:02:38
tc_3f2a7413 submit_finding 18ms 2026-06-06T08:02:57
tc_dcc40157 submit_finding 17ms 2026-06-06T08:03:19
tc_fa4a8753 get_raw_output 16700ms 2026-06-06T08:03:35
tc_e31d4bd8 search 70ms 2026-06-06T08:03:35
tc_21676b66 search 52ms 2026-06-06T08:03:35
tc_c6f14406 search 766ms 2026-06-06T08:04:02
tc_cb9433b1 search 30ms 2026-06-06T08:04:02
tc_ddc8b2e9 search 751ms 2026-06-06T08:04:03
tc_72ac69de search 55ms 2026-06-06T08:04:15
tc_a94819e6 search 695ms 2026-06-06T08:04:17
tc_acbbe6cc get_raw_output 16304ms 2026-06-06T08:04:33
tc_662460ae search 97ms 2026-06-06T08:04:45
tc_baebf015 search 50ms 2026-06-06T08:04:46
tc_1447f7a3 search 767ms 2026-06-06T08:04:47
tc_3cce3174 search 54ms 2026-06-06T08:04:58
tc_3f8a74fb search 60ms 2026-06-06T08:04:59
tc_2ae9c6eb search 22ms 2026-06-06T08:04:59
tc_924f269b search 732ms 2026-06-06T08:05:02
tc_40079482 search 64ms 2026-06-06T08:05:02
tc_a5f16f8e search 345ms 2026-06-06T08:05:03
tc_906401ea search 25ms 2026-06-06T08:05:06
tc_570b004f search 63ms 2026-06-06T08:05:07
tc_58f8e305 search 302ms 2026-06-06T08:05:07
tc_c034bef0 list_sources 12ms 2026-06-06T08:05:13
tc_c769b531 search 24ms 2026-06-06T08:05:20
tc_0f7c1e8b search 25ms 2026-06-06T08:05:20
tc_dd5b51dc search 37ms 2026-06-06T08:05:30
tc_8c2bc049 search 106ms 2026-06-06T08:05:30
tc_8283766f search 363ms 2026-06-06T08:05:32
tc_52486421 get_raw_output 7009ms 2026-06-06T08:05:39
tc_82b41ad4 search 51ms 2026-06-06T08:05:42
tc_eca43fd9 search 60ms 2026-06-06T08:05:42
tc_29656fb7 search 80ms 2026-06-06T08:05:47
tc_b913a22e search 128ms 2026-06-06T08:05:48
tc_df019bee submit_finding 15ms 2026-06-06T08:06:14
tc_10c7b485 submit_finding 14ms 2026-06-06T08:06:29
tc_5a1b743e search 29ms 2026-06-06T08:06:34
tc_d92b6f32 search 97ms 2026-06-06T08:06:35
tc_ea3f5c27 submit_finding 16ms 2026-06-06T08:06:59
tc_2bb544be search 787ms 2026-06-06T08:07:05
tc_24ecd44f search 44ms 2026-06-06T08:07:06
tc_532a33a9 search 47ms 2026-06-06T08:07:11
tc_294f8623 search 2210ms 2026-06-06T08:07:13
tc_36de8666 get_findings 15ms 2026-06-06T08:07:36
tc_2e8d4fc5 search 94ms 2026-06-06T08:07:37
tc_9cc41026 search 93ms 2026-06-06T08:07:38
tc_20c4055c submit_finding 16ms 2026-06-06T08:07:38
tc_1be2bcb5 submit_finding 13ms 2026-06-06T08:07:57
tc_cc60869f search 52ms 2026-06-06T08:08:02
tc_cd6817fa search 718ms 2026-06-06T08:08:04
tc_0ccf2abb search 36ms 2026-06-06T08:08:08
tc_d61aeaff get_deleted_files 2365ms 2026-06-06T08:08:11
tc_d5782820 search 124ms 2026-06-06T08:08:16
tc_8ee551fc update_finding 18ms 2026-06-06T08:08:17
tc_a2a12f1b get_findings 10ms 2026-06-06T08:08:18
tc_dffb31fb search 63ms 2026-06-06T08:08:18
tc_3b42b30a get_findings 10ms 2026-06-06T08:08:22
tc_ebe8dbc9 track_progress 27ms 2026-06-06T08:08:49
tc_6d1b30b6 update_finding 15ms 2026-06-06T08:08:50
tc_0964161e update_finding 15ms 2026-06-06T08:09:05
tc_f227f0ff get_investigation_summary 13ms 2026-06-06T08:09:12
tc_aaad0fad update_finding 13ms 2026-06-06T08:09:17
tc_df008f5b update_finding 13ms 2026-06-06T08:09:34
tc_76ddebba update_finding 16ms 2026-06-06T08:09:35
tc_7b50c82f update_finding 13ms 2026-06-06T08:09:36
tc_5aaa051d update_finding 16ms 2026-06-06T08:09:36
tc_b570eac1 update_finding 19ms 2026-06-06T08:09:38
tc_be58548c update_finding 13ms 2026-06-06T08:09:38
tc_ad6b5e9b search 44ms 2026-06-06T08:09:55
tc_65f75871 search 42ms 2026-06-06T08:09:56
tc_810bce4c submit_finding 12ms 2026-06-06T08:10:14
tc_706eb13c open_case 18ms 2026-06-06T08:10:30
tc_4dfca2a9 track_progress 16ms 2026-06-06T08:10:47
tc_d45e1af9 search 45ms 2026-06-06T08:10:54
tc_5591ac88 search 104ms 2026-06-06T08:11:01
tc_61bf3361 open_case 26ms 2026-06-06T08:11:29
tc_18aab753 get_investigation_summary 14ms 2026-06-06T08:11:35
tc_825b845c start_extraction_batch 18ms 2026-06-06T08:11:37
tc_af97f313 start_extraction_batch 13ms 2026-06-06T08:11:39
tc_35c4b86f run_mmls 0ms 2026-06-06T08:11:39
tc_1f3eeabe run_fls 167642ms 2026-06-06T08:14:27
tc_4eeb764c yara_scan_memory 171567ms 2026-06-06T08:14:29
tc_e04b3d9d scan_evidence 115ms 2026-06-06T08:16:57
tc_57bb866a open_case 52ms 2026-06-06T08:22:06
tc_d4e2bbac open_case 16ms 2026-06-06T08:23:04
tc_3204d99b start_extraction_batch 31ms 2026-06-06T08:23:14
tc_758be7a0 run_mmls 0ms 2026-06-06T08:23:14
tc_616c1dd2 run_fls 66020ms 2026-06-06T08:24:20
tc_03e21bf1 run_volatility_batch 855938ms 2026-06-06T08:25:53
tc_9857f16b yara_scan_memory 218475ms 2026-06-06T08:26:58
tc_d406bc2d run_volatility_batch 998135ms 2026-06-06T08:28:15
tc_b69fb26b run_volatility_batch 396131ms 2026-06-06T08:29:50
tc_4096bae3 run_bulk_extractor 1223697ms 2026-06-06T08:32:03
tc_8e60cf23 wait_all 1222342ms 2026-06-06T08:32:06
tc_47fb25d5 get_completed_results 0ms 2026-06-06T08:37:12
tc_d049c462 get_completed_results 0ms 2026-06-06T08:41:08
tc_dee89a98 start_extraction_batch 97ms 2026-06-06T08:41:18
tc_da29d2d4 run_hayabusa 34ms 2026-06-06T08:41:18
tc_43bfe21c run_chainsaw 123ms 2026-06-06T08:41:23
tc_a1a6fa5a run_amcache_parser 60864ms 2026-06-06T08:42:23
tc_b2edff08 run_prefetch_parser 91904ms 2026-06-06T08:42:54
tc_2b716b21 run_mft_parser 110540ms 2026-06-06T08:43:13
tc_bd39f3f6 run_evtx_parser 128335ms 2026-06-06T08:43:31
tc_cf801298 run_shimcache_parser 151757ms 2026-06-06T08:43:54
tc_da3036a5 run_bulk_extractor 1462108ms 2026-06-06T08:47:41
tc_52b66b04 get_completed_results 0ms 2026-06-06T08:47:48
tc_8ab4888c start_extraction_batch 56ms 2026-06-06T08:47:57
tc_220f1062 run_chainsaw 130ms 2026-06-06T08:47:57
tc_7a7a3d16 run_hayabusa 137ms 2026-06-06T08:47:57
tc_a278957e open_case 85ms 2026-06-06T08:56:05
tc_7ae07cf8 get_source_stats 50127ms 2026-06-06T08:57:02
tc_b056c57d run_mft_parser 548421ms 2026-06-06T08:57:06
tc_418b5d68 run_amcache_parser 558142ms 2026-06-06T08:57:15
tc_75f06782 run_prefetch_parser 575344ms 2026-06-06T08:57:32
tc_249a3d57 start_extraction_batch 33ms 2026-06-06T08:57:51
tc_43efc609 run_hayabusa 52ms 2026-06-06T08:57:51
tc_f968569a run_evtx_parser 595292ms 2026-06-06T08:57:52
tc_28e00d00 yara_scan_files 601684ms 2026-06-06T08:57:59
tc_d2b0fe5d run_shimcache_parser 615271ms 2026-06-06T08:58:12
tc_e0529ae1 run_prefetch_parser 51198ms 2026-06-06T08:58:47
tc_d4088db1 run_shimcache_parser 89437ms 2026-06-06T08:59:21
tc_b8dfe856 get_completed_results 0ms 2026-06-06T08:59:25
tc_70d4d37c index_evtx_file 1535ms 2026-06-06T08:59:33
tc_5325314a index_evtx_file 378ms 2026-06-06T08:59:33
tc_f3442962 index_evtx_file 370ms 2026-06-06T08:59:34
tc_c8906627 open_case 12ms 2026-06-06T09:00:24
tc_72e6767a get_investigation_summary 24ms 2026-06-06T09:00:29
tc_0a10984d get_source_stats 24141ms 2026-06-06T09:00:54
tc_350face7 list_sources 11ms 2026-06-06T09:00:56
tc_f5ad2dd6 get_findings 4ms 2026-06-06T09:01:07
tc_d03a6962 get_process_tree 9ms 2026-06-06T09:01:09
tc_19d42dbc find_suspicious_processes._query(volatility.malfind) 753ms 2026-06-06T09:01:10
tc_339d6b34 find_suspicious_processes._query(volatility.cmdline) 248ms 2026-06-06T09:01:10
tc_781644ca find_suspicious_processes._query(volatility.netscan) 244ms 2026-06-06T09:01:11
tc_126b182a find_suspicious_processes._query(volatility.pstree) 250ms 2026-06-06T09:01:11
tc_b5e3f2db find_suspicious_processes._query(volatility.psscan) 208ms 2026-06-06T09:01:11
tc_8f7c5714 find_suspicious_processes._query(volatility.pslist) 213ms 2026-06-06T09:01:11
tc_ef1daf6a find_suspicious_processes._query(volatility.dlllist) 256ms 2026-06-06T09:01:12
tc_dec900ce find_suspicious_processes 2180ms 2026-06-06T09:01:12
tc_35746b03 search 413ms 2026-06-06T09:01:43
tc_1d767543 search 172ms 2026-06-06T09:01:43
tc_307398ac run_registry_parser 835515ms 2026-06-06T09:01:53
tc_281c02ec get_completed_results 0ms 2026-06-06T09:02:02
tc_cfff6fbb get_raw_output 23801ms 2026-06-06T09:02:07
tc_00c85f2f start_extraction_batch 3ms 2026-06-06T09:02:09
tc_c9a551e5 run_amcache_parser 25097ms 2026-06-06T09:02:34
tc_35b64691 search 363ms 2026-06-06T09:02:39
tc_ac8c179c search 894ms 2026-06-06T09:02:40
tc_69511331 get_raw_output 10556ms 2026-06-06T09:02:51
tc_88979068 run_prefetch_parser 62048ms 2026-06-06T09:03:11
tc_75e2b12a run_shimcache_parser 88425ms 2026-06-06T09:03:37
tc_a6ea3d9d search 671ms 2026-06-06T09:03:56
tc_24f459bd search 311ms 2026-06-06T09:03:56
tc_e29f965b search 1269ms 2026-06-06T09:03:57
tc_7977b3d2 open_case 50ms 2026-06-06T09:04:01
tc_aaba6a88 wait_all 0ms 2026-06-06T09:04:05
tc_8a710a80 get_raw_output 734ms 2026-06-06T09:04:16
tc_10f7aec5 search 318ms 2026-06-06T09:04:17
tc_294d05c9 search 73ms 2026-06-06T09:04:17
tc_30c01c77 open_case 20ms 2026-06-06T09:04:27
tc_943b43ec get_investigation_summary 28ms 2026-06-06T09:04:32
tc_05b0129b search 340ms 2026-06-06T09:04:41
tc_41d39d5d search 1949ms 2026-06-06T09:04:44
tc_efaaec20 search 598ms 2026-06-06T09:04:44
tc_8b75c34a get_source_stats 25015ms 2026-06-06T09:04:58
tc_c6187020 list_sources 15ms 2026-06-06T09:05:00
tc_d86c96fb search 159ms 2026-06-06T09:05:12
tc_38a21ae6 search 67ms 2026-06-06T09:05:12
tc_9768ef79 get_findings 7ms 2026-06-06T09:05:12
tc_a41c6625 get_findings 5ms 2026-06-06T09:05:20
tc_3c313619 search 92ms 2026-06-06T09:05:20
tc_64d7eca2 search 72ms 2026-06-06T09:05:21
tc_7ef18f8d search 328ms 2026-06-06T09:05:31
tc_12a40aeb list_directory 4ms 2026-06-06T09:05:31
tc_41ea2b2f search 61ms 2026-06-06T09:05:49
tc_32113eb8 search 159ms 2026-06-06T09:06:01
tc_219c5208 search 86ms 2026-06-06T09:06:01
tc_9f8bf3f2 search 86ms 2026-06-06T09:06:02
tc_ecf4e55e search 82ms 2026-06-06T09:06:02
tc_0a821c5a search 68ms 2026-06-06T09:06:12
tc_b4fea2de search 143ms 2026-06-06T09:06:12
tc_9da77de3 search 94ms 2026-06-06T09:06:13
tc_21b031b8 search 645ms 2026-06-06T09:06:30
tc_a8a9cc62 search 335ms 2026-06-06T09:06:31
tc_2e16c9e4 search 308ms 2026-06-06T09:06:31
tc_9d1c6325 search 768ms 2026-06-06T09:06:42
tc_ce2e634b run_evtx_parser 0ms 2026-06-06T09:06:42
tc_66186a53 decode_payload 26ms 2026-06-06T09:06:42
tc_dd8768a7 search 27ms 2026-06-06T09:06:43
tc_fc085250 search 336ms 2026-06-06T09:06:44
tc_4e21d89f search 507ms 2026-06-06T09:06:59
tc_f2377d73 search 1121ms 2026-06-06T09:07:00
tc_b85c6533 get_raw_output 21436ms 2026-06-06T09:07:22
tc_e404a23e get_raw_output 31517ms 2026-06-06T09:07:22
tc_5fb52880 list_directory 37ms 2026-06-06T09:07:36
tc_25b53971 search 663ms 2026-06-06T09:07:37
tc_cd819765 list_directory 6ms 2026-06-06T09:07:41
tc_5852e067 list_directory 10ms 2026-06-06T09:07:47
tc_f554bd0e get_raw_output 6906ms 2026-06-06T09:07:53
tc_be9033ac search 128ms 2026-06-06T09:07:53
tc_e368fb48 get_raw_output 14189ms 2026-06-06T09:08:07
tc_afe3d00b search 95ms 2026-06-06T09:08:07
tc_bf8833b3 search 78ms 2026-06-06T09:08:42
tc_751f561e search 44ms 2026-06-06T09:08:42
tc_ca244314 search 21ms 2026-06-06T09:08:43
tc_16f074f5 search 40ms 2026-06-06T09:08:56
tc_371efca6 search 93ms 2026-06-06T09:08:56
tc_ef30fea3 search 819ms 2026-06-06T09:08:58
tc_7886512f find_suspicious_processes._query(volatility.malfind) 779ms 2026-06-06T09:09:11
tc_fa9bed31 find_suspicious_processes._query(volatility.cmdline) 240ms 2026-06-06T09:09:11
tc_0d4ca29d find_suspicious_processes._query(volatility.netscan) 242ms 2026-06-06T09:09:12
tc_bfba5ed5 find_suspicious_processes._query(volatility.pstree) 231ms 2026-06-06T09:09:12
tc_23252f51 find_suspicious_processes._query(volatility.psscan) 238ms 2026-06-06T09:09:12
tc_53d0cdd2 find_suspicious_processes._query(volatility.pslist) 228ms 2026-06-06T09:09:12
tc_82046ceb find_suspicious_processes._query(volatility.dlllist) 235ms 2026-06-06T09:09:13
tc_d339af1e find_suspicious_processes 2203ms 2026-06-06T09:09:13
tc_3bf5d403 get_process_tree 4ms 2026-06-06T09:09:13
tc_7421e7e0 search 45ms 2026-06-06T09:09:13
tc_c461a7a8 submit_finding 22ms 2026-06-06T09:09:30
tc_822957a2 submit_finding 22ms 2026-06-06T09:09:37
tc_a3b2c92a get_raw_output 14177ms 2026-06-06T09:09:40
tc_405e5e4e submit_finding 22ms 2026-06-06T09:09:47
tc_49a65d26 get_raw_output 14095ms 2026-06-06T09:09:57
tc_815054ce submit_finding 24ms 2026-06-06T09:10:03
tc_2aa15451 get_raw_output 13914ms 2026-06-06T09:10:11
tc_33087f7f submit_finding 31ms 2026-06-06T09:10:12
tc_8624dc96 submit_finding 19ms 2026-06-06T09:10:19
tc_093a9dab search 338ms 2026-06-06T09:10:27
tc_28e83ea3 search 57ms 2026-06-06T09:10:27
tc_0f1c97cf search 2179ms 2026-06-06T09:10:30
tc_d368a531 search 35ms 2026-06-06T09:10:46
tc_266162f2 search 666ms 2026-06-06T09:10:48
tc_3d8e5b7f list_sources 7ms 2026-06-06T09:10:48
tc_b1f9b1bd search 237ms 2026-06-06T09:11:04
tc_7f3846b7 search 387ms 2026-06-06T09:11:06
tc_b4fab9f2 search 80ms 2026-06-06T09:11:06
tc_98db80e4 search 684ms 2026-06-06T09:11:09
tc_eb9eb4e7 search 1287ms 2026-06-06T09:11:11
tc_f94c5119 search 58ms 2026-06-06T09:11:11
tc_a28b47d0 submit_finding 15ms 2026-06-06T09:11:28
tc_275824ac get_investigation_summary 20ms 2026-06-06T09:11:39
tc_da959893 get_findings 4ms 2026-06-06T09:11:39
tc_b23db012 get_raw_output 6845ms 2026-06-06T09:11:53
tc_b4b6bae6 search 392ms 2026-06-06T09:11:53
tc_c9a5610d search 413ms 2026-06-06T09:11:54
tc_2c8a4e14 track_progress 19ms 2026-06-06T09:12:05
tc_9d545bf4 search 58ms 2026-06-06T09:12:34
tc_63252390 search 38ms 2026-06-06T09:12:35
tc_e616e35e search 84ms 2026-06-06T09:12:35
tc_32f9ac26 search 1096ms 2026-06-06T09:12:37
tc_b7cdbdc6 get_investigation_summary 17ms 2026-06-06T09:12:42
tc_53652403 scan_evidence 49ms 2026-06-06T09:12:58
tc_8d704b31 open_case 20ms 2026-06-06T09:13:02
tc_acd9391a search 47ms 2026-06-06T09:13:05
tc_2ffb899b search 52ms 2026-06-06T09:13:05
tc_7a7a412b search 472ms 2026-06-06T09:13:06
tc_62970d7a search 53ms 2026-06-06T09:13:42
tc_925b5942 open_case 16ms 2026-06-06T09:13:42
tc_22c06ccc search 51ms 2026-06-06T09:13:43
tc_a207f355 search 43ms 2026-06-06T09:13:43
tc_a98411de start_extraction_batch 27ms 2026-06-06T09:13:49
tc_f19cd01d run_mmls 0ms 2026-06-06T09:13:49
tc_b53f321a get_raw_output 10605ms 2026-06-06T09:14:24
tc_3368a415 run_fls 76999ms 2026-06-06T09:15:06
tc_3ec26e83 search 3588ms 2026-06-06T09:19:28
tc_c9109378 submit_finding 35ms 2026-06-06T09:23:47
tc_c418671b submit_finding 1ms 2026-06-06T09:26:20
tc_2e46e9f9 search 655ms 2026-06-06T09:26:29
tc_2c5eaec1 search 126ms 2026-06-06T09:26:29
tc_71a308b5 search 308ms 2026-06-06T09:26:30
tc_bb9cfc71 submit_finding 11ms 2026-06-06T09:26:53
tc_4c6de672 search 285ms 2026-06-06T09:26:59
tc_12eee7d7 search 860ms 2026-06-06T09:27:00
tc_c151316c search 2724ms 2026-06-06T09:27:11
tc_44119bd7 search 137ms 2026-06-06T09:27:11
tc_559ed9c6 search 104ms 2026-06-06T09:27:24
tc_b82b5dbd get_deleted_files 7842ms 2026-06-06T09:27:32
tc_13c19c2e search 246ms 2026-06-06T09:27:43
tc_70e34cab search 74ms 2026-06-06T09:27:44
tc_2f5cdab9 submit_finding 11ms 2026-06-06T09:28:07
tc_1c1f42e1 search 91ms 2026-06-06T09:28:14
tc_bc392e2d search 1006ms 2026-06-06T09:28:25
tc_ec404e38 submit_finding 18ms 2026-06-06T09:28:57
tc_d6451e84 track_progress 14ms 2026-06-06T09:29:18
tc_735e508b get_investigation_summary 24ms 2026-06-06T09:30:13
tc_d31236ba open_case 20ms 2026-06-06T09:30:55
tc_644c9105 list_directory 11ms 2026-06-06T09:31:00
tc_34684894 list_sources 13ms 2026-06-06T09:31:00
tc_6788c8c7 search 40ms 2026-06-06T09:31:25
tc_e2de1ddd search 803ms 2026-06-06T09:31:26
tc_1ca065d5 search 132ms 2026-06-06T09:31:27
tc_33a9590c search 33ms 2026-06-06T09:31:27
tc_bf615fa0 list_directory 16ms 2026-06-06T09:31:44
tc_cb5dc5af list_directory 11ms 2026-06-06T09:31:49
tc_88dcc576 list_directory 3ms 2026-06-06T09:31:49
tc_98ad60ab list_directory 3ms 2026-06-06T09:31:50
tc_99013df5 list_directory 2ms 2026-06-06T09:31:50
tc_c55e2d10 open_case 17ms 2026-06-06T09:33:00
tc_d090caa5 run_bulk_extractor 1154344ms 2026-06-06T09:33:03
tc_69d493ef get_completed_results 0ms 2026-06-06T09:33:08
tc_645ecd62 start_extraction_batch 40ms 2026-06-06T09:33:09
tc_074540a3 start_extraction_batch 31ms 2026-06-06T09:33:16
tc_2bbe2ba7 run_amcache_parser 99362ms 2026-06-06T09:34:55
tc_90393917 run_mft_parser 117814ms 2026-06-06T09:35:13
tc_ad932d60 run_prefetch_parser 163596ms 2026-06-06T09:35:59
tc_713f69d2 run_evtx_parser 211232ms 2026-06-06T09:36:47
tc_2b4a5fbc run_shimcache_parser 237169ms 2026-06-06T09:37:13
tc_faf6c1b5 run_registry_parser 489445ms 2026-06-06T09:41:25
tc_a3ade1ba get_completed_results 0ms 2026-06-06T09:41:31
tc_579dee78 start_extraction_batch 33ms 2026-06-06T09:41:38
tc_db164f00 run_hayabusa 90ms 2026-06-06T09:41:38
tc_8c4a284d run_chainsaw 200ms 2026-06-06T09:41:38
tc_b72bbaa1 yara_scan_files 115874ms 2026-06-06T09:43:34
tc_d69ad83a get_completed_results 0ms 2026-06-06T09:43:39
tc_54fc3219 open_case 40ms 2026-06-06T09:44:04
tc_fd616d95 wait_all 0ms 2026-06-06T09:44:08
tc_7bdf2dda open_case 12ms 2026-06-06T09:44:34
tc_76980d17 run_volatility_batch 691769ms 2026-06-06T09:44:41
tc_d0426e09 get_investigation_summary 25ms 2026-06-06T09:44:42
tc_9a6fd114 get_source_stats 33431ms 2026-06-06T09:45:16
tc_d871216f list_sources 44ms 2026-06-06T09:45:18
tc_bb20a5b6 search 162ms 2026-06-06T09:45:28
tc_d657f96a search 336ms 2026-06-06T09:45:29
tc_a0161694 search 16ms 2026-06-06T09:45:29
tc_b04cfa14 search 75ms 2026-06-06T09:45:56
tc_556664bc search 119ms 2026-06-06T09:45:57
tc_e1e7a8af search 97ms 2026-06-06T09:45:57
tc_131fa565 search 543ms 2026-06-06T09:45:58
tc_96b935fa search 61ms 2026-06-06T09:46:06
tc_e4af112e get_raw_output 34470ms 2026-06-06T09:46:41
tc_17612d38 search 90ms 2026-06-06T09:46:44
tc_ed842d68 get_raw_output 3510ms 2026-06-06T09:46:56
tc_7c2abe8c search 806ms 2026-06-06T09:46:57
tc_7a398143 search 318ms 2026-06-06T09:46:57
tc_4f7f2bef search 61ms 2026-06-06T09:46:57
tc_9a7e94f6 search 268ms 2026-06-06T09:47:12
tc_5cba6078 search 3380ms 2026-06-06T09:47:16
tc_a19152b0 search 110ms 2026-06-06T09:47:32
tc_e5fc73e7 search 41ms 2026-06-06T09:47:33
tc_3266235d search 37ms 2026-06-06T09:47:33
tc_2b68df97 search 42ms 2026-06-06T09:47:33
tc_6b948bf9 search 336ms 2026-06-06T09:48:05
tc_6cb3e6c6 get_raw_output 31400ms 2026-06-06T09:48:36
tc_5dcc2763 search 815ms 2026-06-06T09:48:37
tc_cb33e02b search 35ms 2026-06-06T09:48:50
tc_5efe7b9a search 2625ms 2026-06-06T09:48:52
tc_d7949753 get_raw_output 926ms 2026-06-06T09:49:03
tc_e0b86d84 search 69ms 2026-06-06T09:49:03
tc_e8b2f175 search 35ms 2026-06-06T09:49:03
tc_06e8ff8e search 26ms 2026-06-06T09:49:26
tc_3ecae655 search 261ms 2026-06-06T09:49:27
tc_4a8309da search 709ms 2026-06-06T09:49:28
tc_ba235578 search 91ms 2026-06-06T09:49:58
tc_c083512f search 59ms 2026-06-06T09:49:58
tc_4c4b6a93 search 23ms 2026-06-06T09:49:58
tc_577a6d84 detect_timestomping 9534ms 2026-06-06T09:50:08
tc_d6d6040c get_raw_output 24391ms 2026-06-06T09:50:41
tc_1d805e0a search 94ms 2026-06-06T09:50:41
tc_8b677aaa get_deleted_files 7309ms 2026-06-06T09:50:48
tc_1d6e7b11 get_findings 30ms 2026-06-06T09:51:17
tc_6492ef7f search 112ms 2026-06-06T09:51:28
tc_6fe1de22 search 548ms 2026-06-06T09:51:30
tc_b02416fa search 34ms 2026-06-06T09:51:30
tc_796b4828 triage_binary 302ms 2026-06-06T09:53:30
tc_29561007 search 608ms 2026-06-06T09:53:31
tc_cfba6703 search 49ms 2026-06-06T09:53:31
tc_d3126b8b extract_file_by_inode 328ms 2026-06-06T09:53:58
tc_56b81ec0 run_volatility_batch 1266932ms 2026-06-06T09:54:16
tc_0a181906 get_raw_output 37906ms 2026-06-06T09:54:36
tc_6edabdcc search 268ms 2026-06-06T09:54:36
tc_ab2a13f3 search 208ms 2026-06-06T09:55:12
tc_f3b1d43d search 11055ms 2026-06-06T09:55:23
tc_f456c2e7 search 151ms 2026-06-06T09:55:32
tc_16188147 search 25ms 2026-06-06T09:55:32
tc_cd399173 submit_finding 8ms 2026-06-06T09:56:14
tc_4e069cdf submit_finding 15ms 2026-06-06T09:56:24
tc_c65e851a submit_finding 8ms 2026-06-06T09:56:41
tc_14b522c1 submit_finding 7ms 2026-06-06T09:56:50
tc_b06ebd7c submit_finding 7ms 2026-06-06T09:57:06
tc_d3ee5963 submit_finding 8ms 2026-06-06T09:57:19
tc_c48e48c8 submit_finding 7ms 2026-06-06T09:57:39
tc_6a5544ea search 150ms 2026-06-06T09:57:39
tc_c6714440 run_volatility_batch 1474346ms 2026-06-06T09:57:44
tc_7cd6b96f search 223ms 2026-06-06T09:57:48
tc_ec68fab4 search 121ms 2026-06-06T09:57:49
tc_3f734ef1 search 343ms 2026-06-06T09:57:49
tc_66105ca8 search 693ms 2026-06-06T09:57:59
tc_312d150b search 48ms 2026-06-06T09:57:59
tc_42304342 search 1884ms 2026-06-06T09:58:01
tc_88f94100 search 51ms 2026-06-06T09:58:12
tc_7a5f7db9 search 2461ms 2026-06-06T09:58:15
tc_6c385b23 submit_finding 16ms 2026-06-06T09:58:41
tc_beae086f run_volatility_batch 1541895ms 2026-06-06T09:58:51
tc_144e6aa9 get_completed_results 0ms 2026-06-06T09:58:57
tc_a72c8a43 submit_finding 12ms 2026-06-06T09:58:59
tc_8b5110c0 track_progress 11ms 2026-06-06T09:59:22
tc_7321b41a get_investigation_summary 21ms 2026-06-06T10:00:09
tc_c4696c33 yara_scan_memory 101293ms 2026-06-06T10:00:42
tc_4d2a49d6 open_case 23ms 2026-06-06T10:00:47
tc_6aa9179d get_investigation_summary 33ms 2026-06-06T10:00:52
tc_4d6ffb1d list_sources 10ms 2026-06-06T10:00:52
tc_f1a903c2 search 456ms 2026-06-06T10:01:00
tc_561d2e69 open_case 43ms 2026-06-06T10:01:03
tc_6a37f932 wait_all 0ms 2026-06-06T10:01:03
tc_fdd5b9b0 search 70ms 2026-06-06T10:01:10
tc_5f0fc523 open_case 22ms 2026-06-06T10:01:23
tc_ec4e7479 get_investigation_summary 45ms 2026-06-06T10:01:27
tc_685d5637 list_sources 11ms 2026-06-06T10:01:27
tc_fe0646d8 search 140ms 2026-06-06T10:01:36
tc_9096ff34 search 2122ms 2026-06-06T10:01:39
tc_03b4c266 search 343ms 2026-06-06T10:01:40
tc_8815f683 search 104ms 2026-06-06T10:01:40
tc_a87b431c get_source_stats 30373ms 2026-06-06T10:01:40
tc_9e034750 list_directory 18ms 2026-06-06T10:01:55
tc_6e6aafd4 list_directory 16ms 2026-06-06T10:02:02
tc_e7744506 get_source_stats 29020ms 2026-06-06T10:02:16
tc_43fea313 search 129ms 2026-06-06T10:02:52
tc_4cbbb36a search 79ms 2026-06-06T10:02:52
tc_aacc9f1a search 78ms 2026-06-06T10:02:53
tc_d5219ff9 search 76ms 2026-06-06T10:02:54
tc_fce2032b search 88ms 2026-06-06T10:02:54
tc_80882858 list_sources 25ms 2026-06-06T10:02:59
tc_749736d2 search 2467ms 2026-06-06T10:03:02
tc_0e72fb11 search 62ms 2026-06-06T10:03:02
tc_c248043c search 6ms 2026-06-06T10:03:02
tc_bc650ee2 search 6ms 2026-06-06T10:03:02
tc_d5c0a356 search 6ms 2026-06-06T10:03:02
tc_4c6faf82 search 1093ms 2026-06-06T10:03:03
tc_37b47d67 search 1013ms 2026-06-06T10:03:04
tc_66fe0fcf search 222ms 2026-06-06T10:03:05
tc_2eca78ff search 8ms 2026-06-06T10:03:05
tc_7b148889 search 857ms 2026-06-06T10:03:05
tc_78350b5c search 31025ms 2026-06-06T10:03:05
tc_dbafa152 search 385ms 2026-06-06T10:03:05
tc_08023a85 search 46ms 2026-06-06T10:03:05
tc_55effc9b search 294ms 2026-06-06T10:03:05
tc_0ffed909 search 73ms 2026-06-06T10:03:06
tc_39c403ca search 60ms 2026-06-06T10:03:06
tc_dc53a579 search 82ms 2026-06-06T10:03:06
tc_7b033701 search 84ms 2026-06-06T10:03:07
tc_0d9fc57b search 50ms 2026-06-06T10:03:07
tc_97de55e5 search 70ms 2026-06-06T10:03:07
tc_1d5a7a0a search 32ms 2026-06-06T10:03:07
tc_06326d5b search 79ms 2026-06-06T10:03:08
tc_cd71fc63 search 28ms 2026-06-06T10:03:08
tc_2c1be445 get_findings 14ms 2026-06-06T10:03:08
tc_e2adfed7 search 36ms 2026-06-06T10:03:08
tc_716fdd0c search 5ms 2026-06-06T10:03:09
tc_8ebec980 search 5ms 2026-06-06T10:03:09
tc_69ea0394 search 5ms 2026-06-06T10:03:10
tc_8bde66ac search 6ms 2026-06-06T10:03:10
tc_30c27baa search 7ms 2026-06-06T10:03:10
tc_7f3cc489 scan_hidden_processes 32ms 2026-06-06T10:03:10
tc_80a4cbc4 scan_kernel_modules 20ms 2026-06-06T10:03:11
tc_0272f7e9 search 3343ms 2026-06-06T10:03:11
tc_f0cc944d list_sources 26ms 2026-06-06T10:03:14
tc_e9a95985 search 161ms 2026-06-06T10:03:16
tc_f2df639f list_sources 27ms 2026-06-06T10:03:19
tc_b396d3d3 get_raw_output 1893ms 2026-06-06T10:03:19
tc_833ce6ae search 82ms 2026-06-06T10:03:19
tc_bdb783fd search 86ms 2026-06-06T10:03:19
tc_a13cd137 search 9ms 2026-06-06T10:03:19
tc_7fab7a0f list_directory 6ms 2026-06-06T10:03:19
tc_14497df1 search 220ms 2026-06-06T10:03:20
tc_09c472fe list_directory 6ms 2026-06-06T10:03:20
tc_21073175 search 100ms 2026-06-06T10:03:20
tc_65bceb37 search 95ms 2026-06-06T10:03:20
tc_eae53dd5 get_process_tree 58ms 2026-06-06T10:03:21
tc_f71aacff list_processes_from_memory 24ms 2026-06-06T10:03:21
tc_157c85fa search 4850ms 2026-06-06T10:03:25
tc_14a026bc search 365ms 2026-06-06T10:03:28
tc_cf37c3d6 search 13ms 2026-06-06T10:03:29
tc_9ab468c6 search 26ms 2026-06-06T10:03:29
tc_021512e3 list_directory 9ms 2026-06-06T10:03:32
tc_ce9b2750 search 17723ms 2026-06-06T10:03:34
tc_a2be401f search 130ms 2026-06-06T10:03:34
tc_00c26494 run_volatility_batch 0ms 2026-06-06T10:03:39
tc_23aaf781 search 19102ms 2026-06-06T10:03:40
tc_8576ee3d search 466ms 2026-06-06T10:03:43
tc_a27adb93 search 37ms 2026-06-06T10:03:43
tc_f9897235 get_investigation_summary 15ms 2026-06-06T10:03:43
tc_82177d7b open_case 38ms 2026-06-06T10:03:44
tc_7ccb52cf extract_archive 5ms 2026-06-06T10:03:44
tc_2d353007 extract_archive 3ms 2026-06-06T10:03:45
tc_f5582e2b extract_archive 2ms 2026-06-06T10:03:45
tc_8663d127 get_raw_output 1260ms 2026-06-06T10:03:48
tc_1e3a6b78 search 155ms 2026-06-06T10:03:48
tc_3ae24443 search 17ms 2026-06-06T10:03:48
tc_dbd19020 search 19ms 2026-06-06T10:03:49
tc_dbd24d1c search 3093ms 2026-06-06T10:03:49
tc_fdcde275 search 89ms 2026-06-06T10:03:50
tc_cab780ab search 796ms 2026-06-06T10:03:50
tc_ade941c6 search 7ms 2026-06-06T10:03:50
tc_12514556 search 99ms 2026-06-06T10:03:50
tc_de8b5656 search 125ms 2026-06-06T10:03:50
tc_9241208c search 6ms 2026-06-06T10:03:51
tc_5e1cbf3d search 11ms 2026-06-06T10:03:51
tc_bc66baf6 search 1179ms 2026-06-06T10:03:52
tc_3219ef27 list_directory 5ms 2026-06-06T10:03:52
tc_ff263cbb search 36ms 2026-06-06T10:03:52
tc_aeaa4cb2 start_extraction_batch 147ms 2026-06-06T10:03:57
tc_0c1b7b1c get_raw_output 1552ms 2026-06-06T10:04:00
tc_08933611 get_raw_output 78ms 2026-06-06T10:04:00
tc_90cc1c7e search 170ms 2026-06-06T10:04:00
tc_dba2d114 search 69ms 2026-06-06T10:04:00
tc_6c130500 get_raw_output 83ms 2026-06-06T10:04:00
tc_f808bd64 search 12ms 2026-06-06T10:04:00
tc_018f3b6e list_directory 5ms 2026-06-06T10:04:01
tc_4908e26e search 12ms 2026-06-06T10:04:01
tc_c9b68406 list_directory 4ms 2026-06-06T10:04:01
tc_4adb620a list_directory 10ms 2026-06-06T10:04:08
tc_295ab417 get_raw_output 76ms 2026-06-06T10:04:08
tc_c75f1805 search 77ms 2026-06-06T10:04:09
tc_3db43a2f search 6ms 2026-06-06T10:04:09
tc_c90d0e14 get_raw_output 76ms 2026-06-06T10:04:09
tc_c1b0a556 search 26ms 2026-06-06T10:04:09
tc_a64bd7a8 search 465ms 2026-06-06T10:04:15
tc_4a62d77d get_raw_output 43939ms 2026-06-06T10:04:29
tc_981d2942 get_source_stats 42399ms 2026-06-06T10:04:29
tc_a70489d3 get_raw_output 79ms 2026-06-06T10:04:29
tc_a059436c list_directory 8ms 2026-06-06T10:04:32
tc_7fb18fd4 get_raw_output 1848ms 2026-06-06T10:04:33
tc_847b771a get_raw_output 3765ms 2026-06-06T10:04:33
tc_540525c3 get_source_stats 18077ms 2026-06-06T10:04:33
tc_bf37c2b3 get_raw_output 270ms 2026-06-06T10:04:34
tc_68d09d35 list_directory 44ms 2026-06-06T10:04:38
tc_87025930 list_directory 4ms 2026-06-06T10:04:38
tc_d4be05c6 search 153ms 2026-06-06T10:04:39
tc_257f5fed search 118ms 2026-06-06T10:04:43
tc_c4f1dda0 search 41ms 2026-06-06T10:04:44
tc_2dd9aeac list_directory 11ms 2026-06-06T10:04:46
tc_1bbd1cf9 search 2629ms 2026-06-06T10:04:47
tc_82b01a67 search 232ms 2026-06-06T10:04:47
tc_57d37375 run_volatility_batch 0ms 2026-06-06T10:04:53
tc_c99ca150 search 309ms 2026-06-06T10:04:55
tc_0281669a search 139ms 2026-06-06T10:04:56
tc_476c9c61 search 7ms 2026-06-06T10:04:57
tc_0aa5781a search 5951ms 2026-06-06T10:05:04
tc_401f23b8 get_raw_output 1483ms 2026-06-06T10:05:12
tc_dd4280ae search 762ms 2026-06-06T10:05:13
tc_040b221a search 378ms 2026-06-06T10:05:14
tc_ec703c4d get_raw_output 32063ms 2026-06-06T10:05:20
tc_e5000cad search 1631ms 2026-06-06T10:05:25
tc_e2945dd0 get_raw_output 31584ms 2026-06-06T10:05:56
tc_f948ee98 get_raw_output 27999ms 2026-06-06T10:05:56
tc_4048fe94 search 710ms 2026-06-06T10:06:00
tc_9d25e588 search 296ms 2026-06-06T10:06:00
tc_51f7511a search 136ms 2026-06-06T10:06:00
tc_8c95f7e6 search 196ms 2026-06-06T10:06:07
tc_45b15c7f search 76ms 2026-06-06T10:06:08
tc_08b0c2a4 search 235ms 2026-06-06T10:06:09
tc_dbc1fe1f search 1113ms 2026-06-06T10:06:10
tc_d9029b81 search 190ms 2026-06-06T10:06:18
tc_11f1b786 search 3205ms 2026-06-06T10:06:21
tc_488523dc run_volatility_batch 122465ms 2026-06-06T10:07:00
tc_47fe06d8 search 85ms 2026-06-06T10:07:08
tc_b5f4aa01 search 24ms 2026-06-06T10:07:08
tc_f7323eb2 search 31ms 2026-06-06T10:07:08
tc_299f1b7c search 11ms 2026-06-06T10:07:28
tc_0fe91c77 get_raw_output 30609ms 2026-06-06T10:07:59
tc_09f62339 search 885ms 2026-06-06T10:08:47
tc_6643d924 get_raw_output 42467ms 2026-06-06T10:09:30
tc_c77ea118 get_raw_output 2542ms 2026-06-06T10:09:42
tc_f5b4775f get_raw_output 31530ms 2026-06-06T10:10:14
tc_feacba0b search 805ms 2026-06-06T10:10:25
tc_cf7df671 search 202ms 2026-06-06T10:10:25
tc_ee55499e search 3010ms 2026-06-06T10:10:28
tc_6a045b01 search 133ms 2026-06-06T10:10:37
tc_5fce4d87 search 49ms 2026-06-06T10:10:38
tc_2bb01a39 search 45ms 2026-06-06T10:10:38
tc_555bbf4a run_volatility_batch 424834ms 2026-06-06T10:11:02
tc_19489c7d open_case 15ms 2026-06-06T10:12:28
tc_502d8b7f get_investigation_summary 23ms 2026-06-06T10:12:34
tc_e941c650 get_findings 5ms 2026-06-06T10:12:34
tc_5b080140 get_source_stats 29452ms 2026-06-06T10:13:03
tc_e411bc09 get_findings 5ms 2026-06-06T10:13:12
tc_68261b80 get_findings 5ms 2026-06-06T10:13:12
tc_d2203371 get_bookmarks 5ms 2026-06-06T10:13:24
tc_c7d4184c search 38ms 2026-06-06T10:13:24
tc_5a675fcb search 112ms 2026-06-06T10:13:34
tc_b8c927e5 search 72ms 2026-06-06T10:13:34
tc_9af581b0 search 33ms 2026-06-06T10:13:44
tc_62d62ffd search 2856ms 2026-06-06T10:13:47
tc_19c435b0 search 793ms 2026-06-06T10:14:02
tc_66808333 search 230ms 2026-06-06T10:14:02
tc_b685a0a5 search 95ms 2026-06-06T10:14:24
tc_885cf743 search 28ms 2026-06-06T10:14:26
tc_67037ef5 search 46ms 2026-06-06T10:14:38
tc_d9ef5d3c search 315ms 2026-06-06T10:14:39
tc_aeae3c99 get_raw_output 720ms 2026-06-06T10:14:50
tc_3808d8ea search 171ms 2026-06-06T10:14:50
tc_2e69cfc8 search 370ms 2026-06-06T10:15:18
tc_2b4ffb94 search 45ms 2026-06-06T10:15:19
tc_94019da7 get_raw_output 748ms 2026-06-06T10:15:27
tc_a99601d8 search 89ms 2026-06-06T10:15:27
tc_d750604e update_finding 12ms 2026-06-06T10:16:08
tc_63ec0187 update_finding 10ms 2026-06-06T10:16:08
tc_cf11ebb6 update_finding 12ms 2026-06-06T10:16:09
tc_b81c0eeb submit_finding 10ms 2026-06-06T10:16:29
tc_12d8de90 submit_finding 8ms 2026-06-06T10:16:48
tc_c280846d submit_finding 10ms 2026-06-06T10:17:09
tc_a51aced2 update_finding 12ms 2026-06-06T10:17:15
tc_30405990 submit_finding 9ms 2026-06-06T10:17:43
tc_7b5ab96c update_finding 8ms 2026-06-06T10:17:49
tc_bf294aee search 73ms 2026-06-06T10:17:50
tc_9f2ba1ed search 70ms 2026-06-06T10:17:59
tc_5b5cc5bb search 370ms 2026-06-06T10:17:59
tc_14375e22 get_raw_output 776ms 2026-06-06T10:18:14
tc_8982d31b search 862ms 2026-06-06T10:18:15
tc_d9425d94 submit_finding 9ms 2026-06-06T10:18:44
tc_a3674760 search 834ms 2026-06-06T10:20:35
tc_58e4dd0d search 369ms 2026-06-06T10:20:36
tc_72083e0e search 376ms 2026-06-06T10:20:36
tc_a6cca9b9 update_finding 11ms 2026-06-06T10:20:44
tc_e38defe1 get_source_stats 28993ms 2026-06-06T10:21:13
tc_dfd5eccd search 234ms 2026-06-06T10:21:23
tc_7b9c3efc search 607ms 2026-06-06T10:21:24
tc_00920e2c search 851ms 2026-06-06T10:21:45
tc_f998a908 search 68ms 2026-06-06T10:21:45
tc_52762417 search 258ms 2026-06-06T10:22:17
tc_46254594 search 1339ms 2026-06-06T10:22:18
tc_aaae333d get_raw_output 4078ms 2026-06-06T10:22:41
tc_0dcee2c9 search 381ms 2026-06-06T10:23:02
tc_52f7599d decode_payload 0ms 2026-06-06T10:25:00
tc_b48924db search 62ms 2026-06-06T10:25:14
tc_ed6dcd46 search 344ms 2026-06-06T10:25:15
tc_8b5703fa submit_finding 14ms 2026-06-06T10:25:57
tc_69bf6e17 run_volatility_batch 1323744ms 2026-06-06T10:26:01
tc_ebd773a5 get_raw_output 727ms 2026-06-06T10:26:06
tc_80506846 submit_finding 9ms 2026-06-06T10:26:39
tc_08547015 update_finding 10ms 2026-06-06T10:26:59
tc_0428ec25 run_volatility_batch 1388673ms 2026-06-06T10:27:05
tc_a0b4b81f track_progress 11ms 2026-06-06T10:27:17
tc_2223d1b8 get_investigation_summary 19ms 2026-06-06T10:27:34
tc_de4075cb run_volatility_batch 1432907ms 2026-06-06T10:27:50
tc_3c6a00be get_completed_results 0ms 2026-06-06T10:27:56
tc_bc35685e open_case 13ms 2026-06-06T10:28:03
tc_41c463cf list_directory 6ms 2026-06-06T10:28:10
tc_ecf1b02c list_directory 4ms 2026-06-06T10:28:15
tc_304d8b35 list_sources 14ms 2026-06-06T10:28:25
tc_06bc283d list_directory 4ms 2026-06-06T10:28:27
tc_80954be6 list_directory 4ms 2026-06-06T10:28:33
tc_a0c02f68 list_directory 4ms 2026-06-06T10:28:34
tc_6fd2ec9b list_directory 4ms 2026-06-06T10:28:35
tc_1b3839a4 list_directory 4ms 2026-06-06T10:28:35
tc_bb55cd7c search 113ms 2026-06-06T10:28:42
tc_485a6000 search 110ms 2026-06-06T10:28:42
tc_54b4c351 search 52ms 2026-06-06T10:28:43
tc_e44c8bee search 42ms 2026-06-06T10:28:43
tc_cccb3900 get_source_stats 30474ms 2026-06-06T10:29:25
tc_e2d5ea7a yara_scan_memory 103533ms 2026-06-06T10:29:44
tc_7575ca10 open_case 44ms 2026-06-06T10:30:00
tc_4b4c3154 wait_all 0ms 2026-06-06T10:30:01
tc_0bd326e8 open_case 22ms 2026-06-06T10:30:25
tc_ac37ab37 get_investigation_summary 40ms 2026-06-06T10:30:29
tc_a83a3f04 open_case 25ms 2026-06-06T10:30:49
tc_6cd295ba get_source_stats 27113ms 2026-06-06T10:30:56
tc_b2ce3910 start_extraction_batch 34ms 2026-06-06T10:30:58
tc_8229494b search 378ms 2026-06-06T10:31:07
tc_8ce30e07 search 139ms 2026-06-06T10:31:08
tc_aed187fa search 134ms 2026-06-06T10:31:08
tc_5c9cfdae search 139ms 2026-06-06T10:31:09
tc_912529b3 list_sources 15ms 2026-06-06T10:31:15
tc_05a33f0d search 344ms 2026-06-06T10:31:30
tc_7587fac6 get_raw_output 26590ms 2026-06-06T10:32:17
tc_e56fa5ec search 102ms 2026-06-06T10:32:35
tc_d9208dec search 86ms 2026-06-06T10:32:36
tc_0f12456a search 54ms 2026-06-06T10:32:36
tc_9070c1cb search 37ms 2026-06-06T10:32:51
tc_4d47022d search 1534ms 2026-06-06T10:32:53
tc_733cfb01 search 2541ms 2026-06-06T10:32:56
tc_7f73be3b get_findings 12ms 2026-06-06T10:33:19
tc_d30cde46 search 1344ms 2026-06-06T10:33:21
tc_a56ca10e search 91ms 2026-06-06T10:33:55
tc_c001fd33 search 141ms 2026-06-06T10:33:56
tc_f833ab4b search 167ms 2026-06-06T10:33:56
tc_ff133965 get_raw_output 858ms 2026-06-06T10:34:30
tc_321deca2 get_raw_output 20065ms 2026-06-06T10:34:50
tc_24e27d3c decode_payload 0ms 2026-06-06T10:35:33
tc_40efe655 search 80ms 2026-06-06T10:35:33
tc_c4f93619 decode_payload 1ms 2026-06-06T10:35:40
tc_7896bbde search 106ms 2026-06-06T10:35:40
tc_a8df8353 search 44ms 2026-06-06T10:36:28
tc_f7914606 decode_payload 120ms 2026-06-06T10:36:28
tc_8cac8cc4 scan_hidden_processes 86ms 2026-06-06T10:37:05
tc_dd1cc8eb search 754ms 2026-06-06T10:37:06
tc_33400b38 search 122ms 2026-06-06T10:39:23
tc_d6159c69 search 116ms 2026-06-06T10:39:24
tc_bf72b446 search 1803ms 2026-06-06T10:39:26
tc_f9bfbab6 run_volatility_batch 520769ms 2026-06-06T10:39:39
tc_59d084a3 search 107ms 2026-06-06T10:40:01
tc_ca6a4a98 search 293ms 2026-06-06T10:40:02
tc_32e6cd38 search 119ms 2026-06-06T10:40:02
tc_1ec62a19 submit_finding 78ms 2026-06-06T10:40:59
tc_b23fd3f0 submit_finding 14ms 2026-06-06T10:41:13
tc_9625dbc4 submit_finding 13ms 2026-06-06T10:41:29
tc_660586d3 submit_finding 9ms 2026-06-06T10:41:44
tc_ddb139ca submit_finding 78ms 2026-06-06T10:42:01
tc_0b8ecc5e search 1996ms 2026-06-06T10:42:08
tc_6535f63e search 27374ms 2026-06-06T10:42:36
tc_b05f90a7 submit_finding 10ms 2026-06-06T10:43:11
tc_ed625f8b submit_finding 8ms 2026-06-06T10:43:19
tc_7e72c60e submit_finding 9ms 2026-06-06T10:43:37
tc_4e3c86a3 search 60ms 2026-06-06T10:43:42
tc_0d5ab1cf search 493ms 2026-06-06T10:43:43
tc_bc894c34 get_findings 15ms 2026-06-06T10:43:57
tc_f5172ece run_volatility_batch 784880ms 2026-06-06T10:44:03
tc_f65c6bfa submit_finding 30ms 2026-06-06T10:44:23
tc_8f187757 track_progress 12ms 2026-06-06T10:44:34
tc_de714144 track_progress 7ms 2026-06-06T10:44:40
tc_504ca4b9 track_progress 9ms 2026-06-06T10:44:45
tc_69ce26f0 track_progress 7ms 2026-06-06T10:44:48
tc_ed0aad19 get_investigation_summary 30ms 2026-06-06T10:45:16
tc_40ea1c9e scan_evidence 33ms 2026-06-06T10:45:40
tc_d32b8f13 list_directory 5ms 2026-06-06T10:47:01
tc_5418491f list_directory 4ms 2026-06-06T10:47:02
tc_7463c5ce list_directory 4ms 2026-06-06T10:47:07
tc_b712b051 list_sources 16ms 2026-06-06T10:47:07
tc_2f696cd5 search 126ms 2026-06-06T10:47:19
tc_c6166898 search 33ms 2026-06-06T10:47:19
tc_98b9bdd9 open_case 13ms 2026-06-06T10:48:04
tc_e3664473 start_extraction_batch 17ms 2026-06-06T10:48:13
tc_ae9c90b5 start_extraction_batch 7ms 2026-06-06T10:48:14
tc_f257179a run_volatility_batch 1277987ms 2026-06-06T10:52:16
tc_7cdd6f99 run_volatility_batch 294094ms 2026-06-06T10:53:08
tc_a23b456d run_volatility_batch 1355367ms 2026-06-06T10:53:34
tc_afdb8418 get_completed_results 0ms 2026-06-06T10:53:39
tc_73f03b2a start_extraction_batch 1ms 2026-06-06T10:53:45
tc_4fbd9fa6 yara_scan_memory 104694ms 2026-06-06T10:55:29
tc_9cedcd66 get_completed_results 0ms 2026-06-06T10:55:35
tc_75a75919 open_case 13ms 2026-06-06T10:55:57
tc_ea75fc72 get_investigation_summary 31ms 2026-06-06T10:56:01
tc_ff6cf472 get_source_stats 32506ms 2026-06-06T10:56:33
tc_b73b5753 find_suspicious_processes._query(volatility.malfind) 1147ms 2026-06-06T10:56:45
tc_8d7c49cf find_suspicious_processes._query(volatility.cmdline) 309ms 2026-06-06T10:56:46
tc_ce4d0f70 find_suspicious_processes._query(volatility.netscan) 306ms 2026-06-06T10:56:46
tc_74f9ba4f find_suspicious_processes._query(volatility.pstree) 296ms 2026-06-06T10:56:46
tc_3608e3de find_suspicious_processes._query(volatility.psscan) 297ms 2026-06-06T10:56:47
tc_c2a7fc79 find_suspicious_processes._query(volatility.pslist) 288ms 2026-06-06T10:56:47
tc_06e27325 find_suspicious_processes._query(volatility.dlllist) 476ms 2026-06-06T10:56:47
tc_1d5fbc0a find_suspicious_processes 3135ms 2026-06-06T10:56:47
tc_a1bfd54a scan_hidden_processes 18ms 2026-06-06T10:56:47
tc_0e2dd863 scan_kernel_modules 23ms 2026-06-06T10:56:48
tc_38db20cd get_process_tree 8ms 2026-06-06T10:56:48
tc_1703568f run_volatility_batch 528624ms 2026-06-06T10:57:01
tc_a7d6fd4f search 340ms 2026-06-06T10:57:03
tc_893b5f27 search 35ms 2026-06-06T10:57:04
tc_e33d659f wait_all 526746ms 2026-06-06T10:57:06
tc_9f7ab972 search 4495ms 2026-06-06T10:57:09
tc_c4cc059a get_completed_results 0ms 2026-06-06T10:57:11
tc_ccf11d45 get_completed_results 0ms 2026-06-06T10:57:11
tc_f6ca3eae start_extraction_batch 2ms 2026-06-06T10:57:18
tc_591d2f4e decode_payload 0ms 2026-06-06T10:57:26
tc_1ad04615 search 262ms 2026-06-06T10:57:27
tc_5ed8bd30 search 2944ms 2026-06-06T10:57:30
tc_1016aad4 get_findings 18ms 2026-06-06T10:57:48
tc_1234cc57 get_raw_output 7675ms 2026-06-06T10:57:56
tc_96bb9770 get_findings 23ms 2026-06-06T10:58:09
tc_c42e70b6 search 256ms 2026-06-06T10:58:10
tc_6bfbd5bc get_findings 11ms 2026-06-06T10:58:19
tc_d8c74751 search 675ms 2026-06-06T10:58:20
tc_fdcffe26 yara_scan_memory 100538ms 2026-06-06T10:58:59
tc_b7c4e4e4 get_completed_results 0ms 2026-06-06T10:59:03
tc_e3a9646d open_case 36ms 2026-06-06T10:59:19
tc_a6e0c304 wait_all 0ms 2026-06-06T10:59:19
tc_d08ad382 open_case 40ms 2026-06-06T10:59:32
tc_9909e506 get_investigation_summary 29ms 2026-06-06T10:59:36
tc_47eb0eb4 list_sources 6ms 2026-06-06T10:59:36
tc_643ad9f1 search 100ms 2026-06-06T10:59:45
tc_485d5ff0 search 42ms 2026-06-06T10:59:45
tc_26239521 search 57ms 2026-06-06T10:59:46
tc_27791d9c search 29ms 2026-06-06T10:59:46
tc_4bce530b get_source_stats 27838ms 2026-06-06T11:00:20
tc_b76fbf1a search 237ms 2026-06-06T11:00:27
tc_39e0d78b search 190ms 2026-06-06T11:00:27
tc_404a87e2 search 60ms 2026-06-06T11:00:35
tc_dfcb0f68 search 47ms 2026-06-06T11:00:35
tc_52f9dda3 search 54ms 2026-06-06T11:00:35
tc_aa5c57a1 search 60ms 2026-06-06T11:00:36
tc_7453df17 get_raw_output 817ms 2026-06-06T11:00:53
tc_bc36392e get_raw_output 200ms 2026-06-06T11:00:53
tc_0b5bea30 search 61ms 2026-06-06T11:01:03
tc_3c53397f search 27ms 2026-06-06T11:01:03
tc_6b6edb55 search 423ms 2026-06-06T11:01:14
tc_f7d37834 search 249ms 2026-06-06T11:01:42
tc_85169414 search 1868ms 2026-06-06T11:01:44
tc_abe2c884 search 2368ms 2026-06-06T11:01:46
tc_680895e6 get_raw_output 28511ms 2026-06-06T11:01:46
tc_fdca035b search 197ms 2026-06-06T11:02:16
tc_0eb9ba08 search 757ms 2026-06-06T11:02:17
tc_12bcc4dd get_raw_output 27764ms 2026-06-06T11:02:30
tc_2b13d181 get_raw_output 1553ms 2026-06-06T11:02:45
tc_ad9401aa search 3738ms 2026-06-06T11:02:49
tc_90c42a95 get_raw_output 20075ms 2026-06-06T11:02:53
tc_b3de379c search 1915ms 2026-06-06T11:03:23
tc_825e18aa get_raw_output 28610ms 2026-06-06T11:03:24
tc_af127c6b get_raw_output 1210ms 2026-06-06T11:03:24
tc_331b14d7 get_raw_output 6453ms 2026-06-06T11:03:32
tc_c7614a06 search 2215ms 2026-06-06T11:03:46
tc_5e0d937a search 84ms 2026-06-06T11:03:46
tc_bff17e5c search 60ms 2026-06-06T11:03:46
tc_1e2f0885 search 355ms 2026-06-06T11:03:46
tc_a016152c search 352ms 2026-06-06T11:04:02
tc_2961a14c search 259ms 2026-06-06T11:04:02
tc_b811da6f search 202ms 2026-06-06T11:04:03
tc_c923ab2d search 71ms 2026-06-06T11:04:05
tc_98e68c1e search 50ms 2026-06-06T11:04:06
tc_5b1fe50b search 28ms 2026-06-06T11:04:06
tc_1254b33f search 972ms 2026-06-06T11:04:19
tc_097f363f search 82ms 2026-06-06T11:04:19
tc_eb5e6b69 decode_payload 2ms 2026-06-06T11:04:25
tc_3a32c805 scan_hidden_processes 24ms 2026-06-06T11:04:25
tc_98d2bf03 search 49ms 2026-06-06T11:04:26
tc_f70a7d55 search 31ms 2026-06-06T11:04:26
tc_20a2f3ee search 434ms 2026-06-06T11:04:55
tc_44b5269e search 230ms 2026-06-06T11:04:55
tc_5888f2c4 get_raw_output 686ms 2026-06-06T11:04:56
tc_8c87be03 submit_finding 21ms 2026-06-06T11:05:20
tc_3168c4d4 submit_finding 16ms 2026-06-06T11:05:44
tc_633899f6 get_findings 17ms 2026-06-06T11:05:47
tc_9be1c5b1 search 84ms 2026-06-06T11:05:48
tc_2be2ca6e submit_finding 15ms 2026-06-06T11:06:04
tc_20be659f get_findings 12ms 2026-06-06T11:06:33
tc_f6c98bd4 search 248ms 2026-06-06T11:06:34
tc_d2d2060a search 890ms 2026-06-06T11:06:41
tc_6f993ee2 search 70ms 2026-06-06T11:06:41
tc_9afbec68 get_raw_output 703ms 2026-06-06T11:07:09
tc_33ba5844 get_findings 23ms 2026-06-06T11:08:40
tc_2728a7ed list_sources 13ms 2026-06-06T11:08:40
tc_30873166 get_findings 9ms 2026-06-06T11:08:50
tc_5c10a69d search 83ms 2026-06-06T11:09:07
tc_ca6adb56 search 28ms 2026-06-06T11:09:07
tc_1cdd895e get_source_stats 27517ms 2026-06-06T11:09:43
tc_d29b904f search 420ms 2026-06-06T11:09:48
tc_91cea853 search 51ms 2026-06-06T11:09:48
tc_5880fc44 get_raw_output 673ms 2026-06-06T11:10:16
tc_77d906a0 search 195ms 2026-06-06T11:10:16
tc_287cc0bf search 177ms 2026-06-06T11:10:55
tc_c3c902c7 search 50ms 2026-06-06T11:10:55
tc_99349433 submit_finding 17ms 2026-06-06T11:11:07
tc_9d7d16e2 track_progress 16ms 2026-06-06T11:11:20
tc_8d4bff6c track_progress 16ms 2026-06-06T11:11:26
tc_7c00cab7 track_progress 16ms 2026-06-06T11:11:30
tc_9070d6e6 track_progress 12ms 2026-06-06T11:11:33
tc_83e0936f get_raw_output 228ms 2026-06-06T11:11:43
tc_c1b348a4 search 2584ms 2026-06-06T11:11:47
tc_14a57b65 get_investigation_summary 20ms 2026-06-06T11:12:31
tc_2fed88d5 search 115ms 2026-06-06T11:13:01
tc_9ec85f58 search 85ms 2026-06-06T11:13:02
tc_11f47952 search 28ms 2026-06-06T11:13:12
tc_ccaff221 search 27ms 2026-06-06T11:13:12
tc_c0090a5e search 186ms 2026-06-06T11:13:23
tc_833d340e search 138ms 2026-06-06T11:13:23
tc_84df7239 search 1280ms 2026-06-06T11:13:49
tc_63b64e47 get_raw_output 700ms 2026-06-06T11:13:49
tc_8dd53546 submit_finding 22ms 2026-06-06T11:14:50
tc_1ac54180 submit_finding 15ms 2026-06-06T11:15:14
tc_ce1ce787 submit_finding 14ms 2026-06-06T11:15:44
tc_b13fb556 search 44ms 2026-06-06T11:17:44
tc_4abd8c0a scan_hidden_processes 36ms 2026-06-06T11:17:44
tc_cdb728e6 search 631ms 2026-06-06T11:17:45
tc_028a9484 search 212ms 2026-06-06T11:17:45
tc_6b5931e5 search 93ms 2026-06-06T11:18:05
tc_7da335ae search 51ms 2026-06-06T11:18:05
tc_96531f90 search 813ms 2026-06-06T11:18:07
tc_a4de5c67 search 397ms 2026-06-06T11:18:15
tc_fcd06883 track_progress 14ms 2026-06-06T11:18:47
tc_b05bbd67 track_progress 15ms 2026-06-06T11:18:53
tc_4a5d2e1f get_investigation_summary 22ms 2026-06-06T11:19:19
tc_7ee7a3e8 open_case 22ms 2026-06-06T11:19:31
tc_80616df8 get_findings 15ms 2026-06-06T11:19:35
tc_1431a169 get_investigation_summary 27ms 2026-06-06T11:19:36
tc_5463b892 get_source_stats 27796ms 2026-06-06T11:20:04
tc_79cf68dd get_bookmarks 4ms 2026-06-06T11:20:06
tc_95dfe2b7 get_findings 10ms 2026-06-06T11:20:13
tc_7e5afe35 get_findings 9ms 2026-06-06T11:20:13
tc_5e5aebcd get_findings 9ms 2026-06-06T11:20:13
tc_fe1cf1a6 get_timeline 1692ms 2026-06-06T11:20:16
tc_802b9021 list_sources 13ms 2026-06-06T11:20:16
tc_323c0cb3 get_ioc_summary 21865ms 2026-06-06T11:21:10
tc_16f783b6 open_case 22ms 2026-06-06T11:22:42
tc_d5c62e06 correlate_across_sources 270ms 2026-06-06T11:22:48
tc_158cc432 correlate_across_sources 1060ms 2026-06-06T11:22:49
tc_b1efd0f0 correlate_across_sources 149ms 2026-06-06T11:22:52
tc_57e20305 correlate_across_sources 73ms 2026-06-06T11:22:52
tc_e3da7bfa correlate_across_sources 298ms 2026-06-06T11:22:52
tc_24853f2b find_lateral_movement_indicators._search(all) 107ms 2026-06-06T11:22:52
tc_41d92d21 find_lateral_movement_indicators._search(all) 34ms 2026-06-06T11:22:52
tc_f9383e7e find_lateral_movement_indicators._search(all) 48ms 2026-06-06T11:22:52
tc_4096eafd find_lateral_movement_indicators._query(volatility.netscan) 592ms 2026-06-06T11:22:53
tc_d4882a38 find_lateral_movement_indicators._search(all) 45ms 2026-06-06T11:22:53
tc_7174a1e5 find_lateral_movement_indicators._search(all) 25ms 2026-06-06T11:22:53
tc_8e005962 find_lateral_movement_indicators._search(all) 61ms 2026-06-06T11:22:53
tc_58375581 find_lateral_movement_indicators 922ms 2026-06-06T11:22:53
tc_b6e1ae9b find_persistence_mechanisms._query(registry.system) 758ms 2026-06-06T11:22:54
tc_4cb5d031 find_persistence_mechanisms._query(registry.software) 423ms 2026-06-06T11:22:54
tc_b8f824dd find_persistence_mechanisms._query(volatility.svcscan) 329ms 2026-06-06T11:22:55
tc_bc6b8226 find_persistence_mechanisms._search(all) 38ms 2026-06-06T11:22:55
tc_845feccc find_persistence_mechanisms._search(all) 29ms 2026-06-06T11:22:55
tc_22479b9d find_persistence_mechanisms._query(ez.amcache) 276ms 2026-06-06T11:22:55
tc_56470c5f find_persistence_mechanisms._search(all) 45ms 2026-06-06T11:22:55
tc_803e7145 find_persistence_mechanisms._query(tsk.filelist) 1662ms 2026-06-06T11:22:57
tc_9d6b7343 find_persistence_mechanisms 3927ms 2026-06-06T11:22:57
tc_da6f0c80 find_data_exfiltration_indicators._query(bulk.url) 7270ms 2026-06-06T11:23:10
tc_802a38db find_data_exfiltration_indicators._query(bulk.email) 1720ms 2026-06-06T11:23:21
tc_6f871dde find_data_exfiltration_indicators._query(bulk.domain) 4090ms 2026-06-06T11:23:25
tc_7ba60897 find_data_exfiltration_indicators._query(volatility.netscan) 341ms 2026-06-06T11:23:31
tc_35e5b123 find_data_exfiltration_indicators._search(all) 82ms 2026-06-06T11:23:31
tc_d60adc32 find_data_exfiltration_indicators 28488ms 2026-06-06T11:23:31
tc_14529128 open_case 47ms 2026-06-06T11:24:08
tc_f541f830 find_data_exfiltration_indicators._query(bulk.url) 6760ms 2026-06-06T11:24:24
tc_06681b96 find_data_exfiltration_indicators._query(bulk.email) 1663ms 2026-06-06T11:24:35
tc_15c9672c find_data_exfiltration_indicators._query(bulk.domain) 4188ms 2026-06-06T11:24:39
tc_919d27f8 find_data_exfiltration_indicators._query(volatility.netscan) 347ms 2026-06-06T11:24:45
tc_77a25f16 find_data_exfiltration_indicators._search(all) 58ms 2026-06-06T11:24:45
tc_c370fca9 find_data_exfiltration_indicators 27998ms 2026-06-06T11:24:45
tc_3b340190 open_case 45ms 2026-06-06T11:25:15
tc_7f83a47b find_defense_evasion._search(all) 39ms 2026-06-06T11:25:20
tc_3fb8a25b find_defense_evasion._search(ez.mft) 21ms 2026-06-06T11:25:20
tc_031230b8 find_defense_evasion._search(all) 26ms 2026-06-06T11:25:20
tc_610d9906 find_defense_evasion._search(all) 12ms 2026-06-06T11:25:20
tc_27d61159 find_defense_evasion._query(volatility.psscan) 286ms 2026-06-06T11:25:21
tc_ef779b6b find_defense_evasion._query(volatility.pslist) 280ms 2026-06-06T11:25:21
tc_0d2feddc find_defense_evasion._search(all) 25ms 2026-06-06T11:25:21
tc_a7dc09fc find_defense_evasion._query(volatility.cmdline) 274ms 2026-06-06T11:25:21
tc_147b731e find_defense_evasion 970ms 2026-06-06T11:25:21
tc_db6e03b4 find_suspicious_processes._query(volatility.malfind) 322ms 2026-06-06T11:25:26
tc_b0e1c20b find_suspicious_processes._query(volatility.cmdline) 282ms 2026-06-06T11:25:27
tc_649dd7f2 find_suspicious_processes._query(volatility.netscan) 284ms 2026-06-06T11:25:27
tc_d6c41391 find_suspicious_processes._query(volatility.pstree) 295ms 2026-06-06T11:25:27
tc_c5db7b13 find_suspicious_processes._query(volatility.psscan) 277ms 2026-06-06T11:25:27
tc_c46dc0fd find_suspicious_processes._query(volatility.pslist) 273ms 2026-06-06T11:25:28
tc_01fa5372 find_suspicious_processes._query(volatility.dlllist) 415ms 2026-06-06T11:25:28
tc_6873efbd find_suspicious_processes 2168ms 2026-06-06T11:25:28
tc_18e402b0 reconstruct_execution_chains._query(volatility.pstree) 330ms 2026-06-06T11:25:34
tc_e52be2d3 reconstruct_execution_chains._query(volatility.cmdline) 285ms 2026-06-06T11:25:34
tc_b94ac69e reconstruct_execution_chains._query(volatility.netscan) 282ms 2026-06-06T11:25:34
tc_1dccb69b reconstruct_execution_chains._query(volatility.malfind) 285ms 2026-06-06T11:25:35
tc_c292a272 reconstruct_execution_chains._query(volatility.dlllist) 332ms 2026-06-06T11:25:35
tc_bce334e9 reconstruct_execution_chains 1525ms 2026-06-06T11:25:35
tc_5d167450 find_execution_evidence._query(ez.amcache) 318ms 2026-06-06T11:25:40
tc_2762ceaf find_execution_evidence._query(volatility.pstree) 277ms 2026-06-06T11:25:40
tc_e878a530 find_execution_evidence 603ms 2026-06-06T11:25:40
tc_65cfd05b analyze_execution_timeline._query(ez.amcache) 286ms 2026-06-06T11:25:47
tc_3dbe656e analyze_execution_timeline 348ms 2026-06-06T11:25:47
tc_58288a36 find_file_staging._search(tsk.filelist) 24ms 2026-06-06T11:25:53
tc_a0c14bd0 find_file_staging._search(ez.mft) 12ms 2026-06-06T11:25:53
tc_3557b964 find_file_staging._query(tsk.filelist) 1039ms 2026-06-06T11:25:54
tc_6dc52e55 find_file_staging._query(ez.mft) 5497ms 2026-06-06T11:26:01
tc_f79e5ac8 find_file_staging._search(ez.mft) 85ms 2026-06-06T11:26:04
tc_1ba9d440 find_file_staging._search(ez.mft) 34ms 2026-06-06T11:26:04
tc_9d7b5e06 find_file_staging 11481ms 2026-06-06T11:26:04
tc_c0d7bb5c find_data_exfiltration_indicators._query(bulk.url) 6744ms 2026-06-06T11:26:21
tc_a1bb19eb find_data_exfiltration_indicators._query(bulk.email) 1565ms 2026-06-06T11:26:33
tc_eb76e6ce find_data_exfiltration_indicators._query(bulk.domain) 4176ms 2026-06-06T11:26:37
tc_d7bcb918 find_data_exfiltration_indicators._query(volatility.netscan) 336ms 2026-06-06T11:26:42
tc_fe6c027d find_data_exfiltration_indicators._search(all) 53ms 2026-06-06T11:26:42
tc_f27093bf find_data_exfiltration_indicators 27850ms 2026-06-06T11:26:42
tc_3d4c91e7 open_case 44ms 2026-06-06T11:27:08
tc_30d9c9ad assess_recovery._query(tsk.filelist) 1088ms 2026-06-06T11:27:14
tc_f7411768 assess_recovery._query(ez.amcache) 290ms 2026-06-06T11:27:15
tc_dee8dd3c assess_recovery 1445ms 2026-06-06T11:27:15
tc_302fe7f1 open_case 27ms 2026-06-06T11:27:48
tc_8c8e986d get_investigation_summary 29ms 2026-06-06T11:27:52
tc_12c6d32f get_findings 7ms 2026-06-06T11:27:52
tc_c3b3a5d0 get_findings 13ms 2026-06-06T11:27:58
tc_3398c111 get_findings 8ms 2026-06-06T11:27:59
tc_3dc764c6 get_findings 9ms 2026-06-06T11:27:59
tc_d5ada384 get_source_stats 7420ms 2026-06-06T11:28:07
tc_4b86da2a get_raw_output 5340ms 2026-06-06T11:28:24
tc_62c039de get_raw_output 5770ms 2026-06-06T11:28:32
tc_ae4fb9de get_raw_output 2021ms 2026-06-06T11:28:34
tc_052d6977 get_raw_output 5663ms 2026-06-06T11:28:42
tc_2b9a42c4 get_raw_output 5722ms 2026-06-06T11:28:54
tc_af18430f get_raw_output 5388ms 2026-06-06T11:28:59
tc_357b3d4d get_raw_output 5604ms 2026-06-06T11:29:05
tc_3cb7bcf2 get_raw_output 5619ms 2026-06-06T11:29:10
tc_2af66614 deduplicate_findings 240ms 2026-06-06T11:29:29
tc_a0f5fa3b get_ioc_summary 12771ms 2026-06-06T11:29:42
tc_d2732e48 lookup_attack_technique 167ms 2026-06-06T11:29:42
tc_2be887c9 deduplicate_findings 320ms 2026-06-06T11:29:57
tc_c10f5388 search 880ms 2026-06-06T11:31:25
tc_a217d119 search 541ms 2026-06-06T11:31:26
tc_d4c18198 search 26ms 2026-06-06T11:31:26
tc_480dcd7b search 59ms 2026-06-06T11:31:26
tc_3b68cd88 search 152ms 2026-06-06T11:31:34
tc_782e4ed1 search 66ms 2026-06-06T11:31:34
tc_57843b2b search 47ms 2026-06-06T11:31:35
tc_66c827bb search 96ms 2026-06-06T11:31:54
tc_c0650def search 208ms 2026-06-06T11:31:54
tc_2dcacf45 submit_finding 19ms 2026-06-06T11:32:23
tc_421e9c52 submit_finding 17ms 2026-06-06T11:32:30
tc_d0dcd445 submit_finding 11ms 2026-06-06T11:32:42
tc_e870cd4c submit_finding 10ms 2026-06-06T11:32:50
tc_e5a4cfc8 get_findings 10ms 2026-06-06T11:32:57
tc_b1fd395c get_findings 5ms 2026-06-06T11:32:57
tc_74ec245e get_findings 6ms 2026-06-06T11:32:57
tc_3ead028a get_findings 11ms 2026-06-06T11:33:04
tc_f6bc1d73 deduplicate_findings 172ms 2026-06-06T11:33:19
tc_7272efb0 deduplicate_findings 174ms 2026-06-06T11:33:37
tc_cdfd34f4 delete_finding 5ms 2026-06-06T11:33:37
tc_05fe0c27 delete_finding 15ms 2026-06-06T11:33:38
tc_5aa5894d delete_finding 11ms 2026-06-06T11:33:38
tc_58c91e02 delete_finding 14ms 2026-06-06T11:33:50
tc_fa31b025 delete_finding 11ms 2026-06-06T11:33:51
tc_ed8354c6 update_finding 23ms 2026-06-06T11:33:52
tc_9b3fcd0e update_finding 14ms 2026-06-06T11:33:53
tc_49c64fd2 delete_finding 10ms 2026-06-06T11:34:04
tc_67e4fbe3 update_finding 19ms 2026-06-06T11:34:25
tc_4c1feb51 get_investigation_summary 31ms 2026-06-06T11:35:04
tc_addeb2f0 update_finding 16ms 2026-06-06T11:35:18
tc_97eb2506 update_finding 17ms 2026-06-06T11:35:18
tc_3c856548 update_finding 17ms 2026-06-06T11:35:19
tc_aaeb53d5 update_finding 18ms 2026-06-06T11:35:19
tc_706c2770 update_finding 17ms 2026-06-06T11:35:20
tc_3e2ca87e update_finding 16ms 2026-06-06T11:35:34
tc_21f22799 update_finding 18ms 2026-06-06T11:35:35
tc_b7876a19 update_finding 23ms 2026-06-06T11:35:36
tc_6c50eaa4 update_finding 11ms 2026-06-06T11:35:36
tc_1c67ec9f update_finding 18ms 2026-06-06T11:35:37
tc_76518afb track_progress 20ms 2026-06-06T11:36:06
tc_61c9bb95 get_investigation_summary 18ms 2026-06-06T11:36:27
tc_06b7f6a5 open_case 25ms 2026-06-06T11:36:41
tc_5fb2d2f2 get_findings 16ms 2026-06-06T11:36:45
tc_f41d5c17 get_investigation_summary 26ms 2026-06-06T11:36:48
tc_7252b895 list_sources 8ms 2026-06-06T11:36:48
tc_d61f3e35 get_source_stats 7632ms 2026-06-06T11:37:08
tc_d760f4cb get_findings 8ms 2026-06-06T11:37:16
tc_5ff90817 get_timeline 860ms 2026-06-06T11:37:18
tc_f27b170d open_case 53ms 2026-06-06T11:40:17
tc_cd0356ff search 736ms 2026-06-06T11:40:24
tc_a26bd704 search 64ms 2026-06-06T11:40:24
tc_c808ec26 search 82ms 2026-06-06T11:40:24
tc_ab6417bb search 52ms 2026-06-06T11:40:25
tc_c0acb15f search 53ms 2026-06-06T11:40:26
tc_93850a34 search 43ms 2026-06-06T11:40:26
tc_00701064 search 646ms 2026-06-06T11:40:28
tc_89e38835 search 42ms 2026-06-06T11:40:28
tc_a20e4200 search 339ms 2026-06-06T11:40:29
tc_a1cee6d4 search 25ms 2026-06-06T11:40:29
tc_f4ba8aba search 29ms 2026-06-06T11:40:29
tc_fce8320a search 38ms 2026-06-06T11:40:30
tc_a4e458a8 search 29ms 2026-06-06T11:40:31
tc_625e5254 search 75ms 2026-06-06T11:40:31
tc_00cbe93f search 35ms 2026-06-06T11:40:32
tc_9c6ddce6 search 34ms 2026-06-06T11:40:33
tc_8acd8cce search 87ms 2026-06-06T11:40:33
tc_61122b91 search 201ms 2026-06-06T11:40:34
tc_4ee83e78 search 181ms 2026-06-06T11:40:35
tc_4114917b search 174ms 2026-06-06T11:40:35
tc_fe6151ad search 34ms 2026-06-06T11:40:36
tc_66643fdb search 928ms 2026-06-06T11:40:38
tc_bb0c3035 search 42ms 2026-06-06T11:40:38
tc_32c5f412 search 36ms 2026-06-06T11:40:38
tc_8e4a62bf search 29ms 2026-06-06T11:40:39
tc_49c20841 search 173ms 2026-06-06T11:40:40
tc_5bb9a5c2 search 647ms 2026-06-06T11:40:40
tc_0936e47d correlate_across_sources 299ms 2026-06-06T11:40:50
tc_7942fd70 correlate_across_sources 33ms 2026-06-06T11:40:50
tc_e5880213 correlate_across_sources 44ms 2026-06-06T11:40:51
tc_8ec00495 audit_evidence_coverage 50131ms 2026-06-06T11:41:42
tc_658f4219 audit_tool_coverage 9ms 2026-06-06T11:41:44
tc_03363eb8 deduplicate_findings 122ms 2026-06-06T11:41:45
tc_e20971da check_finalize_readiness 14ms 2026-06-06T11:41:45
tc_f1302cc3 open_case 37ms 2026-06-06T11:42:23
tc_bae74a8b get_findings 12ms 2026-06-06T11:42:24
tc_0096f9ff get_findings 12ms 2026-06-06T11:42:29
tc_c1c73b5a get_findings 5ms 2026-06-06T11:42:29
tc_704fa783 search 66ms 2026-06-06T11:43:18
tc_40f1e98b search 48ms 2026-06-06T11:43:18
tc_5d94d271 search 36ms 2026-06-06T11:43:19
tc_fde07b21 search 25ms 2026-06-06T11:43:19
tc_47e08b46 search 49ms 2026-06-06T11:43:26
tc_659471d6 search 16ms 2026-06-06T11:43:26
tc_b0339770 search 41ms 2026-06-06T11:43:27
tc_a490d0c7 search 67ms 2026-06-06T11:43:27
tc_1b522a45 search 40ms 2026-06-06T11:43:36
tc_f5079c54 search 39ms 2026-06-06T11:43:36
tc_d44a9882 search 48ms 2026-06-06T11:43:37
tc_d4383fee search 141ms 2026-06-06T11:44:07
tc_5ff0c40e search 233ms 2026-06-06T11:44:08
tc_c60eff1e deduplicate_findings 147ms 2026-06-06T11:44:09
tc_a1c23d0f get_raw_output 249ms 2026-06-06T11:44:59
tc_745592f2 search 56ms 2026-06-06T11:44:59
tc_2b5457b7 update_finding 23ms 2026-06-06T11:45:57
tc_b77fdd69 update_finding 14ms 2026-06-06T11:46:20
tc_7a27dfe0 update_finding 10ms 2026-06-06T11:46:33
tc_5fdb37ea update_finding 18ms 2026-06-06T11:47:01
tc_ab06a77c update_finding 18ms 2026-06-06T11:47:13
tc_e0e7554a update_finding 17ms 2026-06-06T11:47:42
tc_b4995764 update_finding 16ms 2026-06-06T11:47:55
tc_a4abca92 update_finding 12ms 2026-06-06T11:48:30
tc_fdeb1512 update_finding 15ms 2026-06-06T11:48:45
tc_9355194b update_finding 18ms 2026-06-06T11:48:58
tc_6e85d151 update_finding 17ms 2026-06-06T11:49:09
tc_a837fa9a audit_evidence_coverage 48072ms 2026-06-06T11:50:03
tc_5589278a audit_tool_coverage 11ms 2026-06-06T11:50:05
tc_d816800f check_finalize_readiness 16ms 2026-06-06T11:50:05
tc_2c4e2bc3 track_progress 21ms 2026-06-06T11:50:57
tc_1309acf1 get_investigation_summary 19ms 2026-06-06T11:51:41
tc_8603b871 check_finalize_readiness 15ms 2026-06-06T11:51:41
tc_1e7ffd5b open_case 16ms 2026-06-06T11:51:54
tc_f0b358c2 get_findings 16ms 2026-06-06T11:52:00
tc_e7ad7d1f get_investigation_summary 18ms 2026-06-06T11:52:03
tc_46670e69 get_ioc_summary 14359ms 2026-06-06T11:52:17
tc_53c93eab get_bookmarks 51ms 2026-06-06T11:52:17
tc_e7a7116e get_source_stats 10357ms 2026-06-06T11:52:28
tc_c6c9dcae get_findings 8ms 2026-06-06T11:52:47
tc_ef07eca7 submit_narrative 19ms 2026-06-06T11:56:47
tc_a981ade2 check_finalize_readiness 32ms 2026-06-06T11:56:53

Each finding traces back to the specific tool calls that produced the supporting evidence.

PowerView/PowerSploit Active Reconnaissance from Domain Controller 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "powershell", "regex": false, "source": "evtx...
tc_6d56b84a
1959ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "Invoke-UserHunter", "Invoke-ShareFinder", "Invoke-FileFin...
tc_5e2b911e
86ms
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server 5 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "powershell", "regex": false, "source": "vola...
tc_d9eff5a7
925ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "rundll32", "regex": false, "source": "volati...
tc_ac657197
42ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.4.10", "regex": false, "source": "vol...
tc_18f35d85
472ms
4
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "spsql", "regex": false, "source": "evtx", "t_...
tc_9a2617bb
119ms
5
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volatil...
tc_049f2680
44ms
WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11) 6 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "install_wormhole", "regex": false, "source":...
tc_3cce3174
54ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "malfind", "regex": false, "source": "volatil...
tc_5a1b743e
29ms
3
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.malfind" }
tc_b8b432ec
29053ms
4
get_raw_output
{ "after_id": 362608, "limit": 3, "source_name": "volatility.pstree" }
tc_c4f12402
409ms
5
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "sd.exe", "regex": false, "source": "registry....
tc_dd5b51dc
37ms
6
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.cmdline" }
tc_ec862127
17346ms
WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15) 8 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "7100", "regex": false, "source": "volatility...
tc_1c1f42e1
91ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volati...
tc_2c5eaec1
126ms
3
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "powershell", "regex": false, "source": "volat...
tc_3ec26e83
3588ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.netscan" }
tc_5449cb1b
9026ms
5
search
{ "exclude_sources": null, "max_results": 15, "queries": [ "WmiPrvSE", "wmiprvse", "wmi", "4072", "3164" ], "query": ...
tc_a615ccff
363ms
6
get_raw_output
{ "after_id": 654041, "limit": 5, "source_name": "volatility.psscan" }
tc_b53f321a
10605ms
7
scan_hidden_processes
tc_b83a24d3
15ms
8
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.psscan" }
tc_ce81377a
9145ms
Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP 3 refs
1
get_raw_output
{ "after_id": 1020907, "limit": 5, "source_name": "volatility.netscan" }
tc_aeae3c99
720ms
2
get_raw_output
{ "after_id": 1021149, "limit": 5, "source_name": "volatility.psscan" }
tc_94019da7
748ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "108.79.235.64", "regex": false, "source": nu...
tc_a99601d8
89ms
msadvapi2 Backdoor Malware Running as Services on Multiple Systems 3 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "msadvapi2", "regex": false, "source": "volat...
tc_59d084a3
107ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "msadvapi2", "regex": false, "source": null, ...
tc_33400b38
122ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "encodedcommand", "regex": false, "source": "...
tc_ca6a4a98
293ms
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor 4 refs
1
get_raw_output
{ "after_id": 1023700, "limit": 10, "source_name": "volatility.pstree" }
tc_7453df17
817ms
2
get_raw_output
{ "after_id": 1023724, "limit": 5, "source_name": "volatility.netscan" }
tc_bc36392e
200ms
3
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "base-rd-06", "base-wkstn-02", "base-wkstn-03", "BASE-SP" ...
tc_39e0d78b
190ms
4
get_raw_output
{ "after_id": 1023550, "limit": 3, "source_name": "volatility.pstree" }
tc_af127c6b
1210ms
Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 with 20+ Rundll32 Injections and WMI Stager 5 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "4896", "regex": false, "source": "volatility....
tc_2fed88d5
115ms
2
get_raw_output
{ "after_id": 1022007, "limit": 5, "source_name": "volatility.netscan" }
tc_63b64e47
700ms
3
get_raw_output
{ "after_id": 1021754, "limit": 10, "source_name": "volatility.pslist" }
tc_83e0936f
228ms
4
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "putty", "regex": false, "source": "volatility...
tc_c3c902c7
50ms
5
search
{ "exclude_sources": null, "max_results": 10, "queries": [ "p.exe", "5848", "8712", "8260" ], "query": "malfind", "re...
tc_f6c98bd4
248ms
Environment-Wide WMI→PowerShell(64→32)→Rundll32 Attack Chain Across 8+ Systems 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volati...
tc_782e4ed1
66ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "powershell.exe -nop -w hidden -encodedcomman...
tc_66c827bb
96ms
Environment-Wide C2 Proxy Tunneling via 172.16.4.10:8080 Across 7+ Systems 1 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.4.10:8080", "regex": false, "source":...
tc_3b68cd88
152ms
Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September) 2 refs
1
search
{ "exclude_sources": [ "tsk.filelist" ], "max_results": 20, "queries": null, "query": "msadvapi2", "regex": false, "s...
tc_57843b2b
47ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "powershell.exe -nop -w hidden -encodedcomman...
tc_66c827bb
96ms
Data Staging via Rar.exe on File Server 4 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "Rar.exe", "regex": false, "source": null, "t...
tc_2c193200
67ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "Rar", "regex": false, "source": "volatility.p...
tc_37a409ca
36ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "rundll32", "regex": false, "source": "volati...
tc_ac657197
42ms
4
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.psscan" }
tc_ce81377a
9145ms
Compromised SQL Service Account (spsql) Used for Domain Reconnaissance 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": [ "Get-Keystrokes", "Invoke-DllInjection", "Invoke-TokenMani...
tc_765d81e1
67ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "spsql", "regex": false, "source": null, "t_e...
tc_492eb01e
151ms
YARA Signature Matches: Codoso/Deep Panda Tooling in DC Memory 2 refs
1
get_raw_output
{ "after_id": 0, "limit": 5, "source_name": "yara.memory" }
tc_8c475b87
4370ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "APT", "regex": false, "source": "yara", "t_en...
tc_1e007ec4
34ms
Extensive C2 and Lateral Movement Network Connections from base-rd-02 7 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volatil...
tc_049f2680
44ms
2
get_raw_output
{ "after_id": 372958, "limit": 3, "source_name": "volatility.netscan" }
tc_164e59be
499ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.4.10", "regex": false, "source": "vol...
tc_18f35d85
472ms
4
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.7.15", "regex": false, "source": "vol...
tc_2e46e9f9
655ms
5
get_raw_output
{ "after_id": 0, "limit": 50, "source_name": "volatility.netscan" }
tc_5449cb1b
9026ms
6
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "172.16.4.10:8080", "regex": false, "source": ...
tc_71a308b5
308ms
7
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "5985", "regex": false, "source": "volatility....
tc_f91b8518
116ms
Attacker Staging Directories with Malicious Tooling on base-rd-02 2 refs
1
search
{ "exclude_sources": null, "max_results": 50, "queries": null, "query": "install_wormhole", "regex": false, "source":...
tc_3cce3174
54ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "sd.exe", "regex": false, "source": "registry....
tc_dd5b51dc
37ms
C2 Network Connections from base-wkstn-01 to 172.16.4.10:8080 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.7.11", "regex": false, "source": "vol...
tc_fc085250
336ms
2
get_raw_output
{ "after_id": 367610, "limit": 10, "source_name": "volatility.cmdline" }
tc_e368fb48
14189ms
Malicious Executable Dropped and Executed: c:\windows\temp\perfmon\p.exe 2 refs
1
get_raw_output
{ "after_id": 367610, "limit": 10, "source_name": "volatility.cmdline" }
tc_e368fb48
14189ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "perfmon\\\\p.exe", "regex": false, "source":...
tc_bf8833b3
78ms
Encoded PowerShell Stager Delivered to base-wkstn-01 via WinRM 3 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.7.11", "regex": false, "source": "evt...
tc_a8a9cc62
335ms
2
decode_payload
{ "data_length": 3020, "encoding": "utf16le", "extraction": { "extracted_from_source": "evtx.windows_system32_winevt_...
tc_66186a53
26ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.7.11", "regex": false, "source": "bul...
tc_41d39d5d
1949ms
WMI-Based Remote Code Execution on base-wkstn-01 2 refs
1
get_raw_output
{ "after_id": 367610, "limit": 10, "source_name": "volatility.cmdline" }
tc_e368fb48
14189ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volati...
tc_afe3d00b
95ms
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.7.11", "regex": false, "source": "vol...
tc_fc085250
336ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.7.11", "regex": false, "source": "bul...
tc_41d39d5d
1949ms
PowerView Active Directory Reconnaissance from Compromised Systems 1 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "4624", "regex": false, "source": "evtx", "t_e...
tc_b4fab9f2
80ms
Rundll32 Process Injection for Post-Exploitation on base-wkstn-05 3 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "volati...
tc_2c5eaec1
126ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "rundll32", "regex": false, "source": "volati...
tc_4e21d89f
507ms
3
get_raw_output
{ "after_id": 367610, "limit": 10, "source_name": "volatility.cmdline" }
tc_e368fb48
14189ms
WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation 2 refs
1
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "172.16.5.26", "regex": false, "source": "bul...
tc_6fe1de22
548ms
2
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "dblake", "regex": false, "source": "bulk.dom...
tc_16188147
25ms
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All Compromised Subnets 2 refs
1
get_raw_output
{ "after_id": 1020907, "limit": 5, "source_name": "volatility.netscan" }
tc_aeae3c99
720ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "172.16.5.21", "regex": false, "source": "vola...
tc_3808d8ea
171ms
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System 2 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "17016", "regex": false, "source": "volatility...
tc_0dcee2c9
381ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.6.15", "regex": false, "source": "vol...
tc_ed6dcd46
344ms
SearchUI.exe Shellcode Injection with C2 Connection to 172.16.4.10:8080 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "SearchUI.exe", "regex": false, "source": "vo...
tc_d6159c69
116ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.4.10", "regex": false, "source": "vol...
tc_bf72b446
1803ms
Process Injection in PowerShell on SearchUI System (172.16.6.14) 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "powershell", "regex": false, "source": "vola...
tc_6535f63e
27374ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "SearchUI.exe", "regex": false, "source": "vo...
tc_d6159c69
116ms
BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21) 3 refs
1
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "5985", "regex": false, "source": "volatility...
tc_0b8ecc5e
1996ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.5.25", "regex": false, "source": "vol...
tc_0d5ab1cf
493ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "msadvapi2", "regex": false, "source": "volat...
tc_59d084a3
107ms
base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection 2 refs
1
get_raw_output
{ "after_id": 1021771, "limit": 5, "source_name": "volatility.pstree" }
tc_5880fc44
673ms
2
get_raw_output
{ "after_id": 1022004, "limit": 2, "source_name": "volatility.netscan" }
tc_9afbec68
703ms
Remote PowerShell Reconnaissance by cbarton-a on base-rd-02 1 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "WmiPrvSE", "regex": false, "source": "evtx", ...
tc_eca43fd9
60ms
User Account tdungan Compromised — Active Session During Attack on base-rd-02 2 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "tdungan", "regex": false, "source": "evtx", "...
tc_2bb544be
787ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": [ "Dashlane", "OneDrive", "OUTLOOK" ], "query": "", "regex": ...
tc_294f8623
2210ms
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "rsydow", "regex": false, "source": "bulk.dom...
tc_29561007
608ms
2
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "dblake", "regex": false, "source": "bulk.dom...
tc_16188147
25ms
FTP Log Files Deleted - Potential Evidence Destruction on DMZ FTP Server 1 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "sub-win-x64", "regex": false, "source": null...
tc_cfba6703
49ms
FTP Data Exfiltration of User Profile Directories from DMZ FTP Server 2 refs
1
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "dblake", "regex": false, "source": "bulk.dom...
tc_16188147
25ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "rsydow", "regex": false, "source": "bulk.dom...
tc_29561007
608ms
External FTP User rsydow-f Authenticated with Cleartext Password Exposure 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "mprsydow@mail.com", "regex": false, "source"...
tc_ab2a13f3
208ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "165.227.50.129", "regex": false, "source": n...
tc_6492ef7f
112ms
Interactive User Access via rsydow-a Account on DMZ FTP Server 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "sub-win-x64", "regex": false, "source": null...
tc_cfba6703
49ms
2
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "rsydow", "regex": false, "source": "bulk.dom...
tc_29561007
608ms
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "108.79.235.64", "regex": false, "source": nu...
tc_a99601d8
89ms
Suspicious rundll32.exe on base-mail Exchange Server (PID 15116) 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "15116", "regex": false, "source": "volatilit...
tc_32e6cd38
119ms
Chrome.exe C2 Proxy Connection and Code Injection on System 172.16.5.20 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "172.16.4.10", "regex": false, "source": "vol...
tc_bf72b446
1803ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "powershell", "regex": false, "source": "vola...
tc_6535f63e
27374ms
base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Exposure 2 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.4.7", "regex": false, "source": "vola...
tc_0eb9ba08
757ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "SharePoint", "regex": false, "source": "vola...
tc_85169414
1868ms
sub-win-x64_base-hunt_5682_3262.exe — Likely F-Response Subject Agent Binary, Not Cobalt Strike Stager 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "sub-win-x64", "regex": false, "source": null...
tc_cfba6703
49ms
2
extract_file_by_inode
{ "inode": 33581 }
tc_d3126b8b
328ms
base-wkstn-02 (172.16.7.16) - Active Workstation with LARIAT but No Direct Compromise Indicators in Memory 2 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": [ "base-rd-06", "base-sp", "172.16.5.26", "172.16.7.16" ], "...
tc_d8c74751
675ms
2
get_raw_output
{ "after_id": 1023724, "limit": 5, "source_name": "volatility.netscan" }
tc_bc36392e
200ms
subject_srv.exe Identified as F-Response Forensic Remote Acquisition Agent (Not Malicious) 3 refs
1
extract_file_by_inode
{ "inode": 132140 }
tc_839221cf
240ms
2
scan_hidden_processes
tc_b83a24d3
15ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "subject_srv", "regex": false, "source": "reg...
tc_9b859299
31ms
YARA Memory Scan: APT6 Detections Assessed as False Positives 1 refs
1
scan_hidden_processes
tc_b83a24d3
15ms
Shadow Copy Enumeration via PowerShell on File Server — Likely Administrative Activity, Not Ransomware Preparation 2 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "ShadowCopy", "regex": false, "source": "evtx"...
tc_5df21172
56ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "spsql", "regex": false, "source": "evtx", "t_...
tc_9a2617bb
119ms
Cross-System Comparison: F-Response Agent (subject_srv.exe) Deployed Between Memory Captures — IR Activity, Not Attacker Persistence 3 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "Rar", "regex": false, "source": "volatility.p...
tc_37a409ca
36ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "subject_srv", "regex": false, "source": "vola...
tc_dd06c588
30ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "powershell", "regex": false, "source": "vola...
tc_d9eff5a7
925ms
Network IOC Summary: Internal C2 Infrastructure and Lateral Movement Targets 4 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "172.16.4.10", "regex": false, "source": "vol...
tc_18f35d85
472ms
2
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "subject_srv", "regex": false, "source": "vol...
tc_fc7bb189
26ms
3
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "5985", "regex": false, "source": "volatility....
tc_f91b8518
116ms
4
extract_file_by_inode
{ "inode": 132140 }
tc_65ace770
219ms
Timestomping Analysis: No Malicious Timestamp Manipulation Detected 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "subject_srv", "regex": false, "source": null...
tc_1cb6496c
29ms
YARA Disk Scan: Snake Malware Detection Assessed as False Positive on base-rd-02 1 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "Snake_Malware", "regex": false, "source": "ya...
tc_ad6b5e9b
44ms
DMZ FTP Server Configuration - IIS FTPSVC2 on Windows Server 2012 R2 3 refs
1
search
{ "exclude_sources": null, "max_results": 20, "queries": null, "query": "sub-win-x64", "regex": false, "source": null...
tc_cfba6703
49ms
2
search
{ "exclude_sources": null, "max_results": 15, "queries": null, "query": "dblake", "regex": false, "source": "bulk.dom...
tc_16188147
25ms
3
search
{ "exclude_sources": null, "max_results": 10, "queries": null, "query": "mprsydow@mail.com", "regex": false, "source"...
tc_ab2a13f3
208ms
Unindexed EVTX Event Logs on DMZ FTP Server - Analysis Gap 1 refs
1
search
{ "exclude_sources": null, "max_results": 10, "queries": [ ".zip", ".rar", ".7z", "archive" ], "query": "", "regex": ...
tc_7a5f7db9
2461ms
172.16.5.25 Identified as Forensic Workstation (base-hunt) with 15+ C2 Proxy Connections 2 refs
1
get_raw_output
{ "after_id": 1021149, "limit": 5, "source_name": "volatility.psscan" }
tc_94019da7
748ms
2
get_raw_output
{ "after_id": 1020907, "limit": 5, "source_name": "volatility.netscan" }
tc_aeae3c99
720ms
Exchange Server (172.16.4.6) Memory Dump - No C2 Indicators but Accessible to Attacker 1 refs
1
get_raw_output
{ "after_id": 1021979, "limit": 3, "source_name": "volatility.netscan" }
tc_14375e22
776ms
base-wkstn-06 (172.16.5.26) — Admin Workstation with Extensive Infrastructure Access, No Compromise Indicators 2 refs
1
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "putty", "regex": false, "source": "volatility...
tc_c3c902c7
50ms
2
search
{ "exclude_sources": null, "max_results": 5, "queries": null, "query": "wkstn-06", "regex": false, "source": "volatil...
tc_ca6adb56
28ms

Tool Call Details

Copied to clipboard