Investigation Dashboard
The attack timeline spans 2017-12-20 to 2018-09-07. The earliest activity was Attacker Staging Directories with Malicious Tooling on base-rd-02 (2017-12-20). The investigation subsequently uncovered Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September); base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor; Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP. The most recent activity was WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation (2018-09-07).
- PowerView/PowerSploit Active Reconnaissance from Domain Controller
- PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server
- WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)
- WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)
- Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP
-
PowerView/PowerSploit Active Reconnaissance from Domain Controller
2018-08-31T22:16:12 — 2018-08-31T22:52:08
-
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Server
2018-08-28T22:08:25 — 2018-09-06T22:11:15
-
WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11)
2018-08-30T16:43:36 — 2018-09-06T17:26:35
-
WMI-Initiated Multi-Chain PowerShell C2 Attack on base-wkstn-05 (172.16.7.15)
2018-08-31T01:14:44 — 2018-09-06T19:37:40
-
Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TTP
2018-08-15T16:32:11 — 2018-09-07T19:43:31
-
msadvapi2 Backdoor Malware Running as Services on Multiple Systems
2018-06-04T20:19:12
-
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Metasploit Stager, and msadvapi2 Backdoor
2018-06-04T20:19:38 — 2018-09-06T21:02:43
-
Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 with 20+ Rundll32 Injections and WMI Stager
2018-08-27T21:25:58 — 2018-09-06T19:08:45
-
Environment-Wide WMI→PowerShell(64→32)→Rundll32 Attack Chain Across 8+ Systems
2018-09-06T17:43:45 — 2018-09-07T19:43:31
-
Environment-Wide C2 Proxy Tunneling via 172.16.4.10:8080 Across 7+ Systems
2018-08-28T20:40:22
-
Dual Intrusion Campaigns: msadvapi2 Persistent Backdoor (Pre-August) and Metasploit PowerShell Operations (August-September)
2018-06-04T20:19:30 — 2018-09-07T19:43:31
| Case ID | SRL-2018 |
| Evidence Root | /evidence |
| Report Generated | 2026-06-06T11:57:33 |
| Investigation Start | 2026-06-06T06:19:22 |
| Investigation End | 2026-06-06T11:56:53 |
| Total Processing | 47849.4s |
| Audit Log | /home/mulder/.mulder/cases/SRL-2018.audit.jsonl |
Evidence Hashes
sha256sum <file>| File | SHA-256 | Size |
|---|---|---|
| base-admin-memory.7z | 65cd9e49db5d181dec1a34f4b4c67a04903007251700acb99b630485951a4950 | 1.0 GB |
| base-av-memory.7z | d61379467c4f9f27b1267b0e9a164fb01f7e47b5837074de98a8d7cca19d5f8f | 2.1 GB |
| base-dc-memory.7z | 70c3094eb6f814faf2e24c15c83e6a6da1b6d27e001097a2a839022bbea634ba | 808.2 MB |
| base-elf-memory.7z | c9241f92e0e9ac6c4b4885bd2a7a6ea63c70e1d7f0f465876f213e357a9bc6ff | 672.8 MB |
| base-file-memory.7z | 6a1df2332cb8157e3634f5fbee900afeefb5ad44044877e93ca0745e7e7920cf | 303.5 MB |
| base-file-snapshot5.7z | 905e88124c12336451cfe1ef00dc3abf6c7418e0552e329e3c840679d156a3a5 | 774.9 MB |
| base-hunt-memory.7z | 143640711ab5a0378dce3a7ac7c5e083166ab8155123fd14609772e76cdcd7e1 | 1.1 GB |
| base-mail-memory.7z | bde969728cddff1bc688c8eb55c44672f3d91714eea44d7ace715de842303f52 | 2.7 GB |
| base-rd-02-memory.7z | ec66f5076e6b699f251ab72a6102c5af4714dddf5dda7c83967050e6cbec5196 | 931.9 MB |
| base-rd-03-memory.7z | 6c1852e87b20cc02b28be2f2f373f8bdea07935072e56520a2a065100993653c | 932.8 MB |
| base-rd-04-memory.7z | cf03f019a566dcf7b40ced329a3cf9d5090e8c15203f6a4b97b9a512ced110d7 | 997.4 MB |
| base-rd-05-memory.7z | 31652764f1a1ad1cf66a9cc65569fa44e89a818e14075079a26e8e18dd4e5b5d | 513.6 MB |
| base-rd-06-memory.7z | ddc0d1e72fdfb54889c6a3800b10eaa9f1ffe86991def2c7b55b09215d88c465 | 578.6 MB |
| base-rd01-memory.7z | 59b8cd3022625ea310223a0ba33695668c9ce532a41cb53cb855e06634d8efd5 | 837.6 MB |
| base-sp-memory.7z | 7b1539b42f6faf31d83bdd7216cbb831de3bf09c80e1f608e805bcc5ec3e030c | 953.8 MB |
| base-wkstn-01-mem.zip | ef061848edb0d0014155f8ee43cbc67f759520fa96de249ffbd45045b602e29a | 1.2 GB |
| base-wkstn-01-memory.7z | 9c86f5290a25ffce013518a8c98daf90bf4be0ed37450b1239edf9239fe5cc07 | 984.4 MB |
| base-wkstn-02-memory.7z | c1f17907abd262e8f502078fde7058fe06ecc9b2f8cc047333906a01d407df78 | 969.2 MB |
| base-wkstn-03-memory.7z | 33f09a2c10aeceda5c079c55a20e4b2f4b834f4e94c7b770e262d0fc01b88992 | 890.0 MB |
| base-wkstn-04-memory.7z | 34f6cd35eea22e99b4affcd6e9af148ebaa8d8898397201d57f8d75044997697 | 895.5 MB |
| base-wkstn-05-memory.7z | 9e5184194499c01eddee7538ad23f5a7c74533c427ea387f70a249394cb3a4c2 | 625.5 MB |
| base-wkstn-06-memory.7z | ee7edd62c9960d855a8623d5d11506d1b74d40cec7f67e8ab108f81d92a1c5e5 | 549.2 MB |
| base-dc-cdrive.E01 | e2b9cf0cb6759fd079f45fa903d80bde602160ff969c969c6f0cd704965b31b1 | 11.5 GB |
| base-file-cdrive.E01 | ad9c85399fa8b2483f1d8a3684bc7e074b57d4c3ec88726cde271549bd742a18 | 15.3 GB |
| base-rd-01-cdrive.E01 | 12a622aa073dbbda3a4983014328a6085c8247ce93fe47fd6ba7483ed9d19aab | 16.6 GB |
| base-rd-02-cdrive.E01 | 50ad43ff0e8a0cc478e0e68f418b9f752fb440fd5020ca4fe55680292ac834bc | 16.0 GB |
| base-wkstn-01-c-drive.E01 | ede47a0733203134f92c8ae46df4f5106b78a2c357fdb1d3c84301261076429f | 15.8 GB |
| base-wkstn-05-cdrive.E01 | a94f2a866e2e562c58c3fbcd3a94882f2d3c3db3c66a5e5eedf16a4b1c0a65e0 | 13.8 GB |
| dmz-ftp-cdrive.E01 | d19754685d75aecb1fe18c3d75516dc0a965754335d981f3925e0e1b767ca8f8 | 11.9 GB |
Investigation Report
Background
This report documents the forensic investigation of a multi-system intrusion at Stark Research Labs (SRL), designated case SRL-2018. The investigation was initiated in response to suspected network compromise of the shieldbase.lan Active Directory domain. Digital forensic evidence was collected from multiple systems spanning the corporate server infrastructure, R&D workstations, and a DMZ-facing FTP server.
The evidence inventory comprised memory dumps from thirteen hosts across multiple network subnets, disk images from key systems including the file server (BASE-FILE), an R&D workstation (base-rd-02), a DMZ FTP server, and additional endpoints. The investigation indexed 18 distinct evidence sources using 1508 tool invocations across eleven extractor categories including Volatility 3 memory forensics, Sleuth Kit disk analysis, EZ Tools Windows artifact parsing, EVTX event log analysis, bulk_extractor IOC carving, YARA signature scanning, Chainsaw Sigma rule detection, and registry parsing. A total of 55 findings were submitted, of which 43 are corroborated by two or more independent sources and 12 represent single-source inferences requiring further validation. 46 distinct MITRE ATT&CK techniques were mapped across the investigation.
The Stark Research Labs environment operates a Windows Active Directory domain (shieldbase.lan) with infrastructure servers on the 172.16.4.x subnet (domain controller BASE-DC at 172.16.4.4, file server BASE-FILE at 172.16.4.5, Exchange server base-mail at 172.16.4.6, SharePoint server base-sp at 172.16.4.7), a management subnet at 172.16.5.x (forensic workstation base-hunt at 172.16.5.25, a key lateral movement convergence host at 172.16.5.21, and admin workstation at 172.16.5.26), R&D systems on the 172.16.6.x and 172.16.7.x subnets, and a DMZ FTP server at 172.16.10.12. A SoftEther VPN gateway at 172.16.1.20 provides external remote access. All internal systems route web traffic through an organizational HTTP proxy at 172.16.4.10:8080. McAfee endpoint protection suites were deployed across the environment but failed to detect the intrusion. Sysmon was running on at least one compromised host (base-wkstn-05) and similarly did not prevent compromise.
Incident Timeline
The investigation reconstructed an intrusion spanning from at least mid-2017 through early September 2018, characterized by two distinct but operationally linked campaigns. The timeline is organized into five phases reflecting the attack's progression from initial persistent access through active offensive operations.
Phase 1 — Persistent Backdoor Deployment (December 2017 – June 2018)
The earliest evidence of attacker activity is the creation of the msadvapi2 installer binary (install_msadvapi2_32.exe, 14,183,796 bytes) at C:\ProgramData\staging\install_wormhole\ on 2017-12-20 at 14:52:51 UTC. ShimCache records confirm this installer was executed on 2018-05-08 at 21:07:43, deploying the msadvapi2 backdoor suite. Both 32-bit and 64-bit variants were installed as Windows services under fabricated directory names ("C:\Program Files (x86)\Microsoft Advanced API 32\" and "Microsoft Advanced API 64\"), designed to mimic the legitimate Windows advapi32.dll library. A companion uninstaller (unins000.exe) was registered in the ShimCache at 2018-05-08 21:07:27, confirming a professionally packaged deployment. Memory forensics confirmed msadvapi2 processes running as children of services.exe across three systems: BASE-DC (172.16.4.4, PID 1072/1240), base-wkstn-03 (172.16.6.13, PIDs 2288/2304 since boot on 2018-08-17), and 172.16.6.15 (msadvapi2_64.exe). DLL analysis revealed the malware loads wpcap.dll (WinPcap packet capture library), IPHLPAPI.DLL, and network-related libraries, indicating network interception and packet capture capabilities. The backdoor persisted through reboots, confirmed by its presence in three independent memory captures spanning June through September 2018.
Phase 2 — Possible Early Detection and Triage (August 15, 2018)
On 2018-08-15 at approximately 16:32–16:36 UTC, the cbarton-a account conducted remote PowerShell reconnaissance against base-rd-02 (172.16.6.11) via WinRM. The commands executed — process enumeration via WMI, network adapter information gathering, and directory listing with the -Force flag — are consistent with incident response triage rather than attacker activity. On the same date, Autorunsc.exe (a Sysinternals persistence-auditing tool) was executed on 172.16.6.15, further supporting the interpretation that IT staff detected anomalous indicators and began preliminary investigation approximately two weeks before the main offensive operations escalated. Whether this early triage was triggered by the msadvapi2 backdoor's presence or other indicators remains undetermined.
Phase 3 — Active Offensive Operations (August 27 – September 1, 2018)
Beginning on 2018-08-27, the threat actor launched an aggressive lateral movement campaign using a uniform, automated attack chain deployed via Windows Management Instrumentation (WMI). The canonical attack sequence, observed identically across seven or more hosts, proceeds as follows: WmiPrvSE.exe (Session 0, non-interactive) spawns a 64-bit powershell.exe with no visible command-line arguments, which immediately spawns a 32-bit (SysWOW64) powershell.exe with stealth flags (-nop -w hidden -encodedcommand or -Version 5.1 -s -NoLogo -NoProfile), which then injects shellcode into one or more rundll32.exe child processes. The architecture downgrade from 64-bit to 32-bit PowerShell is a hallmark of Metasploit-framework shellcode compatibility requirements.
On 2018-08-27 at 21:25:58, base-wkstn-04 (172.16.6.14) received the earliest confirmed Metasploit implant via an interactive PowerShell session (PID 2664) launched from explorer.exe in the user's desktop session (Session 11). This was the only system showing an interactive-session compromise rather than WMI-based remote delivery, suggesting it may have been compromised through a user-initiated action such as a phishing payload. Over the following three days, PID 2664 spawned over twenty short-lived rundll32.exe injection targets (2–4 second lifetimes each) and established a localhost listener on port 18278, consistent with a SOCKS proxy or C2 relay. A persistent rundll32.exe implant (PID 8856, spawned 2018-08-27 23:39:56) remained running for over ten days until memory capture.
On 2018-08-28 at 22:08:25, WMI remote execution was used to deploy the PowerShell C2 chain on BASE-FILE (172.16.4.5). WmiPrvSE.exe (PID 1196) spawned powershell.exe (PID 4072, 64-bit), which in turn spawned powershell.exe (PID 3164, 32-bit), which then spawned over thirty rundll32.exe child processes between August 30 and September 6. Both PowerShell processes maintained ESTABLISHED connections to 172.16.4.10:8080, tunneling C2 traffic through the organizational web proxy. The powershell.exe processes operated under the compromised service account shieldbase\spsql.
On 2018-08-30 at 16:43:36, base-rd-02 (172.16.6.11) received the same WMI-based attack chain. PID 8712 (64-bit PowerShell) spawned PID 5848 (32-bit), which deployed multiple rundll32.exe injection targets and additionally dropped a second-stage implant, p.exe, at c:\windows\temp\perfmon\p.exe (executed via cmd.exe /C at 22:15:18). Malfind detected a large PAGE_EXECUTE_READWRITE allocation (CommitCharge=481) in p.exe (PID 8260), consistent with injected shellcode. The p.exe binary was subsequently deleted from the filesystem (absent from MFT) but continued running in memory, spawning its own rundll32.exe instances through September 6. An additional tool reference ("sd.") was identified in ShimCache entries for the same staging directory, confirming multiple attacker tools were present.
On 2018-08-31, the offensive tempo intensified. Three parallel WMI attack chains were established on base-wkstn-05 (172.16.7.15, user: mhill) within a 17-minute window beginning at 01:14:44, suggesting the attacker experienced connectivity issues or the first two stagers failed to initialize. The third chain (PID 1332) became the active C2 session, spawning five or more rundll32.exe injection targets. A persistent rundll32.exe implant (PID 7100, 5 threads, 337 handles) remained running at memory capture. On the same date at 01:00:30, an encoded Metasploit PowerShell stager was deployed on 172.16.6.15, and base-wkstn-01 (172.16.7.11) received a WMI-based stager with subsequent WinRM encoded command delivery on September 6.
On 2018-08-31 between 22:16 and 22:52 UTC, the attacker executed the full PowerView/PowerSploit reconnaissance toolkit from base-file.shieldbase.lan using the compromised spsql service account. PowerShell Operational event logs (Event ID 4104 ScriptBlock logging) captured the complete script content, which included Invoke-UserHunter, Invoke-ShareFinder, Invoke-CheckLocalAdminAccess, Get-NetDomain, Get-NetForest, Invoke-MapDomainTrust, Get-ForeignGroup, Get-DNSRecord, Invoke-EnumerateLocalAdmin, Find-LocalAdminAccess, Get-Keystrokes, and Invoke-ACLScanner. References to both Metasploit and PowerShell Empire GitHub repositories were embedded in the script code. The Find-UserField function was used to search Active Directory user description fields for plaintext passwords, a common technique for harvesting credentials stored by administrators in AD attributes.
On 2018-09-06, a second wave of WMI stagers was deployed on base-wkstn-04 (172.16.6.14, a fresh WMI chain alongside the pre-existing interactive implant) and base-wkstn-03 (172.16.6.13, Invoke-WmiMethod targeting "BASE-WKSTN-03" at 17:01:50). On base-wkstn-03, the WMI chain deployed an encoded Metasploit stager alongside the already-running msadvapi2 backdoor services, demonstrating the overlap between the two intrusion campaigns on the same host.
Phase 4 — Data Staging and Potential Exfiltration (September 5, 2018)
On 2018-09-05 at 14:43:11, Rar.exe (PID 2524) was executed on BASE-FILE from an interactive command prompt (cmd.exe PID 6352, spawned from explorer.exe PID 6452). The compression process ran for approximately ten minutes, exiting at 14:52:56, with 67 active threads observed during execution — indicating a significant volume of data being archived. This activity pattern is consistent with data staging for exfiltration. The file server contained substantial business data evidenced by SMB connections from multiple hosts across the environment. No direct evidence of exfiltration of the archived data was recovered, though this does not preclude exfiltration through the attacker's C2 channel.
Phase 5 — Incident Response and Evidence Collection (September 6–7, 2018)
Beginning approximately September 6, 2018, the incident response team deployed F-Response forensic remote acquisition agents (subject_srv.exe) across compromised systems. The F-Response management suite ran on the forensic workstation base-hunt (172.16.5.25), with license_ctrl.exe listening on port 5682 and subject agents connecting back from each target system on port 3262 to the evidence collection endpoint at 172.16.5.50. FTK Imager was launched on the forensic workstation at 2018-09-06 18:48:20 for imaging operations. Memory dumps were collected from thirteen systems, and disk images were acquired from key hosts. The attacker's C2 chains remained active in memory during evidence collection, providing rich forensic artifacts.
Key Findings
Dual Intrusion Campaigns with Operational Overlap
The investigation identified two distinct but operationally linked intrusion campaigns. The first campaign deployed the msadvapi2 persistent backdoor, installed as Windows services masquerading as "Microsoft Advanced API" with both 32-bit and 64-bit variants. The installer was staged as early as December 2017, with confirmed execution in May 2018 and persistence across reboots confirmed through September 2018. The msadvapi2 malware loaded packet capture libraries (wpcap.dll), indicating network interception capabilities. This backdoor was confirmed on at least three systems: the domain controller (BASE-DC), base-wkstn-03 (172.16.6.13), and 172.16.6.15.
The second campaign, active from late August through early September 2018, employed Metasploit-framework PowerShell stagers delivered via WMI remote execution. The uniform attack chain — WmiPrvSE → PowerShell (64-bit) → PowerShell (32-bit/SysWOW64) → rundll32.exe injection — was deployed identically across seven or more systems. The co-existence of both msadvapi2 and Metasploit implants on shared hosts (base-wkstn-03, 172.16.6.15) suggests either a single threat actor with evolving capabilities or a coordinated handoff between persistent access and active operations.
C2 Infrastructure and Proxy Tunneling
All confirmed C2 communications from compromised systems were tunneled through the organizational web proxy at 172.16.4.10:8080. This technique leverages legitimate infrastructure to blend malicious traffic with normal web browsing, making network-based detection significantly more difficult. The C2 distinction was established through process attribution: injected processes (SearchUI.exe PID 9316 on base-wkstn-04, PowerShell processes with confirmed malfind shellcode, persistent rundll32.exe implants) connecting to the proxy constitute confirmed C2, whereas browser processes (Chrome, Edge) connecting to the same proxy represent expected behavior. Five systems showed confirmed C2 via process attribution to attacker-controlled processes.
WinRM Lateral Movement Hub at 172.16.5.21
Network analysis identified 172.16.5.21 as the primary convergence point for WinRM-based lateral movement. Active ESTABLISHED WinRM sessions from base-wkstn-01 (172.16.7.11), the domain controller (172.16.4.4), and BASE-FILE (172.16.4.5) were captured at the time of memory acquisition, with additional CLOSED sessions from 172.16.7.16, 172.16.6.14, and 172.16.7.15. The attacker used WinRM from every compromised pivot point to access this system, which also hosted msadvapi2 backdoor services and maintained SMB connectivity to the file server.
Compromised Service Account and Active Directory Reconnaissance
The domain service account spsql (SID S-1-5-21-3445421715-2530590580-3149308974-1193) was weaponized for domain-wide reconnaissance. MFT entries show the spsql user profile being created on 2018-08-31 at 21:54:13, contemporaneous with the PowerView execution window. The attacker leveraged this SQL service account — which by convention holds elevated domain privileges — to enumerate users, shares, domain trusts, DNS records, and local administrators across the entire forest.
Process Injection Techniques
Malfind analysis confirmed code injection across multiple processes and systems. On base-wkstn-04 (172.16.6.14), SearchUI.exe (PID 9316) contained injected x64 shellcode with the Metasploit block_api prologue (\xfc\xe8\x04\x00\x00\x00, CLD; CALL $+4) and maintained active C2 connections. PowerShell PID 5452 on the same system contained identical Metasploit decoder stub shellcode. On base-rd-02, p.exe (PID 8260) exhibited a large PAGE_EXECUTE_READWRITE allocation consistent with injected shellcode. Multiple PowerShell processes across the environment showed VadS regions with RWX protection containing injected code.
Attacker Staging Directories
The attacker established staging directories designed to blend with legitimate Windows components. The c:\windows\temp\perfmon\ directory on multiple systems hosted the p.exe implant and an additional tool ("sd."), with the "perfmon" name mimicking Windows Performance Monitor paths. The C:\ProgramData\staging\install_wormhole\ directory contained the msadvapi2 installer. Both locations demonstrate deliberate masquerading to evade cursory inspection.
DMZ FTP Server Exposure and Log Deletion
The DMZ FTP server (172.16.10.12) was targeted by brute force credential attacks from multiple external IP addresses including 221.151.127.218 (targeting "administrator"), 95.47.155.87 (targeting "stark-r"), and 138.197.213.41 (rapid-fire automated credential stuffing against rsydow-a). All external brute force attempts appear to have failed. However, two FTP log files (u_ex180805.log and u_ex180823.log) were selectively deleted, creating gaps on August 5 and August 23 in an otherwise complete daily log sequence — suggesting intentional evidence destruction targeting specific dates of activity. The FTP server also exposed cleartext credentials: the rsydow-f account authenticated with the password "mprsydow@mail.com" in logs, representing poor credential hygiene that could enable credential reuse attacks.
False Positive YARA Detections
Several YARA detections were conclusively assessed as false positives. The APT6_Malware_Sample_Gen rule produced 233 match windows across memory dumps, but all matched strings were generic Windows artifacts ("shellcode," "synflood," common system paths). The APT_MAL_RU_WIN_Snake_Malware_May23_1 rule matched format string specifiers ("%s#1", "%s#2") common in Windows binaries. These detections do not indicate the presence of APT6 or Snake/Uroburos malware.
Corrected Assessments
Several initial findings were corrected through counter-analysis. The subject_srv.exe binary, originally flagged as a suspicious backdoor, was conclusively identified as the F-Response forensic remote acquisition agent based on its command-line parameters (-v "F-Response Subject" -k "155522845" -s "base-hunt.shieldbase.lan:5682"). Shadow copy PowerShell activity originally characterized as ransomware preparation was re-assessed as administrative enumeration (Get-CimInstance query with display output, not deletion) performed by the rsydow-a account via WinRM. The sub-win-x64_base-hunt_5682_3262.exe file on the DMZ FTP server was re-assessed as likely an F-Response agent binary based on filename correlation to confirmed F-Response port parameters (5682 license controller, 3262 subject agent).
Threat Intelligence and Attribution
YARA memory scanning detected signatures associated with Codoso/Deep Panda tooling on the domain controller. The Codoso_CustomTCP_4 rule matched the string "varus_service_x86.dll" — a specific malware component name — along with service manipulation commands ("net start %%1", "net stop %%1") and delay techniques ("ping 127.1 > nul"). The DeepPanda_htran_exe rule matched htran-specific syntax ("-slave ConnectHost ConnectPort TransmitHost TransmitPort") and debug messages ("[+] OK! I Closed The Two Socket."). These signatures confirm the presence of specific offensive tools in domain controller memory that have historically been associated with Chinese APT groups.
However, attribution to Codoso/Deep Panda or any specific threat group remains at the "inference" confidence level. The YARA detections represent a single detection tool with no independent corroboration from network IOCs, domain registrations, or infrastructure overlap with known campaigns. The htran network relay tool is publicly available and used by multiple threat groups. No C2 domain or external IP was linked to known Codoso/Deep Panda infrastructure. The co-existence of msadvapi2 (a persistent backdoor with packet capture capabilities deployed months before active operations) alongside Metasploit-framework stagers is consistent with known APT operational patterns — establishing quiet persistent access before conducting louder operational activity — but this pattern is not unique to any single group.
The attack tradecraft demonstrates a sophisticated threat actor with capabilities including: custom malware development (msadvapi2 with WinPcap integration), operational security awareness (proxy tunneling, Living-off-the-Land techniques, memory-resident tools), Active Directory domain expertise (service account compromise, PowerView enumeration, trust mapping), and multi-month operational patience. The tooling mix — custom persistent backdoor plus commodity framework (Metasploit) — is consistent with well-resourced threat groups that develop bespoke persistence tools while leveraging widely available post-exploitation frameworks for operational flexibility.
Impact Assessment
The intrusion compromised at least seven systems across the Stark Research Labs network, spanning the server infrastructure, R&D, and workstation subnets. The domain controller (BASE-DC), file server (BASE-FILE), and multiple user workstations were under active attacker control for a minimum of ten days during the Metasploit campaign, with the msadvapi2 backdoor providing persistent access for approximately three months prior. The compromised systems include the organization's domain controller, granting the attacker effective control over the entire Active Directory environment, including all user credentials, group policies, and trust relationships.
The spsql SQL service account was compromised and used for domain-wide reconnaissance, indicating the attacker had at minimum service-account-level credentials. The PowerView execution confirmed the attacker enumerated all domain users, shares, trust relationships, DNS records, and local administrator access across the forest. Data staging via Rar.exe on the file server, with ten minutes of active compression involving 67 threads, suggests preparation for bulk data exfiltration. The file server's role as a central data repository serving SMB connections from multiple hosts places the organization's core intellectual property and business data at risk.
The credential exposure on the DMZ FTP server (rsydow-f password logged in cleartext) and the VPN infrastructure at 172.16.1.20 (SoftEther VPN with external connections from multiple IPs) represent additional risk vectors. Selective deletion of two FTP log files on dates of interest suggests the attacker was aware of and attempted to cover specific activities on those dates.
McAfee endpoint protection and Windows Defender were deployed across the environment but failed to detect either the msadvapi2 backdoor services or the Metasploit PowerShell stagers, despite the malware running continuously as Windows services for months.
Immediate Tactical Containment
-
Isolate all confirmed compromised systems from the network immediately: BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), 172.16.6.15, and the WinRM hub at 172.16.5.21.
-
Block all traffic to and from 172.16.4.10:8080 at the network perimeter and internal firewall until the proxy server can be audited for C2 relay artifacts. Implement emergency egress filtering on all proxy alternatives.
-
Disable the spsql service account in Active Directory and force a double password reset (reset once, wait for replication, reset again) on all accounts identified in the PowerView enumeration scope, prioritizing domain administrator and service accounts.
-
Terminate the following processes on any systems still accessible: msadvapi2_32.exe and msadvapi2_64.exe (all instances), any powershell.exe processes with the -nop -w hidden -encodedcommand flags, and all orphaned rundll32.exe processes running in Session 0 with no visible command line.
-
Remove the msadvapi2 Windows services and delete the installation directories: "C:\Program Files (x86)\Microsoft Advanced API 32\" and "C:\Program Files (x86)\Microsoft Advanced API 64\" on all systems. Remove the staging directory C:\ProgramData\staging\install_wormhole.
-
Delete attacker staging artifacts: c:\windows\temp\perfmon\p.exe and c:\windows\temp\perfmon\sd.* on base-rd-02 and base-wkstn-01.
-
Disable the rsydow-f and rsydow-a FTP accounts on the DMZ FTP server (172.16.10.12). Disable external FTP access entirely until the service can be migrated to SFTP with certificate-based authentication.
-
Block inbound connections from known FTP brute force source IPs at the perimeter firewall: 138.197.213.41, 221.151.127.218, 95.47.155.87, 146.185.222.48, 185.255.31.2, 58.62.55.130, 60.212.42.56, 164.52.24.165, and 61.153.54.38.
-
Disable WinRM (port 5985) on all non-administrative systems to disrupt the attacker's lateral movement channel. Restrict WinRM access to dedicated jump servers with explicit firewall rules.
-
Initiate a full Kerberos krbtgt password reset (double reset) to invalidate any Golden Tickets the attacker may have forged using the compromised domain controller.
Strategic Remediation
The msadvapi2 backdoor (findings f_e4c31c4b, f_5216d777, f_043b8857) operated as a Windows service for approximately three months without detection by the deployed McAfee endpoint protection or Windows Defender. The malware loaded WinPcap for packet capture and ran under fabricated service names. This failure indicates the organization's endpoint detection capability lacks behavioral monitoring for service-based persistence and library-loading anomalies. The remediation is to deploy an endpoint detection and response (EDR) solution with behavioral analytics capable of detecting anomalous service registrations, suspicious DLL loads (particularly packet capture libraries by non-network-monitoring processes), and service binaries installed under names mimicking legitimate Microsoft products. Application whitelisting on server-class systems would have prevented the msadvapi2 service from executing.
The attacker's entire Metasploit campaign (findings f_9cea16b7, f_340f9940, f_886de2e3, f_10899b93) leveraged WMI remote execution and WinRM for lateral movement, both protocols that were enabled by default across the environment with no access restrictions. The WinRM convergence on 172.16.5.21 from all compromised subnets (finding f_d1f3eb7f) demonstrates the absence of network segmentation enforcement between server, R&D, and workstation subnets. The remediation is to implement host-based firewall rules restricting WMI (TCP 135, dynamic RPC) and WinRM (TCP 5985/5986) to designated management workstations only, and to enforce inter-subnet traffic filtering that prevents workstation-to-workstation lateral movement across subnet boundaries.
The compromised spsql SQL service account (finding f_83e43c8d) was used for domain-wide PowerView reconnaissance, indicating the service account held excessive Active Directory privileges and was not monitored for anomalous interactive logon activity. Service accounts authenticated interactively from workstations should generate immediate alerts. The remediation is to implement the principle of least privilege for all service accounts, configure them as Managed Service Accounts (gMSA) with automatic password rotation, restrict their logon rights to specific service hosts via Group Policy, and deploy SIEM alerting for interactive or network logon events from service account principals.
The attacker tunneled all C2 traffic through the organizational web proxy at 172.16.4.10:8080 (finding f_6325de06), which passed attacker traffic without inspection or alerting. The proxy was configured as a transparent relay without TLS inspection, content categorization, or anomaly detection for command-and-control beaconing patterns. The remediation is to deploy TLS-intercepting proxy infrastructure with domain categorization that blocks uncategorized or newly registered domains, implement JA3/JA3S fingerprint monitoring to detect known C2 framework TLS signatures, and configure alerting for beaconing patterns (regular-interval connections from non-browser processes).
The DMZ FTP server (172.16.10.12) exposed cleartext FTP (port 21) to the internet with password-based authentication (findings f_5c84d8da, f_dc34d77c), resulting in sustained brute force attacks and cleartext password exposure in logs. The rsydow-f password ("mprsydow@mail.com") captured in FTP logs could enable credential reuse against VPN or other services. The remediation is to decommission the cleartext FTP service entirely and migrate to SFTP with key-based authentication, implement account lockout policies to prevent automated brute force, and conduct a credential audit to identify any reuse of the exposed password across other systems.
The selective deletion of two FTP log files on August 5 and August 23 (finding f_6f6465b3) succeeded in creating evidence gaps because log integrity monitoring was absent. The remediation is to implement centralized log collection with immutable storage (write-once, append-only) that forwards logs to a SIEM in real time, preventing an attacker with host-level access from destroying log evidence.
Conclusion
Q1. What systems were compromised?
Seven systems are confirmed compromised: BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), and 172.16.6.15. An eighth system, the WinRM hub at 172.16.5.21, hosted msadvapi2 backdoor services and received inbound WinRM from all compromised subnets. Base-wkstn-01 (172.16.7.11) and base-rd-06 (172.16.6.13) show strong indicators but lack full corroboration. The Exchange server (172.16.4.6) and SharePoint server (172.16.4.7) are on the same subnet as compromised systems and show suspicious indicators but no confirmed attack chains. The DMZ FTP server (172.16.10.12) shows evidence of log tampering but no confirmed code execution.
Q2. How did the attacker gain initial access?
The precise initial access vector was not definitively determined. The earliest confirmed attacker artifact is the msadvapi2 installer staged in December 2017, but the method of initial delivery is unknown. The base-wkstn-04 interactive PowerShell session (launched from explorer.exe in the user's desktop on 2018-08-27) is the only system showing a user-session-initiated compromise, suggesting possible phishing or social engineering for the Metasploit campaign phase. The SoftEther VPN gateway (172.16.1.20) and internet-exposed FTP server represent potential but unconfirmed entry points. The exposed FTP password (mprsydow@mail.com) could have enabled credential reuse against VPN services.
Q3. What lateral movement occurred?
Extensive lateral movement was conducted using WMI remote execution (T1047) for initial code deployment, WinRM (T1021.006) for sustained remote PowerShell access, RDP (T1021.001) between R&D systems, and SMB (T1021.002) for file server access. The system at 172.16.5.21 served as a cross-subnet WinRM convergence point receiving connections from all compromised subnets. The attacker's lateral movement was facilitated by the compromised spsql service account and the absence of inter-subnet access controls.
Q4. What persistence mechanisms were installed?
The primary persistence mechanism was the msadvapi2 Windows service (T1543.003), deployed in both 32-bit and 64-bit variants across at least three systems and surviving reboots for months. The Metasploit campaign relied on memory-resident implants (injected into rundll32.exe and SearchUI.exe processes) that would not survive a reboot but were continuously refreshed via WMI deployment. No additional persistence mechanisms such as scheduled tasks, registry autorun keys, or startup folder modifications were identified.
Q5. Was data exfiltrated, and if so, what and how much?
Data staging was confirmed: Rar.exe compressed data on the file server for approximately ten minutes on September 5, 2018, indicating significant data volume. However, no direct evidence of exfiltration (outbound data transfers to external infrastructure) was recovered from the available evidence. The attacker's C2 channel through the web proxy could have served as an exfiltration path. FTP data retrieval operations by the dblake account accessing /Users/ directories (including user nfury's files) on the DMZ FTP server were observed but may represent authorized activity. The deleted FTP logs may have contained evidence of additional data movement.
Q6. What is the full timeline of the incident?
The incident spans from at least December 2017 (msadvapi2 installer creation) through September 7, 2018 (final evidence collection). The msadvapi2 backdoor was deployed in May 2018. Active Metasploit operations began on August 27, 2018, with WMI-based lateral movement escalating through August 31 and a second deployment wave on September 6. Data staging occurred on September 5. Incident response activities began approximately September 6–7 with F-Response and FTK Imager deployment.
Q7. What is the total scope and business impact?
The attacker achieved domain administrator-equivalent access, compromising the domain controller and conducting full Active Directory reconnaissance. Seven to ten systems across server, R&D, and workstation subnets were compromised, spanning all major network segments. The file server containing organizational data was under active C2 control with confirmed data staging. All domain credentials should be considered compromised. The McAfee endpoint protection suite failed to detect any stage of the intrusion across all monitored systems.
Q8. What are the recommended remediation actions?
Immediate actions include isolating all compromised systems, performing a full krbtgt double reset, disabling compromised accounts (spsql, rsydow-a, rsydow-f), removing msadvapi2 services and staging directories, restricting WMI/WinRM to managed endpoints, and blocking attacker infrastructure. Strategic actions include deploying behavioral EDR with service monitoring, implementing network segmentation with inter-subnet access controls, migrating to managed service accounts with logon restrictions, deploying TLS-inspecting proxy with C2 detection, decommissioning cleartext FTP in favor of SFTP, and implementing centralized immutable log collection.
Attack Timeline
Findings
PowerView (part of the PowerSploit framework) was loaded and executed on the domain controller BASE-DC on 2018-08-31 between 22:16 and 22:52 UTC. The PowerShell Operational event log (Event ID 4104 - ScriptBlock logging) captured the full script content, which includes the following PowerView functions:
- Invoke-UserHunter: Finds logged-in users across the domain
- Invoke-ShareFinder: Enumerates accessible network shares
- Invoke-CheckLocalAdminAccess: Checks local admin access on domain hosts
- Get-NetDomain/Get-NetForest: Domain and forest enumeration
- Invoke-MapDomainTrust: Domain trust mapping
- Get-ForeignGroup: Cross-domain group enumeration
- Get-DNSRecord/Get-DNSZone: DNS record enumeration
- Invoke-EnumerateLocalAdmin: Local admin enumeration across domain
- Find-LocalAdminAccess: Automated local admin access discovery
- Get-Keystrokes: Keystroke logging capability
The script was executed under user SID S-1-5-21-3445421715-2530590580-3149308974-1193 (spsql) on host base-file.shieldbase.lan. The PowerShell host application was C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe. References to both Metasploit and PowerShell Empire GitHub repositories were present in the script code, confirming the offensive tooling origin.
This represents full AD reconnaissance from a compromised domain controller using a service account (spsql), consistent with post-exploitation lateral movement and domain enumeration.
Evidence Chain
A multi-stage attack chain was detected on the file server (BASE-FILE, 172.16.4.5) involving remote WMI execution leading to PowerShell C2 activity and massive rundll32.exe spawning, consistent with a post-exploitation framework (e.g., Cobalt Strike, Empire, Metasploit).
Stage 1 - Remote WMI Execution:
- WmiPrvSE.exe (PID 1196) spawned powershell.exe (PID 4072)
- PID 4072: 64-bit, started 2018-08-28 22:08:25
- WMI remote execution indicates lateral movement from another host
Stage 2 - PowerShell Architecture Downgrade:
- PID 4072 spawned powershell.exe (PID 3164), 32-bit (Wow64=True), started 2018-08-28 22:08:26
- 32-bit PowerShell on a 64-bit host is a red flag commonly used by exploitation frameworks for shellcode compatibility
- Running under user shieldbase\spsql (service account)
Stage 3 - Rundll32 Process Spawning:
- PID 3164 spawned 30+ rundll32.exe child processes between 2018-08-30 and 2018-09-06
- Observed PIDs include: 3548 (08-30 02:52), 3260 (08-30 18:40), 300 (08-30 03:23), and many more
- Rundll32 spawning is a classic technique for code injection / reflective DLL loading
Network C2:
- Both PowerShell processes (PID 4072 and PID 3164) connected to 172.16.4.10:8080 (ESTABLISHED)
- 172.16.4.10 appears to be a web proxy; C2 traffic likely tunneled through the proxy
PowerShell Script Logging (Event ID 4104):
- Scripts executed by shieldbase\spsql included Win32_ShadowCopy manipulation and NetFirewallRule commands
- Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Evidence Chain
A multi-stage attack chain was established on base-rd-02 (172.16.6.11) via WMI, mirroring the pattern observed on the DC and file server.
Full Process Tree:
1. WmiPrvSE.exe (PID 2876, Session 0) → powershell.exe (PID 8712, 64-bit, started 2018-08-30 16:43:36, no visible command-line args)
2. PID 8712 → powershell.exe (PID 5848, 32-bit/SysWOW64, started 2018-08-30 16:43:42, args: "-Version 5.1 -s -NoLogo -NoProfile")
3. PID 5848 spawned multiple rundll32.exe processes for code injection:
- PID 6768: 2018-08-30 18:31:04 – 18:31:35 (SysWOW64)
- PID 5452: 2018-08-30 21:40:18 – 21:40:23
- PID 5588: 2018-08-30 21:40:42 – 21:40:54
- PID 2216: 2018-08-30 22:31:57 – 22:32:19 (SysWOW64)
- PID 4108: 2018-08-30 22:45:25 – 22:45:30
- PID 8148: 2018-08-31 00:56:14 – 00:56:30 (SysWOW64)
4. PID 5848 also spawned cmd.exe (PID 5948) which executed c:\windows\temp\perfmon\p.exe (PID 8260) at 2018-08-30 22:15:18
Second-Stage Implant (p.exe):
- p.exe (PID 8260) spawned its own rundll32.exe instances days later:
- PID 5768: 2018-09-05 12:01:32 – 12:01:40
- PID 1424: 2018-09-06 14:58:41 – 14:58:45
- PID 7552: 2018-09-06 17:26:32 – 17:26:35
- p.exe had a malfind hit: VadS PAGE_EXECUTE_READWRITE, CommitCharge=481 (large RWX allocation consistent with injected shellcode)
- The file at c:\windows\temp\perfmon\p.exe was not found in MFT, suggesting deletion after deployment
Malfind Detections:
- powershell.exe PID 8712: 3 VadS regions with PAGE_EXECUTE_READWRITE (injected code)
- p.exe PID 8260: VadS with PAGE_EXECUTE_READWRITE, 481 commit charge
Key Indicators:
- WMI-initiated execution in Session 0 (non-interactive, remote origin)
- 32-bit PowerShell downgrade on 64-bit OS (framework shellcode compatibility)
- No visible command-line args on initial PowerShell (anti-forensics)
- Stealth flags: -s -NoLogo -NoProfile on child PowerShell
- Short-lived rundll32.exe child processes spanning Aug 30 – Sep 6 (8+ days of sustained access)
This attack chain is identical to the one on the file server (BASE-FILE) and DC, confirming base-rd-02 was compromised via the same campaign using the same Metasploit/Cobalt Strike-style post-exploitation framework.
Affected Systems: ez.mft, registry.system, volatility.cmdline, volatility.dlllist, volatility.malfind, volatility.pstree
Evidence Chain
Three parallel WMI-initiated PowerShell attack chains were established on base-wkstn-05 (172.16.7.15, user: mhill) within a 17-minute window on 2018-08-31, matching the exact pattern observed on other compromised systems (base-rd-02, file server, DC).
Attack Chain Details (from psscan source_id 232):
Chain 1: WmiPrvSE.exe (PID 2676, Session 0) → powershell.exe (PID 4328, 64-bit, 01:14:44) → powershell.exe (PID 1124, WoW64/32-bit, 01:14:45)
Chain 2: WmiPrvSE.exe (PID 2676) → powershell.exe (PID 4064, 64-bit, 01:23:24) → powershell.exe (PID 4072, WoW64/32-bit, 01:23:25)
Chain 3: WmiPrvSE.exe (PID 2676) → powershell.exe (PID 3920, 64-bit, 01:31:24) → powershell.exe (PID 1332, WoW64/32-bit, 01:31:25)
All three chains follow the identical pattern:
1. WMI Provider Host (Session 0, non-interactive) spawns 64-bit PowerShell
2. 64-bit PowerShell immediately spawns 32-bit (WoW64) child for shellcode compatibility
3. No visible command-line args on the 64-bit parent (anti-forensics)
Chain 3 was the active C2 session: PID 1332 (32-bit PowerShell) spawned 5+ rundll32.exe code injection targets:
- PID 5300: 2018-08-31 01:31:44 – 01:31:46 (2 sec)
- PID 3720: 2018-08-31 21:07:21 – 21:07:28 (7 sec)
- PID 5056: 2018-08-31 20:23:08 – 20:23:29 (21 sec)
- PID 4240: 2018-08-31 20:23:17 – 20:23:35 (18 sec)
- PID 1972: 2018-08-31 20:23:52 – 20:23:56 (4 sec)
A persistent rundll32.exe (PID 7100, PPID 7148) was still running at memory capture time with 5 threads and 337 handles, suggesting a long-running implant module.
Three simultaneous chains (vs one on other systems) suggests the attacker experienced connectivity issues or the first two stagers failed to fully initialize, requiring retry attempts.
System context:
- System boot: 2018-08-30 05:14:12
- User mhill connected via RDP (rdpclip.exe PID 4232 in Session 5)
- Active applications: Outlook, Chrome, GROOVE.EXE (OneDrive/SharePoint)
- Sysmon64.exe (PID 1892) was running but did not prevent the compromise
- McAfee AV suite fully deployed (masvc, mfefire, mcshield, HipMgmt)
Affected Systems: volatility.psscan
Affected Systems: volatility.netscan, volatility.psscan
Evidence Chain
COUNTER-ANALYSIS CORRECTIONS applied to comprehensive timeline:
IP Correction: BASE-DC is 172.16.4.4, not 172.16.4.1 as previously stated.
DMZ-FTP Reclassified: DMZ-FTP (172.16.10.12) is downgraded from "confirmed compromised" to "unconfirmed." The primary evidence (sub-win-x64_base-hunt_5682_3262.exe) has been re-assessed as likely an F-Response subject agent binary (see finding f_bec07e91). FTP brute force attempts all failed. FTP log deletion is suspicious but insufficient alone. No memory dump was available for this system, preventing WMI/PowerShell chain confirmation.
IR Activity Separation: subject_srv.exe deployments across all systems are F-Response forensic tooling deployed by incident responders starting ~2018-09-06, not attacker persistence. Autorunsc.exe execution on 2018-08-15 is consistent with IR triage rather than attacker activity.
CORRECTED Attack Timeline (Aug-Sep 2018):
- Pre-Existing Access (June+ 2018):
- msadvapi2 backdoor services deployed on 3+ systems (BASE-DC 172.16.4.4, base-wkstn-03 172.16.6.13, 172.16.6.15)
-
Persistent packet capture capability via wpcap.dll
-
Possible Early IR Triage (August 15, 2018):
- cbarton-a remote PowerShell reconnaissance on base-rd-02 (could be legitimate admin activity)
-
Autorunsc.exe execution on 172.16.6.15
-
Active Offensive Operations (August 27-September 6, 2018):
- WMI-based remote code execution deploying Metasploit PowerShell stagers across 7+ systems
- C2 tunneled through organizational web proxy at 172.16.4.10:8080
- PowerView AD reconnaissance from file server using spsql service account (Aug 31)
- Data staging via Rar.exe on BASE-FILE (Sep 5)
-
WinRM lateral movement converging on 172.16.5.21
-
Confirmed Compromised Systems (7):
-
BASE-FILE (172.16.4.5), BASE-DC (172.16.4.4), base-rd-02 (172.16.6.11), base-wkstn-04 (172.16.6.14), base-wkstn-05 (172.16.7.15), base-wkstn-03 (172.16.6.13), 172.16.6.15
-
Likely Compromised (insufficient evidence for full confirmation):
- base-wkstn-01 (172.16.7.11) — WMI chain observed but limited corroboration
-
base-rd-06 (172.16.6.13) — msadvapi2 + C2 proxy connection
-
Not Compromised:
- 172.16.5.25 (base-hunt) — Forensic workstation
- 172.16.5.26 — Admin workstation
- 172.16.7.16 (base-wkstn-02) — No compromise indicators
Evidence Chain
Two malicious executables disguised as "Microsoft Advanced API" are running as persistent services on at least two compromised systems (memory captures with boot times 2018-06-04, 2018-08-17, and 2018-09-06):
- msadvapi2_32.exe (PIDs 1072/2020, WoW64 32-bit) at "C:\Program Files (x86)\Microsoft Advanced API 32\msadvapi2_32.exe"
- msadvapi2_64.exe (PIDs 1240/1256, 64-bit) at "C:\Program Files (x86)\Microsoft Advanced API 64\msadvapi2_64.exe"
Both processes run under services.exe (Session 0) as system services, indicating service-based persistence. The malware persists across reboots, confirmed by its presence in three separate memory captures spanning June through September 2018. Malfind detected PAGE_EXECUTE_READWRITE memory regions in msadvapi2_32.exe (PID 1072), indicating possible code injection or runtime unpacking. DLL analysis shows the malware loads wpcap.dll (WinPcap), IPHLPAPI.DLL, and network-related libraries, consistent with network packet capture or traffic manipulation capabilities.
The "Microsoft Advanced API" naming is a deliberate deception technique to blend with legitimate Microsoft software. There is no legitimate Microsoft product by this name. The installation under "Program Files (x86)" and registration as a Windows service demonstrates sophisticated persistence by the threat actor.
Evidence Chain
Memory forensics of base-wkstn-03 (172.16.7.14, dual-homed 10.10.150.181) reveals multiple concurrent compromise mechanisms. System boot time: 2018-06-04 20:18:58.
1. WMI-Based Lateral Movement (T1047):
EVTX PowerShell operational logs captured the attacker executing Invoke-WmiMethod with ComputerName="BASE-WKSTN-03" and Class="win32_process" at 2018-09-06 17:01:50, confirming WMI remote code execution targeting this host.
2. Metasploit PowerShell Stager Chain:
- WmiPrvSE.exe (PID 3308, born 2018-06-04 20:19:47) spawned powershell.exe (PID 4340, born 2018-09-06 17:24:47) running: powershell.exe -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIA...
- Decoded payload: $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sI..."));IEX (New-Object IO.StreamReader(New-Object IO.Compression.GzipStream($s,[IO.Compression.CompressionMode]::Decompress))).ReadToEnd();
- Architecture downgrade: PID 4340 (64-bit) spawned PID 1288 (32-bit SysWOW64 powershell.exe, born 2018-09-06 17:24:49) for Metasploit shellcode compatibility
3. msadvapi2 Backdoor (Persistent Services):
- msadvapi2_32.exe (PID 2240, WoW64, born 2018-06-04 20:19:38) at "C:\Program Files (x86)\Microsoft Advanced API 32\"
- msadvapi2_64.exe (PID 2248, born 2018-06-04 20:19:38) at "C:\Program Files (x86)\Microsoft Advanced API 64\"
- Both run as children of services.exe (PID 736), indicating persistent service registration since system boot
- Backdoor has been present since at least 2018-06-04 (3+ months before incident response)
4. LARIAT Framework:
- prunsrv.exe (PID 2268) → java.exe (PID 324) running Lincoln Lab LARIAT c2 client
- LARIAT java connections to external IPs (closed state)
5. Network Indicators:
- SMB from file server: 172.16.4.5:59071 → 172.16.7.14:445 ESTABLISHED (2018-09-06 17:24:47)
- WinRM outbound: 172.16.7.14:54302 → 172.16.5.21:5985 CLOSED (2018-09-06 21:02:43)
- Puppet/MCO: 10.10.150.181:54120 → 10.10.254.1:61613 ESTABLISHED
- F-Response: subject_srv.exe (PID 6556) deployed 2018-09-06 20:55:26
6. Security Tools Deployed but Bypassed:
- McAfee VirusScan Enterprise, Host Intrusion Prevention, Agent
- SecurityHealthService (Windows Defender)
- Neither detected the msadvapi2 backdoor or PowerShell stager
Evidence Chain
Memory forensics of base-wkstn-04 (172.16.6.14, boot 2018-08-06 16:38:49) reveals two distinct, concurrent attack chains operating in different security contexts.
Attack Chain 1 — Interactive User Session (Session 11):
PowerShell PID 2664 was launched from explorer.exe (PID 8392) in the user's interactive desktop session at 2018-08-27 21:25:58. This PowerShell process spawned 20+ short-lived rundll32.exe injection targets over a 3-day period:
- 2018-08-27: PIDs 9644, 4476, 6260, 2508, 9756, 12496, 6720, 1000, 12692 (9 instances, 2-4 second lifetimes each)
- 2018-08-28: PIDs 7696, 9476, 7680, 12208, 6320, 3816, 9784, 10196, 9292, 9824, 12328 (11 instances)
- 2018-08-30: PID 8436 (1 instance)
Additionally, PID 2664 spawned child PowerShell processes: PID 3924 (exited 08-30 04:55:24), PID 6804 (exited 09-06 17:40:12), PID 4520 (still running at capture time). PID 2664 maintained active network connections to C2 proxy at 172.16.4.10:8080 (ports 51278, 52483 CLOSED).
A long-running rundll32.exe PID 8856 (spawned by PID 8448 at 2018-08-27 23:39:56) was still running at memory capture — 10+ days of persistent execution, indicating a persistent implant module.
PID 2664 also opened a local listener on port 18278 (127.0.0.1:18278), consistent with a local C2 relay or socks proxy used by post-exploitation frameworks.
Attack Chain 2 — WMI Remote Execution (Session 0):
On 2018-09-06 17:43:45, WmiPrvSE.exe (PID 3156) spawned powershell.exe PID 4896 with encoded Metasploit stager: "powershell.exe -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIA..." decoding to the standard GZip-compressed shellcode loader ($s=New-Object IO.MemoryStream). PID 4896 spawned 32-bit child powershell.exe PID 5452 (WoW64 architecture downgrade). Malfind confirmed Metasploit shellcode (fc e8 04 00 00 00 — CLD; CALL $+4 decoder stub) in PID 5452's memory.
SearchUI.exe Injection (PID 9316):
SearchUI.exe contained injected x64 shellcode (PAGE_EXECUTE_READWRITE) and maintained 7+ CLOSE_WAIT connections to 172.16.4.10:8080 (ports 55897-55903, 49320-49323), establishing persistent C2 from 2018-08-29 22:01 through 2018-09-06.
Network Summary:
- 30+ connections to C2 proxy 172.16.4.10:8080 (via SearchUI.exe, powershell.exe, svchost.exe, ngen.exe, LogonUI.exe, MicrosoftEdge, software_reporter)
- 8+ WinRM sessions to 172.16.5.21:5985 (lateral movement pivot)
- SMB to file server (172.16.4.5:445), DC (172.16.4.4:445/49670), Exchange (172.16.4.6:443)
- Inbound SMB from file server: 172.16.4.5:59106 → 172.16.6.14:445 (timed with WMI stager delivery at 17:43:46)
- F-Response (subject_srv.exe PID 7140) deployed 2018-09-06 19:05:20
Significance:
Unlike other compromised systems that show only WMI-based remote attack chains, base-wkstn-04 had an INTERACTIVE PowerShell C2 session running from the user's own desktop (Session 11) for 10+ days. This suggests the attacker either had direct desktop access (RDP) or the initial compromise occurred through a user-initiated action (phishing, malicious link).
Affected Systems: volatility.cmdline, volatility.malfind, volatility.netscan, volatility.pslist, volatility.pstree
Evidence Chain
COUNTER-ANALYSIS NOTE: IP correction — the original finding listed "BASE-DC (172.16.4.1)" but the domain controller is at 172.16.4.4.
Cross-system correlation reveals a uniform attack chain deployed across at least 7 confirmed hosts in the shieldbase.lan environment: WmiPrvSE.exe spawns 64-bit PowerShell with encoded command (-nop -w hidden -encodedcommand), which spawns 32-bit PowerShell (SysWOW64) performing a second stage decode, which injects into rundll32.exe via process hollowing.
Confirmed systems with this chain:
- base-wkstn-04 (172.16.6.14) — Interactive + WMI chains
- base-wkstn-05 (172.16.7.15) — 3 parallel WMI chains
- base-wkstn-03 (172.16.6.13) — WMI chain + msadvapi2
- base-rd-02 (172.16.6.11) — WMI chain + p.exe stager
- BASE-FILE (172.16.4.5) — WMI chain + data staging
- 172.16.6.15 — Encoded PowerShell stager
- base-wkstn-01 (172.16.7.11) — WMI chain
The uniformity of this chain—identical process hierarchy, identical PowerShell flags, identical 64→32-bit downgrade, identical rundll32 injection target—indicates automated deployment via WMI, consistent with a Metasploit-style framework. Multiple rundll32 instances per host (up to 20+ on base-wkstn-04) indicate repeated C2 callback injection.
LARIAT Consideration: The LARIAT (Lincoln Lab) testing framework is present on several affected systems but runs as Java processes under prunsrv.exe, completely distinct from the WMI→PowerShell→rundll32 chain. LARIAT cannot account for these artifacts.
Convergence: This finding is corroborated by independent sources—Volatility pstree (parent-child chains), cmdline (encoded commands), malfind (injected code in rundll32), and netscan (C2 connections from rundll32 PIDs).
Evidence Chain
COUNTER-ANALYSIS NOTE: The proxy connections must be interpreted carefully. 172.16.4.10:8080 is the organizational web proxy used by ALL systems on this network for internet access. Systems connecting to this proxy include:
- Confirmed-clean forensic workstation (172.16.5.25) with 15+ connections
- Confirmed-clean admin workstation (172.16.5.26)
- Legitimate user workstations for web browsing
C2 Distinction:
Proxy connections alone do NOT prove C2. What distinguishes attacker C2 from legitimate browsing is the SOURCE PROCESS:
- SearchUI.exe (PID 9316 on 172.16.6.14) connecting to the proxy IS anomalous — Windows Search UI does not normally make HTTP proxy requests
- Injected PowerShell processes (with confirmed malfind shellcode) connecting to the proxy IS C2
- Chrome.exe, Edge, or svchost.exe connecting to the proxy is EXPECTED behavior
Corrected System List (confirmed C2 via process attribution):
- 172.16.6.11 (base-rd-02): PowerShell C2 chain with confirmed malfind
- 172.16.6.14 (base-wkstn-04): SearchUI.exe injection + 30+ connections
- 172.16.7.15 (base-wkstn-05): PowerShell C2 chain with confirmed malfind
- 172.16.4.5 (BASE-FILE): PowerShell PIDs 4072/3164 with confirmed C2 chain
- 172.16.6.13 (base-rd-06): CLOSE_WAIT connection + msadvapi2 present
Systems where proxy connections may be benign browsing:
- 172.16.5.25 (base-hunt): Forensic workstation — NOT compromised
- 172.16.5.26: Admin workstation — NOT compromised
- 172.16.5.20: Chrome browser — ambiguous without process injection evidence
The finding's core conclusion (C2 tunneled through legitimate proxy) remains valid for confirmed-compromised hosts where the connecting processes are attacker-controlled.
Evidence Chain
COUNTER-ANALYSIS NOTE: IP address corrections applied. The original finding referenced "BASE-DC (172.16.4.1)" but the domain controller is at 172.16.4.4 per all other findings. Additionally, the claim of msadvapi2 on "base-wkstn-01 (172.16.7.16)" contains a hostname/IP mismatch — base-wkstn-01 is 172.16.7.11 in other findings, while 172.16.7.16 is identified as base-wkstn-02 in finding f_1c084ed7 (which shows NO msadvapi2 and NO compromise indicators).
Corrected Assessment:
Cross-system analysis reveals two distinct but potentially related intrusion campaigns:
Campaign 1 — msadvapi2 Backdoor (Pre-August 2018):
The msadvapi2_32.exe and msadvapi2_64.exe binaries (masquerading as "Microsoft Advanced API") deployed as Windows services across at least 3 confirmed systems:
- BASE-DC (172.16.4.4) — PID 1072, present since at least June 2018
- base-wkstn-03/base-rd-06 (172.16.6.13) — PIDs 2288/2304, since 2018-08-17 boot
- 172.16.6.15 — msadvapi2_64.exe running as service
DLL analysis shows wpcap.dll (packet capture) loading, consistent with network interception.
Campaign 2 — Metasploit/PowerShell (August-September 2018):
WMI→PowerShell→rundll32 attack chains deployed across 8+ systems using encoded commands with 64→32-bit process downgrade.
Assessment:
The co-existence on shared hosts suggests either a single actor with evolving TTPs, or a coordinated handoff. The msadvapi2 backdoor predates the Metasploit operations by 2+ months, establishing a persistent foothold before the more aggressive August-September lateral movement campaign.
Evidence Chain
Rar.exe (PID 2524) was observed executing on the file server (BASE-FILE) in a pattern consistent with data staging for exfiltration.
Process Details (from snapshot5 - earlier capture):
- PID 2524, PPID 6352 (cmd.exe, spawned from explorer.exe - interactive session)
- Started 2018-09-05 14:43:11
- 67 active threads in snapshot5, indicating active compression
Process Details (from base-file-memory - later capture):
- Same PID 2524, now showing ExitTime 2018-09-05 14:52:56
- Total runtime: approximately 10 minutes of compression activity
Context:
- The cmd.exe parent (PID 6352) was spawned from explorer.exe (PID 6452), indicating interactive user action during a logged-on session
- 10 minutes of active compression suggests a significant volume of data being archived
- File server contains substantial business data as evidenced by SMB connections from multiple hosts in the environment
This activity occurred within the broader attack timeline (Aug 28 - Sep 6, 2018) during which the PowerShell C2 chain and subject_srv.exe were active.
Affected Systems: ez.mft, volatility.psscan
Evidence Chain
The domain service account 'spsql' (SID S-1-5-21-3445421715-2530590580-3149308974-1193) was used to execute PowerView/PowerSploit reconnaissance scripts from base-file.shieldbase.lan on 2018-08-31.
Evidence of account compromise:
1. PowerShell Operational Event Log (Event ID 4104) shows ScriptBlock logging under spsql's SID executing PowerView functions including:
- Invoke-UserHunter (locating logged-in domain admins)
- Invoke-ShareFinder (enumerating accessible shares)
- Invoke-CheckLocalAdminAccess (identifying admin access on remote systems)
- Get-NetDomain, Get-NetForest (domain/forest enumeration)
- Invoke-MapDomainTrust, Get-ForeignGroup (trust mapping)
- Get-DNSRecord, Invoke-EnumerateLocalAdmin
- Invoke-ACLScanner (scanning for modifiable ACLs)
-
MFT entries show Users\spsql profile directories being created/modified on 2018-08-31 21:54:13, contemporaneous with the PowerView execution (22:16-22:52)
-
The spsql account is a SQL service account (suggested by name convention), which was weaponized for lateral reconnaissance — typical of attackers leveraging highly-privileged service accounts.
-
Execution originated from base-file.shieldbase.lan, not the DC itself, indicating the attacker moved laterally to the file server and used the spsql account for domain-wide enumeration.
Evidence Chain
COUNTER-ANALYSIS ASSESSMENT: The Codoso/Deep Panda YARA matches warrant careful evaluation. The "inference" confidence level is APPROPRIATE and should NOT be elevated to "confirmed."
Credible Detections (retained at inference):
Codoso_CustomTCP_4:
- "varus_service_x86.dll" at offset 0x6c6e4ce3 — a specific malware component name not found in legitimate software
- "net start %%1" / "net stop %%1" — service manipulation commands
- "ping 127.1 > nul" (3 instances) — delay technique
- Strings in close memory proximity suggest a single binary
DeepPanda_htran_exe:
- "-slave
- "[+] OK! I Closed The Two Socket." — htran-specific debug message
Why "inference" is correct, not "confirmed":
1. Attribution rests on a SINGLE detection tool (YARA) — no independent corroboration from network IOCs, domain registrations, or TTP-based attribution
2. htran is a publicly available tool used by multiple threat groups, not exclusively Codoso/Deep Panda
3. varus_service_x86.dll is more specific but a single string match doesn't constitute group attribution
4. The Tofu_Backdoor and IMPLANT_5_v3 matches lack detailed analysis of the matched byte sequences
5. No C2 domain or external IP has been linked to known Codoso/Deep Panda infrastructure
Assessment:
The YARA signatures confirm the PRESENCE of specific offensive tools (htran, a varus-named service DLL) in DC memory. These tools have historically been associated with Chinese APT groups including Codoso/Deep Panda. However, tool presence ≠ group attribution. The evidence supports "tools consistent with Codoso/Deep Panda TTPs" but falls short of confirmed attribution to that specific group.
The co-existence of msadvapi2 (persistent backdoor since June) + Metasploit (August-September operations) is consistent with known APT operational patterns (establishing persistent access, then conducting operations), but this pattern is not unique to any single group.
Evidence Chain
Network analysis of the base-rd-02 memory dump (IP: 172.16.6.11) reveals extensive C2 communications and lateral movement activity.
C2 Proxy Connections to 172.16.4.10:8080 (14+ connections):
ESTABLISHED:
- 172.16.6.11:49788 → 172.16.4.10:8080
- 172.16.6.11:49787 → 172.16.4.10:8080
- 172.16.6.11:49786 → 172.16.4.10:8080
CLOSE_WAIT (7 connections — indicating sustained C2 session teardowns):
- Ports 52703, 50253, 50263, 50259, 49774, 50257, 50254, 50258
CLOSED:
- Ports 63931, 49790, 49735
172.16.4.10:8080 is the same C2 proxy observed in the DC and file server compromises, confirming base-rd-02 is part of the same intrusion campaign.
RDP Outbound to File Server (172.16.4.5:3389) — 7 CLOSED connections:
- Ports 63826, 63834, 63958, 63848, 63823, 63841, 63835
- All CLOSED status, indicating multiple completed RDP sessions from base-rd-02 to the file server
SMB/445 Activity:
- 172.16.6.11:49763 → 172.16.4.5:445 ESTABLISHED (file server)
- 172.16.6.11:59352 → 172.16.7.15:445 ESTABLISHED
- Inbound: 172.16.6.14:65368 → 172.16.6.11:445 ESTABLISHED
WinRM/5985 Outbound:
- 172.16.6.11:49791 → 172.16.5.21:5985 CLOSED (remote PowerShell execution)
LDAP to Domain Controller:
- 172.16.6.11:56345 → 172.16.4.4:389 CLOSED
subject_srv.exe (F-Response forensic tool, port 3262):
- Listening on 0.0.0.0:3262 (PID 1096)
- 172.16.6.11:3262 → 172.16.5.50:39372 ESTABLISHED (forensic collection session)
External Connections:
- 172.16.6.11:49782 → 13.89.220.65:443 CLOSED (Microsoft Azure IP)
- 172.16.6.11:49360 → 52.16.55.11:443 CLOSED (Microsoft/cloud IP)
The 14+ connections to 172.16.4.10:8080, combined with the multiple RDP sessions to the file server and WinRM to 172.16.5.21, demonstrate that base-rd-02 was used as an active lateral movement pivot point in the attack campaign.
Affected Systems: bulk.httplogs, volatility.netscan, volatility.psscan
Evidence Chain
Multiple attacker staging directories were identified on base-rd-01 containing malicious tools:
1. c:\windows\temp\perfmon\ — Active Attack Staging Directory:
The primary implant p.exe (PID 8260) was deployed at c:\windows\temp\perfmon\p.exe, confirmed by cmdline output from volatility. An additional tool reference "c:\windows\temp\perfmon\sd." was found in ShimCache entries across multiple registry.system sources (source_ids 182, 202), confirming additional attacker tools were present in this directory. The "sd" filename is consistent with a service deployment tool (e.g., sd.exe for service management or lateral movement).
ShimCache evidence (from registry.system windows 625700 and 634542):
- c:\windows\temp\perfmon\sd. (truncated entry)
- Appears alongside system utilities like ipconfig.exe, systeminfo.exe, wmic.exe, taskkill.exe in the ShimCache ordering
2. C:\ProgramData\staging\install_wormhole\ — Software Deployment Staging:
An executable named install_msadvapi2_32.exe (14,183,796 bytes / ~14MB) was found at ProgramData\staging\install_wormhole\ in the MFT:
- Created: 2017-12-20 14:52:51
- Modified: 2018-05-08 21:07:43
- The file name "msadvapi2" mimics the legitimate Windows advapi32.dll
- ShimCache records show execution on 2018-05-08 21:07:43
- A related "Microsoft Advanced API 64" entry in ShimCache at C:\Program Files (x86)\Microsoft Advanced API 64\unins000.exe (2018-05-08 21:07:27) suggests this installs under a pseudo-legitimate directory name
The attacker used directories designed to blend with legitimate Windows components (perfmon = Performance Monitor, staging/install_wormhole = software deployment).
Evidence Chain
Base-wkstn-01 (IP 172.16.7.11) established 7 TCP connections to the known C2 proxy at 172.16.4.10:8080. All connections were in CLOSED state at memory capture time, indicating completed communication sessions. Source ports: 60085, 59703, 59511, 60121, 60001, 60167, 60117. This is the same C2 proxy address used across multiple compromised systems in the domain (file server, base-rd-02), confirming base-wkstn-01 was part of the same intrusion campaign. The connection pattern (multiple high ephemeral ports to a single destination on port 8080) is consistent with a reverse HTTPS or HTTP proxy used for command-and-control.
Evidence Chain
A suspicious executable named p.exe was dropped to c:\windows\temp\perfmon\ and executed on base-wkstn-01. Evidence from two independent sources:
-
Volatility cmdline (memory): cmd.exe (PID 5948) executing "C:\WINDOWS\system32\cmd.exe /C c:\windows\temp\perfmon\p.exe" with child process p.exe (PID 8260) running.
-
Registry ShimCache: Entry for "c:\windows\temp\perfmon\p.exe" with timestamp 2018-08-30 22:14:02, confirming file existence and execution on the filesystem.
The file location (Windows\Temp subdirectory), single-character filename, and execution via cmd.exe /C are consistent with attacker-dropped tools. The perfmon subdirectory name appears designed to blend with legitimate Windows Performance Monitor paths. The file was not found in the TSK file listing, suggesting it may have been deleted after use (anti-forensics).
Evidence Chain
A GZip-compressed PowerShell stager was delivered to base-wkstn-01 (172.16.7.11) via WinRM remoting at 2018-09-06 17:13:57. Evidence from PowerShell Operational Event Log (Event ID 4103):
The encoded command targeted -ComputerName 172.16.7.11 with a UTF-16LE encoded payload (PowerShell -EncodedCommand). Decoded payload:
$s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sIAAAAAAAAA..."))
The "H4sI" prefix identifies GZip-compressed data. This is the classic pattern used by post-exploitation frameworks (Metasploit, Empire, Cobalt Strike) to deliver compressed shellcode or scripts: Base64 decode → GZip decompress → Execute decompressed script via IEX.
The ScriptBlockId was 70ccb2b2-3c03-4d83-8a9c-e04f90151437. Additionally, earlier WinRM access was identified at 2018-08-22 04:50:38 from 172.16.5.25 (HTTP POST /wsman?PSVersion=5.1.14393.1944).
Evidence Chain
Memory forensics reveals a WMI-based remote code execution chain on base-wkstn-01:
-
WmiPrvSE.exe (PID 8840): Running from C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe with "-Embedding" flag. The use of the 32-bit (SysWOW64) WMI provider is suspicious since the system is 64-bit. Additionally, PID 4936 and PID 11948 WmiPrvSE instances were running from the 64-bit path.
-
PowerShell spawned by WMI: PID 5848 powershell.exe running from c:\windows\syswow64\windowspowershell\v1.0\powershell.exe with flags "-Version 5.1 -s -NoLogo -NoProfile". The NoProfile and NoLogo flags are standard post-exploitation framework indicators (avoid loading user profiles, reduce output).
-
rundll32 spawned by PowerShell: PID 6768 rundll32.exe (empty cmdline) is a child of the PowerShell process, representing shellcode injection.
This WmiPrvSE → PowerShell → rundll32 chain is the canonical execution pattern for WMI-based lateral movement used by Metasploit's wmi_exec and Cobalt Strike's WMI execution methods.
Evidence Chain
Base-wkstn-01 (172.16.7.11) had an active ESTABLISHED WinRM connection to 172.16.5.21:5985 (port 56150) at the time of memory capture. Three additional CLOSED WinRM connections to the same destination were also present (ports 56149, 56137, 56148), indicating sustained WinRM session activity.
Additionally, inbound WinRM access from 172.16.5.25 was captured:
- 2018-08-22 04:50:38: HTTP POST /wsman?PSVersion=5.1.14393.1944 from 172.16.5.25:52783 to 172.16.7.11:5985
The workstation was both a recipient of WinRM-based attacks (receiving encoded PowerShell commands) AND an origin point for outbound WinRM lateral movement to 172.16.5.21. An RPC connection to the domain controller (172.16.4.4:135) was also observed (port 56133, CLOSED).
Evidence Chain
PowerShell Operational logs (Event ID 4103) captured PowerView reconnaissance script execution at 2018-08-31 22:16:12. The logged script blocks contain PowerView function signatures including:
- "SearchTerm, Term to search for, default of 'pass'" - searching user descriptions for passwords
- "SearchField, User field to search, default of 'description'" - targeting AD user description fields
- "ADSpath, The LDAP source to search through, e.g. 'LDAP://OU=secret,DC=testlab,DC=local'" - LDAP enumeration
This is PowerView's Find-UserField function from the PowerSploit framework, commonly used by attackers to search Active Directory user account description fields for plaintext passwords - a common misconfiguration where administrators store passwords in the description field.
The timestamp (2018-08-31 22:16:12) falls within the attack window when multiple systems were compromised via WMI and WinRM lateral movement. This reconnaissance activity was captured across multiple PowerShell log sources (source IDs 74, 75, 81, 82, 86), confirming it was logged on multiple systems in the domain.
Evidence Chain
The active C2 PowerShell session (PID 1332, WoW64/32-bit) on base-wkstn-05 spawned multiple short-lived rundll32.exe processes consistent with Metasploit/Cobalt Strike process migration and module injection.
Short-lived rundll32.exe instances spawned by PowerShell PID 1332:
- PID 5300: 2018-08-31 01:31:44 – 01:31:46 (2 seconds lifetime)
- PID 5056: 2018-08-31 20:23:08 – 20:23:29 (21 seconds)
- PID 4240: 2018-08-31 20:23:17 – 20:23:35 (18 seconds)
- PID 1972: 2018-08-31 20:23:52 – 20:23:56 (4 seconds)
- PID 3720: 2018-08-31 21:07:21 – 21:07:28 (7 seconds)
Long-running persistent rundll32.exe:
- PID 7100 (PPID 7148): Started 2018-08-31 18:43:50, NO exit time — still running at memory capture. 5 threads, 337 handles.
The short-lived rundll32.exe instances (2-21 seconds) are characteristic of Metasploit's process injection technique where rundll32.exe is spawned as a sacrificial process, shellcode is injected into its address space, and it either completes its task or fails and exits. The long-running PID 7100 with 337 handles suggests a persistent implant module (e.g., keylogger, screenshot capture, or lateral movement module) that maintained execution throughout the investigation period.
This pattern — PowerShell downgrade → rundll32 injection — matches the Metasploit post/multi/manage/shell_to_meterpreter module behavior observed on other systems in this investigation.
Affected Systems: volatility.cmdline, volatility.psscan
Evidence Chain
HTTP logs on the DMZ FTP server (172.16.10.12) show WebDAV access from internal workstation 172.16.5.26 to administrative shares, indicating lateral movement or administrative file operations.
WebDAV Access Events:
1. 2018-09-07 02:46:37 - OPTIONS /c$ from 172.16.5.26 via Microsoft-WebDAV-MiniRedir/10.0.16299 (Windows 10 Fall Creators Update)
2. 2018-09-07 05:21:52 - OPTIONS /srl-ftp from 172.16.5.26 via Microsoft-WebDAV-MiniRedir/10.0.16299
Significance:
- The /c$ path is the hidden administrative share mapping to the C: drive, requiring administrator-level credentials
- WebDAV access to admin shares provides full filesystem access to the server from a remote machine
- The User-Agent string identifies a Windows 10 workstation (build 16299/Fall Creators Update)
- The srl-ftp directory contains the suspected Cobalt Strike stager (sub-win-x64_base-hunt_5682_3262.exe) and forensic response tools
Context: The same internal IP (172.16.5.26) also authenticated via FTP as dblake and performed RETR operations on /Users/ paths on 2018-08-07. This workstation appears to have been used for both legitimate FTP access and administrative operations against the DMZ FTP server.
Evidence Chain
Network analysis of the 172.16.5.21 memory dump reveals this system was the convergence point for WinRM-based lateral movement from ALL compromised hosts in the environment. Inbound WinRM (port 5985) connections were observed from:
Active ESTABLISHED WinRM sessions at capture time:
- 172.16.7.11:55308 → 172.16.5.21:5985 (base-wkstn-01)
- 172.16.4.4:57252 → 172.16.5.21:5985 (Domain Controller)
- 172.16.4.5:61707 → 172.16.5.21:5985 (File Server / BASE-FILE)
CLOSED WinRM sessions (completed):
- 172.16.7.16:57202 → 172.16.5.21:5985
- 172.16.6.14:55115 → 172.16.5.21:5985
- 172.16.7.15:61537 → 172.16.5.21:5985 (base-wkstn-05)
Other network activity:
- subject_srv.exe (F-Response, PID 9908) listening on port 3262, deployed 2018-09-07 19:35:23
- 172.16.5.21:3262 → 172.16.5.50:51490 ESTABLISHED (F-Response evidence collection)
- 172.16.5.21:53384 → 172.16.4.5:445 ESTABLISHED (SMB to file server)
- 172.16.5.21:52018 → 172.16.5.20:443 CLOSED
Significance:
All six source IPs connecting via WinRM to this system are confirmed compromised hosts (base-wkstn-01, base-wkstn-05, DC, file server) or are in subnets with confirmed compromised systems (172.16.6.14, 172.16.7.16). The attacker used WinRM from every compromised pivot point to access 172.16.5.21, making it a primary target or management host in the attack campaign. The cbarton-a account was also observed conducting remote PowerShell reconnaissance against this system on 2018-08-15 17:00-17:07 via wsmprovhost.exe -Embedding.
Evidence Chain
A previously unreported compromised system at 172.16.6.15 was discovered during continued analysis. The system shows the identical Metasploit/post-exploitation attack pattern observed across other compromised hosts in the shieldbase.lan domain.
Compromise Evidence:
- powershell.exe (PID 20780) spawned by PID 17016 at 2018-08-31 01:00:30
- Running from SysWOW64 (32-bit architecture downgrade, T1059.001)
- Command: powershell.exe -nop -w hidden -encodedcommand [base64]
- Decoded payload follows Metasploit stager pattern: $s=New-Object IO.MemoryStream(,[Convert]::FromBase64String("H4sI...")); IEX (New-Object IO.StreamReader(New-Object IO.Compression.GzipStream($s,[IO.Compression.CompressionMode]::Decompress))).ReadToEnd()
- This is the EXACT same GZip-compressed, base64-encoded PowerShell stager seen on other compromised systems (BASE-FILE, base-wkstn-01, base-wkstn-05, base-rd-02)
System Profile (172.16.6.15):
- Windows Server (boot: 2018-06-04 20:19:20)
- McAfee endpoint protection deployed (VirusScan Enterprise, Host Intrusion Prevention, ePO Agent)
- Puppet Labs agent (mcollective) communicating with 10.10.254.1:61613
- Nagios NCPA monitoring agent
- LARIAT (Lincoln Lab) java application with external connections (24.59.13.39, 104.96.34.39)
- RDP enabled (port 3389)
- Autorunsc.exe was run on 2018-08-15 (possible forensic triage)
Suspicious Binary:
- msadvapi2_64.exe running from C:\Program Files (x86)\Microsoft Advanced API 64\ as a service (child of services.exe PID 664)
- "Microsoft Advanced API" is NOT a legitimate Microsoft product name
- The binary name mimics Windows advapi32.dll (Advanced Windows 32 Base API)
- This warrants further malware analysis
Network Context:
- java.exe (PID 1736) connections to external IPs 24.59.13.39 and 104.96.34.39 (CLOSED state)
- McAfee management on port 8081
- No observed connection to C2 proxy 172.16.4.10:8080 in netscan data
Evidence Chain
On the system at 172.16.6.14, SearchUI.exe (PID 9316) contains injected shellcode in a PAGE_EXECUTE_READWRITE memory region (VadS). The injected code contains x64 assembly prologue bytes (H\x89T$\x10H\x89L$\x08) and what appears to be a Metasploit-style shellcode decoder stub (\xfc\xe8\x04\x00\x00\x00), which is characteristic of the CLD; CALL $+4 pattern used by Metasploit's block_api and reverse_tcp payloads.
Network analysis confirms SearchUI.exe had an active connection to 172.16.4.10:8080 in CLOSE_WAIT state, consistent with a completed C2 communication session. This IP:port combination (172.16.4.10:8080) has been identified as C2/proxy infrastructure across multiple compromised systems in this investigation.
SearchUI.exe is a legitimate Windows Search UI process that should never contain executable shellcode or connect to internal web proxy infrastructure. The combination of malfind shellcode detection and active C2 network connection confirms process injection was used to establish a covert communication channel.
Evidence Chain
On the system at 172.16.6.14, in addition to the SearchUI.exe shellcode injection (separate finding), powershell.exe (PID 5452) contains injected Metasploit shellcode. Malfind analysis (source_id 398) shows the process has a VadS region with PAGE_EXECUTE_READWRITE protection containing the bytes: \xfc\xe8\x04\x00\x00\x00 - the classic Metasploit block_api shellcode prologue (CLD followed by CALL $+4 to find the return address on the stack).
The complete disassembly pattern shows: fc (CLD), e8 04 00 00 00 (CALL +4), 2c 95 (SUB AL, 0x95), 33 99 (XOR EBX, [ECX]), eb 27 (JMP +0x27), 5f (POP EDI) - this is a known Metasploit encoded payload decoder stub.
This confirms that the threat actor deployed Metasploit payloads on this system, injecting into both SearchUI.exe (PID 9316, with C2 to 172.16.4.10:8080) and PowerShell (PID 5452). The dual injection across processes suggests the attacker maintained redundant access channels.
Evidence Chain
Network analysis of BASE-FILE (172.16.4.5, source_id 7) reveals an outbound WinRM connection from 172.16.4.5:56281 to 172.16.5.21:5985 (CLOSED state), initiated by svchost.exe (PID 928). This demonstrates that the previously compromised BASE-FILE server was used as a pivot point to access the msadvapi2-infected system via Windows Remote Management.
This connection chain establishes lateral movement between the compromised file server infrastructure and the msadvapi2 backdoor system:
- BASE-FILE (172.16.4.5) → WinRM (5985) → 172.16.5.21 (msadvapi2 system)
Additionally, the msadvapi2 system (172.16.5.21) also received inbound WinRM from 172.16.7.16 (separate finding), indicating multiple systems were used to access this machine remotely.
BASE-FILE also shows SMB connections to multiple systems (172.16.5.20, 172.16.6.11, 172.16.7.12), consistent with its role in the attacker's lateral movement infrastructure. The WinRM-based lateral movement is consistent with the WMI/PowerShell attack patterns observed across this campaign.
Affected Systems: volatility.netscan, volatility.pslist
Evidence Chain
The system identified as base-rd-06 (IP 172.16.6.13, R&D subnet) shows confirmed compromise with multiple indicators:
Backdoor Installation:
- msadvapi2_32.exe (PID 2288) running as a service under services.exe (PID 764) since 2018-08-17 13:46:31 from C:\Program Files (x86)\Microsoft Advanced API 32\
- msadvapi2_64.exe (PID 2304) running as a service under services.exe (PID 764) since 2018-08-17 13:46:31 from C:\Program Files (x86)\Microsoft Advanced API 64\
- Both are masquerading as "Microsoft Advanced API" — a fabricated name designed to blend with legitimate Microsoft binaries
C2 Communication:
- CLOSE_WAIT connection from 172.16.6.13:50093 → 172.16.4.10:8080 (organizational web proxy used as C2 relay)
- This matches the same C2 infrastructure observed across other compromised systems
Lateral Movement Evidence:
- RDP connection FROM 172.16.6.14:50663 → 172.16.6.13:3389 (CLOSED) — the attacker moved between R&D systems
- SMB connection to BASE-FILE server: 172.16.6.13:49889 → 172.16.4.5:445 (ESTABLISHED) — possible data access/staging
- WinRM listening on port 5985 — enabled for remote management
System Context:
- Windows 10 VM (VMware Tools present), boot time 2018-08-17 13:46:17
- McAfee endpoint security suite running (AV did not detect the msadvapi2 backdoor)
- LARIAT test framework (Lincoln Lab) present: prunsrv.exe PID 2136 → java.exe PID 2844
- Puppet configuration management agent running
- F-Response forensic agent deployed 2018-09-06 19:03:59
System Identification Note: This system is identified as base-rd-06 based on its location in the R&D subnet (172.16.6.x), being one of the four target memory dumps, and the F-Response deployment for the same investigation. The hostname was not directly confirmed in indexed evidence.
Evidence Chain
COUNTER-ANALYSIS NOTE: The cbarton-a remote PowerShell session on 2018-08-15 should be evaluated in the context of concurrent IR indicators.
Evidence of Concurrent IR Activity on 2018-08-15:
- Autorunsc.exe was executed on 172.16.6.15 on the same date (2018-08-15), consistent with Sysinternals-based IR triage
- The commands executed by cbarton-a (process enumeration via WMI, network adapter info, directory listing) are exactly what an incident responder would run during initial triage
- cbarton-a is referenced in Kerberos principals alongside other admin accounts (VPN infrastructure), suggesting a legitimate admin role
Commands Executed (all consistent with IR triage):
- Get-ChildItem -Force -Path "C:\WINDOWS\..." (directory enumeration — checking for suspicious files)
- WMI queries against \\BASE-RD-01\root\cimv2:Win32_Process (process listing — checking for malicious processes)
- Add-Member operations querying Username and NT AUTHORITY\SYSTEM processes (identifying process owners)
- Network adapter information gathering about 172.16.6.11 (network configuration review)
Assessment:
The most likely interpretation is that cbarton-a is an IT administrator who conducted initial IR triage on 2018-08-15, approximately two weeks before the main Metasploit deployment wave (Aug 27-31). The alignment with Autorunsc execution and the nature of the commands strongly favor the "legitimate admin" interpretation over "attacker using compromised credentials." However, this cannot be confirmed without access to HR/IT records identifying cbarton-a's role.
If cbarton-a IS a legitimate admin, this suggests the organization was aware of potential compromise by August 15 — before the main offensive operations escalated in late August.
Evidence Chain
The primary user account on base-rd-01 is shieldbase\tdungan, who maintained an active interactive session during the entire attack period. The following user accounts were observed interacting with base-rd-01:
1. shieldbase\tdungan (Primary User):
- Active desktop session with rich application set: Outlook (PID 8128), OneDrive, Chrome, Dashlane password manager
- RDP sessions were LOCAL logons (console access)
- User profile paths confirm as primary workstation user
- The attack ran silently in Session 0 via WMI while tdungan's interactive session continued in a separate session — the user likely had no visibility into the compromise
2. shieldbase\Administrator:
- Multiple LOCAL RDP sessions recorded in Terminal Services logs
- Used for system administration tasks
3. shieldbase\cbarton-a:
- Remote PowerShell session via WinRM on 2018-08-15 16:32-16:36 UTC
- Performed system reconnaissance (process enumeration, directory listing, network info)
- User profile (MFT record 154919) exists with AppData under Users\cbarton-a
- This admin account warrants investigation for potential compromise
4. shieldbase\jpallen:
- Profile referenced in ShimCache entries (C:\Users\jpallen\AppData\Local\Microsoft...)
- Appears to be an additional user account that previously logged into this system
No evidence of unauthorized account creation was found in the indexed event logs. The Windows Security event log was not indexed for base-rd-01, limiting visibility into authentication events (logon type 3/10 from remote systems).
Evidence Chain
The DMZ FTP server (IIS FTPSVC2 on 172.16.10.12, port 21) was targeted by brute force credential attacks from multiple external IP addresses. All attempts resulted in 530 (authentication failure) responses.
Attacker IPs and Targeted Accounts:
- 221.151.127.218: Targeted "administrator" account - multiple 530 failures
- 95.47.155.87: Targeted "stark-r" account - multiple 530 failures
- 138.197.213.41: Targeted "rsydow-a" account on 2018-08-16 04:19-04:20 - rapid-fire brute force with dozens of attempts in seconds
- 146.185.222.48: FTP scanning on multiple dates
- 185.255.31.2: FTP scanning on 2018-08-31
- 58.62.55.130, 60.212.42.56, 164.52.24.165, 61.153.54.38: Additional brute force/scanning sources on 2018-08-08 through 2018-08-10
Pattern Analysis: The attack on 138.197.213.41 showed the most aggressive pattern - rapid repeated USER/PASS sequences targeting the rsydow-a account with sub-second intervals, characteristic of automated credential stuffing tools. The targeting of "stark-r" and specific user accounts suggests pre-enumeration of usernames.
Failed Internal Authentication: 172.16.7.11 attempted and failed to authenticate as "dblake" on 2018-08-08 13:24:09 (530 failure), which may indicate lateral movement attempts from a compromised internal host.
None of the external brute force attempts appear to have succeeded based on the available evidence.
Evidence Chain
Two IIS FTP log files from the FTPSVC2 service on DMZ-FTP (172.16.10.12) were deleted, as identified by TSK file listing (deleted entries marked with *):
Deleted Logs:
- u_ex180805.log (August 5, 2018) - deleted, inode marked with * prefix
- u_ex180823.log (August 23, 2018) - deleted, inode marked with * prefix
Context: The FTP log directory (inetpub/logs/LogFiles/FTPSVC2/) contains daily logs spanning from u_ex180728.log through u_ex180907.log. The two deleted files create gaps in the logging timeline:
- Gap 1: August 5, 2018 - during the early investigation period
- Gap 2: August 23, 2018 - mid-incident window
All other daily log files in the sequence are intact. The selective deletion of only two log files, rather than all logs, suggests intentional evidence destruction targeting specific dates of interest rather than routine log rotation. IIS log rotation typically does not delete old files; it creates new ones daily.
These deleted logs may have contained evidence of unauthorized access or data exfiltration during the deleted time periods. The dates fall within the active brute force and scanning window (August 2018).
Evidence Chain
FTP logs show data retrieval operations targeting user profile directories on the DMZ FTP server (172.16.10.12) from internal workstation 172.16.5.26.
Evidence from carved FTP logs:
- 2018-08-07 23:30:07 - RETR /Users/ operations from 172.16.5.26 with data channel activity (DataChannelOpened)
- Multiple DataChannel operations around 23:30-23:36 on 2018-08-07
- 2018-08-07 23:32:23 - dblake authenticated successfully (PASS *** 230) from 172.16.5.26
- Additional FTP operations continued through 23:36
Carved Email Reference: ftp--dblake@ftp.stark-research-labs.com-Users-nfury-Asg... suggests FTP path access into the Users/nfury/ directory structure, indicating user nfury's files were accessed.
Related Activity: The dblake account was also used from Azure IP 40.121.0.91 on 2018-08-10 for FTP operations (TYPE A, PORT commands).
Concern: The RETR operations on /Users/ directories, particularly targeting nfury's profile, indicate file downloads from user directories. This is consistent with either legitimate file retrieval or data staging/exfiltration, depending on whether these operations were authorized. The activity from an internal workstation during late evening hours (23:30 UTC) warrants investigation.
Evidence Chain
FTP logs reveal that user rsydow-f authenticated to the DMZ FTP server (172.16.10.12) from two external IP addresses, with the password captured in cleartext in the logs.
Authentication Events:
1. 2018-07-16 21:08 - rsydow-f authenticated from 108.79.235.64 with password "mprsydow@mail.com" (230 success)
- Followed by PORT and data channel operations at 21:09
- Password visible in cleartext in carved FTP log entry
- 2018-09-03 18:20:25 - Activity from 165.227.50.129 with password "asdfa" (response code in log)
- SYST command executed (215 response)
-
Additional PORT and DataChannel operations at 18:21:35
-
2018-09-05 16:37:28-18:47:48 - rsydow-f authenticated from 165.227.50.129 as DMZ-FTP\rsydow-f
- Active data channel operations (DataChannelOpened/Closed)
- Session persisted for over 2 hours
User Profile: The rsydow-a user profile exists on the server at Users/rsydow-a/ with Downloads directory created 2018-08-07T19:05:25 and PowerShell ModuleAnalysisCache present (MFT entry 33601), indicating interactive logon activity.
Security Concern: The FTP password (mprsydow@mail.com) is logged in cleartext, violating credential protection best practices. The use of an email address as a password represents poor credential hygiene. The rsydow account accessed the server from multiple external IPs across multiple dates.
Evidence Chain
The rsydow-a user account has an interactive local profile on the DMZ FTP server (172.16.10.12) with evidence of active system usage, suggesting interactive logon access beyond FTP.
User Profile Evidence (from tsk.filelist and ez.mft):
- Full user profile directory at Users/rsydow-a/ with standard AppData structure
- rsydow-a Downloads directory created: 2018-08-07T19:05:25 (MFT)
- PowerShell ModuleAnalysisCache present (MFT entry 33601) - generated only when PowerShell runs interactively
- AppData/Roaming/Microsoft/Protect/CREDHIST file present - credential protection history, populated during interactive logon
- Network Connections phonebook (rasphone.pbk) present
External FTP Access by rsydow Account:
- rsydow-f authenticated successfully from 108.79.235.64 on 2018-07-16 (password: mprsydow@mail.com)
- rsydow-f authenticated from 165.227.50.129 on 2018-09-03 through 2018-09-05
- 138.197.213.41 attempted brute force against rsydow-a on 2018-08-16 (all failed)
Significance: The presence of an interactive user profile (PowerShell cache, CREDHIST) for rsydow-a indicates this account was used for RDP, console, or other interactive logon sessions, not merely FTP access. The rsydow-a/rsydow-f accounts appear related (possibly the same person using different account names for local vs FTP access). The Downloads directory creation date (2018-08-07) aligns with the period of active attacker interest in this server.
Evidence Chain
Bulk_extractor carved data reveals a SoftEther VPN Server running on 172.16.1.20, providing external remote access to the shieldbase.lan network. Multiple external IP addresses connected via VPN:
External VPN connections identified:
- 108.79.235.64: Connected via MSRASV5.20, associated with account rsydow-f (same IP used for FTP access to DMZ-FTP server)
- 144.121.9.222: Connected to SoftEther VPN Server
- 65.114.90.19: SoftEther VPN connection
- 107.107.185.201: SoftEther VPN connection
- 166.172.120.210: MSRASV connection
- 40.121.0.91: Azure IP associated with dblake FTP access (from DMZ FTP finding)
VPN User Accounts:
- NFury: VPN account (referenced as "NFury" in VPN logs at 172.16.1.20)
- rsydow: VPN account
- cbarton: Kerberos principal cbarton@SHIELDBASE.LAN
Security Implications:
The SoftEther VPN provides a legitimate pathway for external access that the attacker could leverage. The rsydow-f account accessing both FTP and VPN services from 108.79.235.64 suggests this may be a legitimate remote worker. However, the VPN infrastructure provides external entry that could have been used for initial access if credentials were compromised. The FTP brute force attempts against rsydow-a from 138.197.213.41 (separate from the VPN IP) suggest the attacker was aware of this account's existence.
Network Context:
The VPN server at 172.16.1.20 bridges external users into the 172.16.x.x corporate network, providing a potential initial access vector if VPN credentials were compromised through phishing, credential stuffing, or reuse from the FTP password exposure (mprsydow@mail.com).
Evidence Chain
On the base-mail Exchange server (172.16.4.6, boot 2018-08-30 21:27:22), a long-running rundll32.exe process (PID 15116) was identified running in Session 0 (system context) since 2018-08-31 19:47:10. The process runs as WoW64 (32-bit on 64-bit OS) and was spawned by an unknown parent (PPID 15896, which has exited).
DLL analysis (source_id 407) shows PID 15116 loads network-related libraries including rsaenh.dll (RSA encryption), napinsp.dll, mswsock.dll, GDI32.dll, and win32u.dll. This DLL combination is unusual for a legitimate rundll32.exe invocation. The command line for this process was not captured in the cmdline output, which may indicate it was launched with cleared command-line arguments.
Timeline context: This rundll32.exe started approximately 24 minutes after an RDP session began (2018-08-31 19:23:54, Session 2). The RDP session includes rdpclip.exe, explorer.exe, iexplore.exe, ServerManager, and PowerShell (PID 5144). The close temporal proximity suggests the rundll32.exe may have been deployed during this RDP session.
While base-mail does not show direct C2 connections to 172.16.4.10:8080, the pattern of a long-running Session 0 rundll32.exe with no visible command line is consistent with post-exploitation implant behavior seen on other compromised systems in this investigation.
Evidence Chain
COUNTER-ANALYSIS NOTE: This finding requires cautious interpretation.
Chrome.exe C2 Connections — Ambiguous:
Chrome.exe (PID 7300) connecting to 172.16.4.10:8080 and :80 is EXPECTED behavior on this network. The 172.16.4.10 system is the organizational web proxy used by ALL systems in the environment (including the confirmed-clean forensic workstation at 172.16.5.25 and admin workstation at 172.16.5.26). Chrome browser traffic through a web proxy is normal, not inherently a C2 indicator. Without evidence of Chrome being injected with malicious code or generating unusual traffic patterns (beaconing intervals, encoded payloads), Chrome's proxy connection alone does not confirm C2.
Malfind Detections — Require Scrutiny:
- MsDtsSrvr.exe (PID 1208): SQL Server Integration Services runtime. SSIS executes .NET code including dynamic compilation, which can legitimately produce RWX memory regions for JIT compilation. This detection is LIKELY a false positive without examination of the actual memory content.
- sqlceip.exe (PID 2184): SQL Server Customer Experience Improvement Program telemetry. .NET-based process with expected JIT RWX regions.
- explorer.exe (PID 1396): This detection is more concerning as explorer.exe does not typically require large RWX regions. However, without examining the hex dump for shellcode patterns (NOP sleds, call stubs), this remains ambiguous.
Assessment:
The finding remains at "inference" confidence. The Chrome proxy connection is NOT evidence of C2 by itself. The explorer.exe malfind is the strongest indicator but lacks corroboration from other sources (no PowerShell stager, no WMI chain observed on this system). This finding is individually weak but is noted as part of the broader pattern — the system is on the same subnet as confirmed compromised systems and had SMB connectivity from BASE-FILE.
Evidence Chain
Memory forensics of base-sp (172.16.4.7) reveals a Microsoft SharePoint Server with potentially suspicious PowerShell activity.
SharePoint Server Identification:
- IP: 172.16.4.7
- SharePoint service ports: 808 (SharePoint app server) and 22233 (SharePoint Search service) with multiple active local connections
- Multiple self-referential connections (172.16.4.7:808 ↔ 172.16.4.7:50xxx) are normal SharePoint inter-component communication
- plasrv.exe (PID 12636) running on port 58661 (Performance Logs & Alerts)
Suspicious PowerShell Activity:
- powershell.exe (PID 7520) created 2018-08-02 05:04:03 with active UDP connections (both IPv4 and IPv6)
- This PowerShell process was actively creating network connections, which could indicate:
a) Legitimate SharePoint administration via PowerShell
b) Post-exploitation activity (Metasploit/Empire stager)
- The timestamp (2018-08-02 05:04 UTC, early morning) warrants investigation for authorized activity
Network Exposure:
- WinRM (port 5985) LISTENING - accessible for remote management
- SMB (port 445) LISTENING
- No direct C2 connections to 172.16.4.10:8080 observed in available netscan data
- The server is on the same subnet (172.16.4.x) as the compromised file server (172.16.4.5), domain controller (172.16.4.4), and Exchange server (172.16.4.6)
Context:
- Admin workstation 172.16.5.26 RDP'd to "base-sp" at 2018-08-25 23:25:36 (from finding f_4cb0d525)
- Being on the 172.16.4.x server subnet, base-sp was within direct reach of the attacker who had compromised the DC and file server
- Without indexed EVTX Security logs from this server, authentication events and potential lateral movement TO this system cannot be fully assessed
Assessment:
The PowerShell process (PID 7520) on the SharePoint server at 2018-08-02 05:04 UTC is suspicious but without additional context (cmdline not captured, no EVTX), it cannot be confirmed as malicious. The server's WinRM exposure and subnet placement make it a high-value lateral movement target.
Evidence Chain
COUNTER-ANALYSIS CORRECTION: The filename components strongly suggest this is an F-Response forensic tool binary, not a Cobalt Strike stager.
F-Response Interpretation (PREFERRED):
- "sub" = F-Response "Subject" agent (the subject_srv.exe binary deployed on target systems)
- "win-x64" = Windows x64 platform variant
- "base-hunt" = The F-Response management workstation hostname (confirmed at 172.16.5.25, running license_ctrl.exe on port 5682)
- "5682" = F-Response license controller port (confirmed: PID 1716 on base-hunt listening on port 5682)
- "3262" = F-Response subject agent port (confirmed: subject_srv.exe listens on port 3262 across all deployed systems)
The file resides in the srl-ftp directory alongside fresponse-agent.msi (the F-Response installer) and Mnemosyne.sys (a forensic driver), consistent with an IR tool staging location.
Remaining Concern — Timestamp Anomaly:
MFT analysis shows $SI Created (2013-08-22) predates $FN timestamps (2018-08-09) by 5 years. This could indicate:
a) Timestomping by an attacker who placed a malicious file alongside IR tools
b) The file was extracted from a signed/versioned installer package that preserved original build timestamps
c) Filesystem metadata inconsistency during file copy or extraction
At 4,246 bytes, the file size is consistent with both a small stager AND a minimal agent executable.
Assessment:
Given the strong filename correlation to F-Response port parameters (5682/3262 exactly match confirmed F-Response infrastructure), the co-location with other F-Response tools, and the absence of any evidence this file was executed maliciously, the Cobalt Strike interpretation is LESS likely than the F-Response interpretation. The timestamp anomaly prevents full dismissal but is not sufficient alone to override the naming evidence. Severity downgraded from high to low.
Original MITRE mappings removed: T1059.001 (no execution evidence), T1036.006, T1070.006 (timestamp anomaly preserved as a note).
Evidence Chain
Memory forensics of base-wkstn-02 (172.16.7.16, dual-homed 10.10.150.177) reveals an actively used Windows 10 workstation. System boot time: ~2018-09-03 13:51.
Legitimate User Activity:
- OUTLOOK.EXE (PID 3044): Multiple ESTABLISHED connections to Exchange server (172.16.4.6:80) - confirmed OWA/Exchange access
- firefox.exe (PID 3656): Active browser session with connections to 104.88.80.153:443 (SYN_SENT) and localhost loopback (port 7055, 49429)
- SMB to file server: 172.16.7.16:49236 → 172.16.4.5:445 ESTABLISHED
LARIAT Framework Present:
- java.exe (PID 1752/5040) running LARIAT with connections to 10.10.200.207:5672 (RabbitMQ AMQP)
- LARIAT java processes connected to multiple external IPs in CLOSED state: 24.139.91.27, 88.197.234.24, 104.201.158.26, 216.232.147.26, 248.86.12.27
- LARIAT ncpa_passive.exe (PID 2784) listening on localhost:49299
Infrastructure Services:
- McAfee Agent (masvc.exe PID 1824), macmnsvc.exe (PID 1744) on port 8081/8082
- Puppet Labs rubyw.exe (PID 5796) → 10.10.254.1:61613 ESTABLISHED
- subject_srv.exe (PID 488, F-Response) on port 3262 → 172.16.5.50:46980 ESTABLISHED
Assessment:
- No Metasploit/Empire PowerShell stager detected
- No msadvapi2 backdoor present
- No C2 connections to 172.16.4.10:8080 observed
- No WMI→PowerShell attack chain observed
- No malfind code injection detections specific to this system
- Previous WinRM connection from this IP to 172.16.5.21:5985 was observed (CLOSED state in 172.16.5.21's memory), but this could have been initiated by the attacker using compromised credentials rather than indicating this workstation itself was compromised
This system appears to be a legitimate workstation that was accessible to the attacker via WinRM but does not show active compromise at the time of memory capture.
Evidence Chain
CORRECTION: subject_srv.exe has been identified as the F-Response Subject agent, a legitimate forensic remote acquisition tool — NOT malicious activity.
Conclusive Evidence:
The command line for subject_srv.exe (PID 1096 on base-rd-02, PID 6160 on file server) reads:
C:\windows\subject_srv.exe -s "base-hunt.shieldbase.lan:5682" -l 3262 -v "F-Response Subject" -k "155522845"
The "-v F-Response Subject" parameter identifies this as the F-Response forensic acquisition agent. F-Response is a commercial forensic tool that provides remote access to systems for evidence collection. The "base-hunt.shieldbase.lan" server name suggests a forensic investigation workstation.
Expected Behavior Explained:
- Installed in C:\windows\ — F-Response deploys its agent to the Windows directory
- Running as WoW64 (32-bit) — F-Response Subject agent is a 32-bit binary
- Listening on non-standard port 3262 — this is the F-Response access port specified by -l flag
- Outbound to 172.16.5.50 — the forensic examiner's workstation conducting evidence collection
- Running as a service from services.exe — F-Response installs as a Windows service for persistence during evidence collection
- Present since 2018-04-10 — consistent with a previously deployed forensic investigation capability or an earlier investigation
Assessment:
All indicators previously assessed as suspicious are consistent with legitimate F-Response deployment. This finding supersedes the original assessment. The YARA Codoso/Deep Panda matches previously associated with subject_srv.exe should be evaluated independently of this binary.
Previous MITRE ATT&CK mappings (T1543.003, T1036) are removed as this is legitimate software.
Evidence Chain
YARA memory scanning produced 233 windows of APT6_Malware_Sample_Gen matches across the memory dumps. Upon examination of the matched strings, these detections are assessed as FALSE POSITIVES rather than evidence of APT6 malware.
The matched strings are generic and commonly found in legitimate Windows binaries and system memory:
- "shellcode" - generic string found in many security tools and documentation
- "synflood", "udpflood" - networking terms found in system libraries
- "C:\WINDOWS\system32\" - common Windows system path prefix
- Other generic byte patterns common in system DLLs
These strings individually and collectively do not indicate the presence of APT6 malware. The YARA rule APT6_Malware_Sample_Gen appears to use overly broad signatures that match common system artifacts.
While the DC IS compromised (as evidenced by the C2 channel, PowerView execution, and Meterpreter-style code injection), the YARA matches do not provide attribution to APT6 or any specific threat actor. The attack TTPs (PowerView, WMI, Meterpreter, Rar.exe staging) are widely used across criminal and nation-state groups.
Evidence Chain
COUNTER-ANALYSIS CORRECTION: The Win32_ShadowCopy PowerShell activity originally characterized as "Shadow Copy Manipulation" and "ransomware preparation" has been re-assessed as shadow copy enumeration by an administrator or incident responder.
Corrected Evidence Analysis:
The PowerShell Operational Log (Event ID 4103, 2018-08-31 21:53:03) captures:
1. Get-CimInstance -ClassName win32_ShadowCopy — This is a READ/QUERY operation, NOT a deletion command. The Delete() method or Remove-CimInstance cmdlet are NOT present.
2. ForEach-Object { write "VSC created $($_.installdate) for host $($_.Servicemachine)" } — This simply DISPLAYS the creation date and service machine for each shadow copy. This is diagnostic output, not manipulation.
3. The user executing this was shieldbase\rsydow-a via WinRM (Host Application: wsmprovhost.exe -Embedding), NOT spsql as originally reported. rsydow-a appears to be an administrator or incident responder.
NetFirewallRule Module Loading:
The co-occurring NetFirewallRule module content (Export-ModuleMember for Show-NetFirewallRule, Rename-NetFirewallRule) is automatic PowerShell module loading, not explicit firewall manipulation.
Assessment:
This activity is consistent with routine administrative shadow copy auditing or incident response reconnaissance. The original T1490 (Inhibit System Recovery) mapping is removed as no evidence of shadow copy deletion exists. The original finding significantly overstated the threat level.
MITRE ATT&CK mapping removed: T1490 (no deletion evidence), T1562.004 (no firewall manipulation evidence). Retaining T1059.001 for PowerShell execution only.
Evidence Chain
COUNTER-ANALYSIS CORRECTION: The original finding framed subject_srv.exe deployment as the attacker "installing a persistent backdoor service" as a final step in the attack chain. This is INCORRECT — finding f_5bcb1c4e conclusively identifies subject_srv.exe as the F-Response forensic remote acquisition agent deployed by incident responders.
Corrected Timeline:
The deployment of subject_srv.exe between Snapshot5 (~2018-09-05 15:03) and Base-file-memory (~2018-09-06 19:25) represents the IR team deploying F-Response for forensic evidence collection, NOT an attacker establishing persistence.
Valid Observations (Retained):
- Snapshot5 captured active attacker operations: Rar.exe data staging (PID 2524), PowerShell C2 chain (PIDs 4072/3164)
- Base-file-memory captured post-IR-deployment state with F-Response active and attacker artifacts still resident in memory
- The PowerShell C2 chain remained active across both captures, confirming sustained attacker presence
- Rar.exe completed execution between captures (exited 2018-09-05 14:52:56)
Impact on Attack Timeline:
The subject_srv.exe deployment milestone should be removed from the attacker kill chain. The actual attacker timeline on BASE-FILE remains: WMI C2 initiation (Aug 28) → rundll32 injection (Aug 30-Sep 6) → data staging via Rar.exe (Sep 5).
MITRE mapping corrected: T1543.003 removed (subject_srv.exe is IR tooling, not attacker persistence). T1560.001 retained for Rar.exe staging.
Evidence Chain
Analysis of network connections from memory dumps and disk artifacts reveals the following IOCs and network architecture:
Compromised Hosts (10+ systems):
- 172.16.4.5 (BASE-FILE) - Active C2 implant, data staging, Rar.exe exfil prep
- 172.16.4.4 (BASE-DC) - Domain controller, YARA Codoso/Deep Panda tool signatures
- 172.16.5.21 - WinRM convergence point, msadvapi2 backdoor, cross-subnet pivot
- 172.16.5.20 - Web/DB server, Chrome C2 proxy connections, process injection
- 172.16.6.11 (base-rd-02) - Metasploit stager, p.exe implant, C2 via proxy
- 172.16.6.13 (base-wkstn-03/base-rd-06) - msadvapi2 + Metasploit dual compromise
- 172.16.6.14 (base-wkstn-04) - Interactive C2, SearchUI.exe injection, 30+ proxy connections
- 172.16.6.15 - msadvapi2_64 + Metasploit stager
- 172.16.7.15 (base-wkstn-05) - 3 WMI attack chains, rundll32 injection
- 172.16.7.16 (base-wkstn-01) - WMI stager, WinRM encoded command delivery
C2/Proxy Infrastructure:
- 172.16.4.10:8080 - Web proxy used for C2 tunneling (7+ compromised hosts connect)
Lateral Movement Hub:
- 172.16.5.21:5985 - WinRM convergence from all compromised subnets
Legitimate Infrastructure (Not Compromised):
- 172.16.5.25 (base-hunt) - F-Response forensic workstation
- 172.16.5.50 - F-Response evidence collection endpoint
- 172.16.5.26 (admin workstation) - SSH/RDP admin access, no compromise indicators
- 172.16.4.6 (base-mail) - Exchange server, suspicious rundll32 but no confirmed C2
- 172.16.4.7 (base-sp) - SharePoint, suspicious PowerShell but unconfirmed
External IOCs:
- 108.79.235.64 - rsydow-f FTP/VPN access (likely legitimate remote worker)
- 138.197.213.41 - Aggressive brute force against rsydow-a FTP account
- 221.151.127.218, 95.47.155.87, 146.185.222.48, 185.255.31.2 - FTP scanning/brute force
- 172.16.1.20 - SoftEther VPN server (external access gateway)
Evidence Chain
Analysis of $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT data detected only 2 timestomping entries across both disk images. Both were root directory entries (likely OS installation artifacts) and showed no indicators of malicious timestamp manipulation.
Forensic Note:
Despite the absence of timestomping detections, the attacker used other defense evasion techniques:
- Placing subject_srv.exe in C:\windows\ to blend with legitimate system files
- Using legitimate tools (PowerShell, rundll32, WMI) for attack operations (Living off the Land)
- Tunneling C2 traffic through the web proxy at 172.16.4.10:8080
- Shadow Copy manipulation to prevent recovery
The lack of timestomping may indicate that the attacker did not attempt to modify file timestamps, or that the tools used (which are primarily memory-resident) didn't require timestamp manipulation for persistence.
Evidence Chain
YARA scanning of the base-rd-02 disk image (base-rd-02-cdrive.E01) produced a single rule match: APT_MAL_RU_WIN_Snake_Malware_May23_1. Upon examination of the matched strings, this detection is assessed as a FALSE POSITIVE.
Matched Strings:
- $a: 25 73 23 31 → hex for "%s#1" (a generic format specifier)
- $b: 25 73 23 32 → hex for "%s#2" (a generic format specifier)
Multiple offset matches were found across the disk image at various locations. These format strings ("%s#1", "%s#2") are extremely common in Windows binaries and are used for string formatting operations. They do not indicate the presence of Snake/Uroburos malware.
Context:
- The same false positive occurred on the base-rd-01 disk image with identical matched strings
- No other YARA rules triggered on the base-rd-02 disk image
- The real compromise on base-rd-02 was identified through memory forensics (PowerShell C2 chain, p.exe implant, malfind hits) rather than disk-based signatures
- The attacker's tools on base-rd-02 were primarily memory-resident, explaining the limited disk-based signature matches
Assessment:
The Snake Malware YARA rule uses overly broad format string signatures that match common Windows binary patterns. No evidence of Snake/Uroburos malware was found on base-rd-02.
Evidence Chain
The DMZ FTP server is identified as:
System Identity:
- Hostname: DMZ-FTP
- IP Address: 172.16.10.12
- Domain: shieldbase.lan (Stark Research Labs)
- Operating System: Windows Server 2012 R2 (kernel version 6.3.x per MFT entries)
FTP Service Configuration:
- Software: Microsoft IIS FTP Service (FTPSVC2, version 8.5.0.0 per carved package data)
- Log Directory: inetpub/logs/LogFiles/FTPSVC2/
- FTP Logs: Daily rotation files from u_ex180728.log through u_ex180907.log
- IIS HTTP (W3SVC1): Also running with logs at inetpub/logs/LogFiles/W3SVC1/
- Web Root: inetpub/wwwroot/ with default IIS content (iisstart.htm, iis-85.png)
FTP User Accounts Identified:
- dblake (DMZ-FTP\dblake): Legitimate user, accessed from Azure (40.121.0.91) and internal (172.16.5.26)
- rsydow-f (DMZ-FTP\rsydow-f): External user, accessed from 108.79.235.64 and 165.227.50.129
- rsydow-a: User profile exists at Users/rsydow-a/ with interactive session evidence (PowerShell cache, Downloads directory created 2018-08-07)
- anonymous: Attempted from 172.16.5.26, authentication failed
FTP Content Directory (srl-ftp):
- fresponse-agent.msi: Forensic response tool, created 2018-09-07T20:57:23
- Mnemosyne.sys: Likely forensic driver/tool
- sub-win-x64_base-hunt_5682_3262.exe: Suspicious executable (see separate finding)
- test.txt: Test file
Network Exposure: The FTP server on port 21 was accessible from external internet addresses, with brute force attempts observed from multiple countries.
Evidence Chain
The DMZ FTP server disk image contains Windows Event Log files that were not extracted or indexed during the initial processing phase. This creates an analysis gap for several investigation questions.
Event Logs Present on Disk (from TSK file listing):
- Archive-Security-2018-08-08-08-57-05-737.evtx
- Archive-Security-2018-08-20-00-56-16-595.evtx
- Archive-Security-2018-08-23-23-18-50-784.evtx
- Additional Security archive files
- Microsoft-Windows-TaskScheduler%4Operational.evtx
- Multiple other Microsoft-Windows-* operational and admin logs
- PowerShell operational logs
Impact on Investigation:
Without these logs indexed, the following questions cannot be fully answered for the DMZ FTP server:
- Unauthorized account creation or privilege escalation
- Detailed authentication events (logon types, source workstation names)
- Event log clearing/tampering (Event IDs 1102, 104)
- Scheduled task creation or modification (persistence)
- PowerShell execution history
- Service installation events
Recommendation: Run EVTX extraction (run_evtx_parser) on /evidence/dmz-ftp-cdrive.E01 and index the Security, System, PowerShell, and TaskScheduler logs to complete the investigation.
Evidence Chain
Memory analysis confirms 172.16.5.25 is the forensic investigation workstation "base-hunt.shieldbase.lan", running the F-Response management suite and AccessData FTK Imager. However, the system shows 15+ connections to the C2 proxy at 172.16.4.10:8080 which warrant documentation.
Forensic Tool Processes:
- license_ctrl.exe (PID 1716): F-Response license controller, listening on port 5682
- subject_ctrl.exe (PID 7076): F-Response subject controller
- connector_ctrl.exe (PID 6868): F-Response connector controller
- imager_ctrl.exe (PID 3324): F-Response imager controller
- license_monitor (PID 4272): F-Response license monitor
- main_console.exe (PID 6960): F-Response main console
- FTK Imager.exe (PID 928): AccessData forensic imager, started 2018-09-06 18:48:20
- ftusbsrvc.exe (PID 4916): FTK USB service on port 33001
- ruby.exe (PIDs 2240, 6780, 8116): F-Response backend (Ruby-based)
Network Connections to C2 Proxy 172.16.4.10:8080:
6 CLOSE_WAIT connections (ports 63084, 63082, 63039, 63036, 64358, 62946)
3 CLOSED connections (ports 58926, 58928, 58917, 58927, 58932, 58937, 58938, 58939, 58940)
Total: 15+ connections
External Connection:
- 172.16.5.25:64720 → 108.79.235.64:33000 ESTABLISHED
Assessment:
While the C2 proxy connections COULD represent legitimate web browsing through the organizational proxy by the forensic examiner, the CLOSE_WAIT state on 6 connections is notable (indicating the remote side closed but local cleanup didn't complete). The connection to 108.79.235.64:33000 is likely related to the F-Response USB service (port 33001 vs 33000) or remote evidence collection. Given this is the forensic workstation, these connections are assessed as likely benign but should be verified with the incident response team.
Evidence Chain
A Microsoft Exchange Server at 172.16.4.6 was captured in memory during the investigation. While no direct C2 indicators (connections to 172.16.4.10:8080) or WMI→PowerShell attack chains were found, the server is on the same subnet as compromised systems and accessible to the attacker.
Exchange Server Configuration:
- IP: 172.16.4.6 (also 10.10.4.6 dual-homed)
- Services: MSExchangeFrontend, EdgeTransport, MSExchangeSubmission, MSExchangeDelivery, MSExchangeMailboxAssistants, MSExchangeRepl, MSExchangeHMHost, MSExchangeHMWorker, ForefrontActive (anti-spam)
- Multiple w3wp.exe IIS worker processes serving OWA/EWS
- noderunner.exe (Exchange search indexing)
- hostcontroller process
- Boot time: 2018-08-30 21:27:31
Network Connections:
- Multiple LDAP connections to DC (172.16.4.4:389 and :3268) - expected Exchange behavior
- SMB connection to DC (172.16.4.4:445) - expected
- HTTP (port 80) ESTABLISHED from 172.16.7.16 - OWA web access
- powershell.exe (PID 5144) connected to DC LDAP and localhost:890 - likely Exchange Management Shell
- subject_srv.exe (F-Response, PID 17880) on port 3262 → 172.16.5.50 (forensic collection)
Assessment:
The Exchange server does not show the characteristic WMI→PowerShell→rundll32 attack chain or C2 proxy connections observed on other compromised systems. However, with domain admin credentials compromised and the attacker having full AD control, the Exchange server's email contents would have been accessible. The powershell.exe process (PID 5144) warrants further investigation but may be legitimate Exchange Management Shell. No Security EVTX logs were indexed for this system.
Evidence Chain
Memory forensics of base-wkstn-06 (172.16.5.26, boot 2018-07-29 12:55:18) identifies a Windows 10 administrative workstation in the 172.16.5.x management subnet. Despite extensive access to critical infrastructure, no indicators of compromise were found.
System Profile:
- Active user session with PuTTY SSH sessions to multiple infrastructure hosts:
- @base-elk (ELK stack), @onion-master (3 sessions), @proxy, @dmz-smtp, @dmz-dns
- RDP sessions via mstsc.exe to:
- /v:"base-sp" (SharePoint server, 2018-08-25 23:25:36)
- /v:"base-dc" (Domain Controller, 2018-09-01 17:23:44)
- Puppet configuration management agent (rubyw.exe PID 3800 → 10.10.254.1:61613 ActiveMQ)
- SMB to file server 172.16.4.5:445 ESTABLISHED (since 2018-08-09)
- notepad++ and MicrosoftEdge present in process tree
Negative Findings (No Compromise):
- No Metasploit/Empire PowerShell stagers or encoded commands detected
- No msadvapi2 backdoor present
- No WMI → PowerShell → rundll32 attack chain observed
- No connections to C2 proxy 172.16.4.10:8080
- No malfind code injection detections
- No suspicious rundll32.exe processes with empty command lines
WebDAV Activity to DMZ FTP Server:
Previously documented (finding f_954b7adf): this IP accessed /c$ and /srl-ftp via WebDAV on DMZ-FTP (172.16.10.12) on 2018-09-07. The dblake account from this IP also performed FTP operations including file retrieval from /Users/ directories.
Assessment:
base-wkstn-06 is a legitimate IT administrator workstation with broad infrastructure access (DC, ELK, DNS, SMTP, proxy, SharePoint) that was NOT compromised during the attack campaign. Its proximity to compromised systems in the domain and its elevated access privileges would have made it a high-value target. The absence of compromise indicators, despite the attacker having domain admin access and the ability to deploy WMI/WinRM attacks to any system, may indicate the attacker either did not target this specific workstation or had not yet reached it before incident response began.
Evidence Chain
MITRE ATT&CK Coverage
Indicators of Compromise
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
| Internal IP | 172.16.4.10 |
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser | VT | |
| Port | TCP 8080 |
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser | ||
| Internal IP | 172.16.4.5 |
PowerShell-Based C2 Activity: WmiPrvSE → PowerShell → Rundll32 Swarm on File Ser | VT | |
| Internal IP | 172.16.6.11 |
WMI-Initiated PowerShell C2 Chain on base-rd-02 (172.16.6.11) | VT | |
| Port | TCP 49788 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49787 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49786 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 3389 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49763 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 445 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 59352 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Internal IP | 172.16.7.15 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Internal IP | 172.16.6.14 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Port | TCP 65368 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49791 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Internal IP | 172.16.5.21 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Port | TCP 5985 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 56345 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Internal IP | 172.16.4.4 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Port | TCP 389 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 3262 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Internal IP | 172.16.5.50 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Port | TCP 39372 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49782 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| External IP | 13.89.220.65 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Port | TCP 443 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| Port | TCP 49360 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | ||
| External IP | 52.16.55.11 |
Extensive C2 and Lateral Movement Network Connections from base-rd-02 | VT | |
| Internal IP | 172.16.6.15 |
Remote PowerShell Reconnaissance by cbarton-a on base-rd-02 | VT | |
| Internal IP | 172.16.7.11 |
C2 Network Connections from base-wkstn-01 to 172.16.4.10:8080 | VT | |
| Internal IP | 172.16.5.25 |
Encoded PowerShell Stager Delivered to base-wkstn-01 via WinRM | VT | |
| Port | TCP 52783 |
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21 | ||
| Port | TCP 135 |
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21 | ||
| Port | TCP 56150 |
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21 | ||
| Port | TCP 56133 |
Lateral Movement via WinRM from base-wkstn-01 to 172.16.5.21 | ||
| Internal IP | 172.16.10.12 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 221.151.127.218 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 95.47.155.87 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 138.197.213.41 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 146.185.222.48 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 185.255.31.2 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 58.62.55.130 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 60.212.42.56 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 164.52.24.165 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| External IP | 61.153.54.38 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | VT | |
| Port | TCP 21 |
External FTP Brute Force Attacks Against DMZ FTP Server from Multiple Source IPs | ||
| Internal IP | 172.16.5.26 |
WebDAV Lateral Movement to DMZ FTP Server Admin Share from Internal Workstation | VT | |
| External IP | 40.121.0.91 |
FTP Data Exfiltration of User Profile Directories from DMZ FTP Server | VT | |
| External IP | 108.79.235.64 |
External FTP User rsydow-f Authenticated with Cleartext Password Exposure | VT | |
| External IP | 165.227.50.129 |
External FTP User rsydow-f Authenticated with Cleartext Password Exposure | VT | |
| Port | TCP 55308 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 57252 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 61707 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Internal IP | 172.16.7.16 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | VT | |
| Port | TCP 57202 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 55115 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 61537 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 51490 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 53384 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Port | TCP 52018 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | ||
| Internal IP | 172.16.5.20 |
WinRM Convergence: 172.16.5.21 as Cross-Subnet Lateral Movement Hub Across All C | VT | |
| Internal IP | 172.16.1.20 |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs | VT | |
| External IP | 144.121.9.222 |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs | VT | |
| External IP | 65.114.90.19 |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs | VT | |
| External IP | 107.107.185.201 |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs | VT | |
| External IP | 166.172.120.210 |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs | VT | |
| Internal IP | 172.16.4.1 |
Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TT | VT | |
| Internal IP | 172.16.6.13 |
Complete Attack Timeline: 6+ Systems Compromised Across 10 Days Using Uniform TT | VT | |
| Internal IP | 10.10.254.1 |
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System | VT | |
| Port | TCP 61613 |
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System | ||
| External IP | 24.59.13.39 |
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System | VT | |
| External IP | 104.96.34.39 |
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System | VT | |
| Port | TCP 8081 |
Metasploit PowerShell Stager on 172.16.6.15 - Additional Compromised System | ||
| Internal IP | 172.16.4.6 |
Suspicious rundll32.exe on base-mail Exchange Server (PID 15116) | VT | |
| Port | TCP 56281 |
BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21) | ||
| Internal IP | 172.16.7.12 |
BASE-FILE (172.16.4.5) WinRM Lateral Movement to msadvapi2 System (172.16.5.21) | VT | |
| Port | TCP 59071 |
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me | ||
| Internal IP | 172.16.7.14 |
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me | VT | |
| Port | TCP 54302 |
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me | ||
| Internal IP | 10.10.150.181 |
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me | VT | |
| Port | TCP 54120 |
base-wkstn-03 (172.16.7.14) - Comprehensive Compromise: WMI Lateral Movement, Me | ||
| Internal IP | 172.16.4.7 |
base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo | VT | |
| Port | TCP 808 |
base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo | ||
| Port | TCP 58661 |
base-sp (172.16.4.7) - SharePoint Server with PowerShell Activity and WinRM Expo | ||
| Port | TCP 50093 |
base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection | ||
| Port | TCP 50663 |
base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection | ||
| Port | TCP 49889 |
base-rd-06 (172.16.6.13) Compromised with msadvapi2 Backdoor and C2 Connection | ||
| Port | TCP 59106 |
Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 wit | ||
| Port | TCP 18278 |
Dual Attack Chains on base-wkstn-04 (172.16.6.14): Interactive PowerShell C2 wit |
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
| Path | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
PowerView/PowerSploit Active Reconnaissance from Domain Controller | ||
| Path | C:\ProgramData\staging\install_wormhole\ |
Attacker Staging Directories with Malicious Tooling on base-rd-02 | ||
| Path | C:\Program |
Attacker Staging Directories with Malicious Tooling on base-rd-02 | ||
| Path | C:\Users\jpallen\AppData\Local\Microsoft |
User Account tdungan Compromised — Active Session During Attack on base-rd-02 | ||
| Path | C:\WINDOWS\system32\cmd.exe |
Malicious Executable Dropped and Executed: c:\windows\temp\perfmon\p.exe | ||
| Path | C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe |
WMI-Based Remote Code Execution on base-wkstn-01 |
| Type | Value | Enrichment | Context | Actions |
|---|---|---|---|---|
ftp--dblake@ftp.stark-research-labs.com |
FTP Data Exfiltration of User Profile Directories from DMZ FTP Server | |||
mprsydow@mail.com |
External FTP User rsydow-f Authenticated with Cleartext Password Exposure | |||
cbarton@shieldbase.lan |
SoftEther VPN Server on 172.16.1.20 with External Access from Multiple IPs |
Evidence Browser
Evidence Sources
| Source Name | Extractor | Lines | Hash | Referenced By |
|---|---|---|---|---|
| tsk.filelist | sleuthkit | 245104 | blake2b:eceaf772... |
7 findings |
| volatility.psscan | volatility3 | 125 | blake2b:9ac8a4aa... |
12 findings |
| volatility.modscan | volatility3 | 218 | blake2b:38bd04f0... |
— |
| tsk.filelist | sleuthkit | 159142 | blake2b:6609e2ab... |
7 findings |
| bulk.domain | bulk_extractor | 1897533 | blake2b:950b8f8f... |
8 findings |
| volatility.netscan | volatility3 | 146 | blake2b:b50ecd53... |
25 findings |
| volatility.netscan | volatility3 | 125 | blake2b:89e7a8f2... |
25 findings |
| volatility.psscan | volatility3 | 102 | blake2b:e79f8559... |
12 findings |
| volatility.psscan | volatility3 | 93 | blake2b:e3947cf4... |
12 findings |
| bulk.email | bulk_extractor | 1044028 | blake2b:e21446f5... |
1 finding |
| bulk.ether | bulk_extractor | 6 | blake2b:8e1aca4c... |
— |
| bulk.ip | bulk_extractor | 31 | blake2b:7dfb22e2... |
— |
| bulk.packets | bulk_extractor | 165 | blake2b:beb2e58a... |
— |
| bulk.rfc822 | bulk_extractor | 1075 | blake2b:be12cf1d... |
— |
| bulk.tcp | bulk_extractor | 14 | blake2b:58383280... |
— |
| bulk.url | bulk_extractor | 585039 | blake2b:dcb0526f... |
— |
| bulk.url_facebook-address | bulk_extractor | 8 | blake2b:f386d751... |
— |
| bulk.url_searches | bulk_extractor | 15 | blake2b:6b63ad98... |
— |
| bulk.url_services | bulk_extractor | 6781 | blake2b:f8995f79... |
— |
| volatility.modscan | volatility3 | 146 | blake2b:77b90c7b... |
— |
| volatility.modscan | volatility3 | 145 | blake2b:efc97b70... |
— |
| chainsaw.hunt | chainsaw | 2 | blake2b:fb984047... |
— |
| ez.amcache | eztools | 639 | blake2b:af51025f... |
— |
| bulk.domain | bulk_extractor | 1484914 | blake2b:cff4769d... |
8 findings |
| ez.mft | eztools | 236796 | blake2b:c72c2739... |
10 findings |
| registry.system | regripper | 416 | blake2b:ac48168a... |
6 findings |
| tsk.timeline | sleuthkit | 895935 | blake2b:cfec4b20... |
— |
| evtx.manifest | evtx-extract | 530 | blake2b:24c88435... |
— |
| registry.system | regripper | 128 | blake2b:962c680e... |
6 findings |
| bulk.email | bulk_extractor | 32275 | blake2b:7482b775... |
1 finding |
| bulk.ether | bulk_extractor | 33024 | blake2b:d5c052e7... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| bulk.httplogs | bulk_extractor | 11 | blake2b:3efea4cc... |
5 findings |
| bulk.ip | bulk_extractor | 35 | blake2b:b41fa333... |
— |
| bulk.packets | bulk_extractor | 162 | blake2b:36977342... |
— |
| bulk.rfc822 | bulk_extractor | 3852 | blake2b:a7107fc5... |
— |
| bulk.tcp | bulk_extractor | 15 | blake2b:20d9f3a2... |
— |
| bulk.url | bulk_extractor | 881789 | blake2b:8ade7620... |
— |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 75 | blake2b:a1fb63af... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 283 | blake2b:cd06251b... |
6 findings |
| registry.system | regripper | 283 | blake2b:d16cdfb5... |
6 findings |
| registry.system | regripper | 7606 | blake2b:20f6f6ae... |
6 findings |
| registry.system | regripper | 199 | blake2b:66848027... |
6 findings |
| bulk.url_facebook-address | bulk_extractor | 1858 | blake2b:702c2be7... |
— |
| bulk.url_searches | bulk_extractor | 14 | blake2b:d80de1ed... |
— |
| bulk.url_services | bulk_extractor | 22845 | blake2b:511d4800... |
— |
| registry.system | regripper | 41219 | blake2b:f52d805b... |
6 findings |
| registry.system | regripper | 199 | blake2b:e976fc92... |
6 findings |
| registry.system | regripper | 128 | blake2b:83d92a46... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 41219 | blake2b:8eea8bdf... |
6 findings |
| registry.system | regripper | 283 | blake2b:cd06251b... |
6 findings |
| registry.system | regripper | 283 | blake2b:f64043cb... |
6 findings |
| registry.system | regripper | 7606 | blake2b:94ce7482... |
6 findings |
| registry.system | regripper | 199 | blake2b:e976fc92... |
6 findings |
| registry.system | regripper | 199 | blake2b:66848027... |
6 findings |
| ez.mft | eztools | 150265 | blake2b:f14ef02a... |
10 findings |
| registry.system | regripper | 75 | blake2b:a1fb63af... |
6 findings |
| evtx.manifest | evtx-extract | 522 | blake2b:84552457... |
— |
| registry.system | regripper | 381 | blake2b:518e5438... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| chainsaw.hunt | chainsaw | 2 | blake2b:281919b7... |
— |
| evtx.windows_system32_winevt_logs_security | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| composite.persistence | composite | 5768 | blake2b:c08b905b... |
— |
| forensic.timestomping | timestomp_detector | 2 | blake2b:a14e1272... |
— |
| composite.persistence | composite | 5768 | blake2b:c08b905b... |
— |
| evtx.windows_system32_winevt_logs_security | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| evtx.windows_system32_winevt_logs_windows-powershell | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2822 | blake2b:13024986... |
9 findings |
| forensic.timestomping | timestomp_detector | 2 | blake2b:a14e1272... |
— |
| volatility.pslist | volatility3 | 130 | blake2b:4b07c368... |
5 findings |
| volatility.pstree | volatility3 | 130 | blake2b:2a892aed... |
12 findings |
| tsk.filelist | sleuthkit | 324108 | blake2b:766e8fb0... |
7 findings |
| volatility.cmdline | volatility3 | 130 | blake2b:7ea77b2a... |
13 findings |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| volatility.netscan | volatility3 | 130 | blake2b:a70bb8f7... |
25 findings |
| volatility.malfind | volatility3 | 8 | blake2b:2a7258b8... |
9 findings |
| volatility.psscan | volatility3 | 143 | blake2b:da8f63d7... |
12 findings |
| volatility.dlllist | volatility3 | 7122 | blake2b:0f623da1... |
4 findings |
| volatility.svcscan | volatility3 | 1324 | blake2b:2a307a65... |
— |
| tsk.filelist | sleuthkit | 318263 | blake2b:e1724920... |
7 findings |
| volatility.netscan | volatility3 | 131 | blake2b:63bead3b... |
25 findings |
| volatility.psscan | volatility3 | 139 | blake2b:39fce9af... |
12 findings |
| volatility.modscan | volatility3 | 286 | blake2b:f4af9511... |
— |
| bulk.domain | bulk_extractor | 1022097 | blake2b:ddf6e161... |
8 findings |
| bulk.email | bulk_extractor | 23492 | blake2b:6cc43a0d... |
1 finding |
| bulk.ether | bulk_extractor | 44489 | blake2b:d904371b... |
— |
| bulk.ip | bulk_extractor | 2357 | blake2b:73ca7c10... |
— |
| bulk.packets | bulk_extractor | 5654 | blake2b:dac41046... |
— |
| bulk.rfc822 | bulk_extractor | 16425 | blake2b:d92185db... |
— |
| bulk.tcp | bulk_extractor | 1169 | blake2b:6cbeeff2... |
— |
| bulk.url | bulk_extractor | 888145 | blake2b:89230a92... |
— |
| bulk.url_facebook-address | bulk_extractor | 27 | blake2b:c98beb41... |
— |
| bulk.url_facebook-id | bulk_extractor | 53 | blake2b:271ecc9f... |
— |
| bulk.url_searches | bulk_extractor | 206 | blake2b:952e7ba5... |
— |
| bulk.url_services | bulk_extractor | 5311 | blake2b:11e2a57f... |
— |
| chainsaw.hunt | chainsaw | 2 | blake2b:6b347e31... |
— |
| ez.amcache | eztools | 881 | blake2b:d30980e8... |
— |
| registry.sam | regripper | 205 | blake2b:b4cd789f... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.system | regripper | 75 | blake2b:1545fee0... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 283 | blake2b:77c52ba6... |
6 findings |
| registry.system | regripper | 283 | blake2b:99c57c1d... |
6 findings |
| registry.system | regripper | 8152 | blake2b:5689a1f4... |
6 findings |
| registry.system | regripper | 199 | blake2b:d3bd07a5... |
6 findings |
| evtx.manifest | evtx-extract | 853 | blake2b:aee4c47c... |
— |
| registry.system | regripper | 47350 | blake2b:55660a4c... |
6 findings |
| registry.system | regripper | 199 | blake2b:a0719339... |
6 findings |
| registry.sam | regripper | 205 | blake2b:7d48d9f1... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 47350 | blake2b:8fc42b11... |
6 findings |
| registry.system | regripper | 283 | blake2b:adc51ab1... |
6 findings |
| registry.system | regripper | 283 | blake2b:df437ac3... |
6 findings |
| registry.system | regripper | 8152 | blake2b:3eb69fc9... |
6 findings |
| registry.system | regripper | 199 | blake2b:a0719339... |
6 findings |
| registry.system | regripper | 199 | blake2b:d3bd07a5... |
6 findings |
| registry.system | regripper | 75 | blake2b:1545fee0... |
6 findings |
| registry.sam | regripper | 205 | blake2b:59967bbe... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.system | regripper | 75 | blake2b:1545fee0... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 453 | blake2b:918bae9f... |
6 findings |
| registry.system | regripper | 47350 | blake2b:e1bd5614... |
6 findings |
| registry.system | regripper | 283 | blake2b:af8a3590... |
6 findings |
| registry.system | regripper | 283 | blake2b:df437ac3... |
6 findings |
| registry.system | regripper | 8152 | blake2b:79ca9a91... |
6 findings |
| registry.system | regripper | 199 | blake2b:a0719339... |
6 findings |
| ez.mft | eztools | 303750 | blake2b:97571ad8... |
10 findings |
| registry.system | regripper | 199 | blake2b:d3bd07a5... |
6 findings |
| bulk.domain | bulk_extractor | 1045808 | blake2b:7e7b0cfe... |
8 findings |
| bulk.email | bulk_extractor | 35797 | blake2b:dcd00193... |
1 finding |
| bulk.ether | bulk_extractor | 2473 | blake2b:8a2e1ce0... |
— |
| bulk.httplogs | bulk_extractor | 7 | blake2b:95e32a7d... |
5 findings |
| bulk.ip | bulk_extractor | 1529 | blake2b:a2202681... |
— |
| bulk.packets | bulk_extractor | 9937 | blake2b:08c16172... |
— |
| bulk.rfc822 | bulk_extractor | 28799 | blake2b:99dd53ce... |
— |
| bulk.tcp | bulk_extractor | 758 | blake2b:96e8f070... |
— |
| bulk.url | bulk_extractor | 1134727 | blake2b:f41c8a2f... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| chainsaw.hunt | chainsaw | 2 | blake2b:dbe7d3a7... |
— |
| ez.mft | eztools | 303841 | blake2b:a3b55e76... |
10 findings |
| yara.files | yara | 35 | blake2b:af20e0cf... |
1 finding |
| evtx.manifest | evtx-extract | 846 | blake2b:418ab17e... |
— |
| registry.system | regripper | 204 | blake2b:3b63a953... |
6 findings |
| bulk.url_facebook-address | bulk_extractor | 27 | blake2b:0420b825... |
— |
| bulk.url_facebook-id | bulk_extractor | 16 | blake2b:fc7cb5f0... |
— |
| bulk.url_searches | bulk_extractor | 262 | blake2b:228eb8aa... |
— |
| bulk.url_services | bulk_extractor | 10131 | blake2b:5063290c... |
— |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 75 | blake2b:72184472... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 283 | blake2b:99eba833... |
6 findings |
| registry.system | regripper | 283 | blake2b:182b80d6... |
6 findings |
| registry.system | regripper | 7766 | blake2b:98c1908a... |
6 findings |
| registry.system | regripper | 199 | blake2b:d2f17585... |
6 findings |
| registry.system | regripper | 46189 | blake2b:7bcf55e2... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-taskscheduler4operational | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-terminalservices-localsessionmanager4operational | eztools | 136 | blake2b:a6701752... |
1 finding |
| registry.system | regripper | 199 | blake2b:3e017d72... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin | eztools | 2 | blake2b:a4a04fb8... |
— |
| registry.system | regripper | 438 | blake2b:e8fbdef3... |
6 findings |
| evtx.windows_system32_winevt_logs_system | eztools | 1310 | blake2b:3fb72c08... |
— |
| registry.system | regripper | 204 | blake2b:da002209... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 6584 | blake2b:6ce86725... |
9 findings |
| registry.system | regripper | 46189 | blake2b:495d9a32... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 7306 | blake2b:7ca6c55a... |
9 findings |
| registry.system | regripper | 283 | blake2b:b450fa64... |
6 findings |
| registry.system | regripper | 283 | blake2b:c7e28ab8... |
6 findings |
| registry.system | regripper | 7766 | blake2b:3f252fb5... |
6 findings |
| registry.system | regripper | 199 | blake2b:3e017d72... |
6 findings |
| registry.system | regripper | 199 | blake2b:d2f17585... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 7306 | blake2b:7ca6c55a... |
9 findings |
| registry.system | regripper | 75 | blake2b:72184472... |
6 findings |
| registry.system | regripper | 204 | blake2b:ca052d7a... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| yara.files | yara | 27 | blake2b:1bbb4e6c... |
1 finding |
| registry.system | regripper | 75 | blake2b:72184472... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 411 | blake2b:db3a86ce... |
6 findings |
| registry.system | regripper | 46189 | blake2b:42955550... |
6 findings |
| registry.system | regripper | 283 | blake2b:c3db5198... |
6 findings |
| registry.system | regripper | 283 | blake2b:6edd34fe... |
6 findings |
| registry.system | regripper | 7766 | blake2b:761f2427... |
6 findings |
| registry.system | regripper | 199 | blake2b:3e017d72... |
6 findings |
| registry.system | regripper | 199 | blake2b:d2f17585... |
6 findings |
| composite.suspicious_processes | composite | 142 | blake2b:5ddbd02e... |
— |
| volatility.cmdline | volatility3 | 164 | blake2b:46a775f3... |
13 findings |
| tsk.filelist | sleuthkit | 318752 | blake2b:63145ecc... |
7 findings |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| volatility.netscan | volatility3 | 149 | blake2b:35037597... |
25 findings |
| volatility.netscan | volatility3 | 140 | blake2b:6d1c9d08... |
25 findings |
| volatility.psscan | volatility3 | 132 | blake2b:715b3401... |
12 findings |
| volatility.psscan | volatility3 | 170 | blake2b:d7e00cb4... |
12 findings |
| tsk.filelist | sleuthkit | 186467 | blake2b:0e902a10... |
7 findings |
| volatility.netscan | volatility3 | 113 | blake2b:73d6af24... |
25 findings |
| volatility.svcscan | volatility3 | 1310 | blake2b:ba6f4dac... |
— |
| volatility.psscan | volatility3 | 97 | blake2b:9bbea4ab... |
12 findings |
| volatility.modscan | volatility3 | 257 | blake2b:87857bfc... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| bulk.domain | bulk_extractor | 754889 | blake2b:0ce83aed... |
8 findings |
| volatility.modscan | volatility3 | 169 | blake2b:648bc1d6... |
— |
| bulk.email | bulk_extractor | 12487 | blake2b:f73512de... |
1 finding |
| bulk.ether | bulk_extractor | 3638 | blake2b:c08527b0... |
— |
| bulk.httplogs | bulk_extractor | 60 | blake2b:928d66b1... |
5 findings |
| bulk.ip | bulk_extractor | 3573 | blake2b:abb904db... |
— |
| bulk.packets | bulk_extractor | 5650 | blake2b:23052f40... |
— |
| bulk.rfc822 | bulk_extractor | 26959 | blake2b:9d857c0c... |
— |
| bulk.tcp | bulk_extractor | 1777 | blake2b:3b63f7cf... |
— |
| bulk.url | bulk_extractor | 947653 | blake2b:17250be0... |
— |
| bulk.url_facebook-address | bulk_extractor | 47 | blake2b:50457483... |
— |
| bulk.url_facebook-id | bulk_extractor | 21 | blake2b:e81cbf6c... |
— |
| bulk.url_searches | bulk_extractor | 172 | blake2b:86c34ed1... |
— |
| bulk.url_services | bulk_extractor | 10040 | blake2b:a0ce4fce... |
— |
| chainsaw.hunt | chainsaw | 2 | blake2b:f7106a96... |
— |
| ez.mft | eztools | 301603 | blake2b:d23d0d5b... |
10 findings |
| evtx.manifest | evtx-extract | 1147 | blake2b:7f785e4e... |
— |
| registry.sam | regripper | 206 | blake2b:a5d57544... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.security | regripper | 75 | blake2b:4f10a278... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.software | regripper | 47526 | blake2b:9c4ce7e6... |
— |
| registry.software | regripper | 283 | blake2b:3ccb45b5... |
— |
| registry.software | regripper | 283 | blake2b:583eaefd... |
— |
| registry.system | regripper | 7496 | blake2b:c3774b12... |
6 findings |
| registry.system | regripper | 199 | blake2b:8977f42c... |
6 findings |
| registry.system | regripper | 199 | blake2b:aa53bf0a... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| registry.default | regripper | 461 | blake2b:f490c13a... |
— |
| registry.sam | regripper | 206 | blake2b:b15004b8... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.security | regripper | 75 | blake2b:4f10a278... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.software | regripper | 283 | blake2b:74a3df51... |
— |
| registry.software | regripper | 283 | blake2b:75099375... |
— |
| registry.system | regripper | 7496 | blake2b:6100209e... |
6 findings |
| registry.system | regripper | 199 | blake2b:aa53bf0a... |
6 findings |
| registry.software | regripper | 47526 | blake2b:c3c4c550... |
— |
| registry.system | regripper | 199 | blake2b:8977f42c... |
6 findings |
| registry.default | regripper | 461 | blake2b:f490c13a... |
— |
| registry.sam | regripper | 206 | blake2b:012419a7... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| registry.software | regripper | 47526 | blake2b:c0b8da2c... |
— |
| registry.software | regripper | 283 | blake2b:277591f7... |
— |
| registry.software | regripper | 283 | blake2b:ab173c9e... |
— |
| registry.system | regripper | 7496 | blake2b:052cdd00... |
6 findings |
| bulk.domain | bulk_extractor | 1343401 | blake2b:6d6051fd... |
8 findings |
| registry.system | regripper | 199 | blake2b:8977f42c... |
6 findings |
| registry.system | regripper | 199 | blake2b:aa53bf0a... |
6 findings |
| registry.security | regripper | 75 | blake2b:4f10a278... |
— |
| registry.sam | regripper | 206 | blake2b:86beba80... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| registry.sam | regripper | 7 | blake2b:e4c6f012... |
— |
| bulk.email | bulk_extractor | 15775 | blake2b:9081f60c... |
1 finding |
| registry.security | regripper | 75 | blake2b:4f10a278... |
— |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| bulk.ether | bulk_extractor | 2775 | blake2b:81bfa0c0... |
— |
| bulk.httplogs | bulk_extractor | 55 | blake2b:ae5a38a8... |
5 findings |
| registry.security | regripper | 8 | blake2b:3c5e87f4... |
— |
| bulk.ip | bulk_extractor | 395 | blake2b:de8ccf66... |
— |
| bulk.packets | bulk_extractor | 2867 | blake2b:948278c7... |
— |
| bulk.rfc822 | bulk_extractor | 29201 | blake2b:5b0d4901... |
— |
| bulk.tcp | bulk_extractor | 198 | blake2b:5421db0a... |
— |
| bulk.url | bulk_extractor | 1100611 | blake2b:cf8df8b1... |
— |
| registry.software | regripper | 47526 | blake2b:46d8fa60... |
— |
| registry.software | regripper | 283 | blake2b:665cc4f2... |
— |
| registry.software | regripper | 283 | blake2b:64da67d2... |
— |
| registry.system | regripper | 7496 | blake2b:ab1be7a5... |
6 findings |
| registry.system | regripper | 199 | blake2b:8977f42c... |
6 findings |
| registry.system | regripper | 199 | blake2b:aa53bf0a... |
6 findings |
| bulk.url_facebook-address | bulk_extractor | 17 | blake2b:1363b2d4... |
— |
| bulk.url_facebook-id | bulk_extractor | 21 | blake2b:1526c1a0... |
— |
| bulk.url_searches | bulk_extractor | 177 | blake2b:343464ff... |
— |
| bulk.url_services | bulk_extractor | 7342 | blake2b:4d28d7b0... |
— |
| chainsaw.hunt | chainsaw | 2 | blake2b:f7106a96... |
— |
| ez.mft | eztools | 170131 | blake2b:c44ae450... |
10 findings |
| evtx.manifest | evtx-extract | 1086 | blake2b:724fc04a... |
— |
| registry.system | regripper | 7 | blake2b:e4c6f012... |
6 findings |
| registry.system | regripper | 8 | blake2b:3c5e87f4... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-smbserver4security | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-fileservices-servermanager-eventprovider4admin | eztools | 2 | blake2b:a4a04fb8... |
— |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2 | blake2b:a4a04fb8... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2 | blake2b:a4a04fb8... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-powershell4operational | eztools | 2 | blake2b:a4a04fb8... |
9 findings |
| evtx.windows_system32_winevt_logs_microsoft-windows-sysmon4operational | eztools | 2 | blake2b:a4a04fb8... |
— |
| composite.suspicious_processes | composite | 242 | blake2b:a76fb9c2... |
— |
| composite.suspicious_processes | composite | 242 | blake2b:a76fb9c2... |
— |
| tsk.filelist | sleuthkit | 298456 | blake2b:edcd0278... |
7 findings |
| bulk.domain | bulk_extractor | 2049009 | blake2b:bb089b69... |
8 findings |
| bulk.email | bulk_extractor | 12143 | blake2b:2a700bce... |
1 finding |
| bulk.ether | bulk_extractor | 28881 | blake2b:14fcb108... |
— |
| bulk.httplogs | bulk_extractor | 40 | blake2b:4d7aa640... |
5 findings |
| bulk.ip | bulk_extractor | 51 | blake2b:621165ac... |
— |
| bulk.packets | bulk_extractor | 156 | blake2b:706a51a9... |
— |
| bulk.rfc822 | bulk_extractor | 1972 | blake2b:f991205c... |
— |
| bulk.tcp | bulk_extractor | 22 | blake2b:296fbe5b... |
— |
| bulk.url | bulk_extractor | 934664 | blake2b:578f4b68... |
— |
| bulk.url_facebook-address | bulk_extractor | 6 | blake2b:87861f76... |
— |
| bulk.url_searches | bulk_extractor | 14 | blake2b:222b33cc... |
— |
| bulk.url_services | bulk_extractor | 2922 | blake2b:9138842e... |
— |
| ez.mft | eztools | 283801 | blake2b:bac30d71... |
10 findings |
| volatility.pslist | volatility3 | 233 | blake2b:2645759b... |
5 findings |
| volatility.pslist | volatility3 | 111 | blake2b:155c4124... |
5 findings |
| volatility.pstree | volatility3 | 111 | blake2b:2f53a7cc... |
12 findings |
| volatility.pstree | volatility3 | 233 | blake2b:c11e5cdd... |
12 findings |
| volatility.cmdline | volatility3 | 111 | blake2b:712e7412... |
13 findings |
| evtx.manifest | evtx-extract | 1281 | blake2b:1d036de1... |
— |
| volatility.cmdline | volatility3 | 233 | blake2b:3d8af26e... |
13 findings |
| registry.system | regripper | 381 | blake2b:518e5438... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| registry.system | regripper | 381 | blake2b:518e5438... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| registry.system | regripper | 255 | blake2b:0d77cf74... |
6 findings |
| volatility.netscan | volatility3 | 206 | blake2b:6b8964d1... |
25 findings |
| volatility.netscan | volatility3 | 127 | blake2b:7315125b... |
25 findings |
| volatility.malfind | volatility3 | 43 | blake2b:9a251476... |
9 findings |
| chainsaw.hunt | chainsaw | 2 | blake2b:e0a65ed1... |
— |
| volatility.netscan | volatility3 | 154 | blake2b:2f43aa1d... |
25 findings |
| volatility.psscan | volatility3 | 115 | blake2b:00dc1052... |
12 findings |
| volatility.dlllist | volatility3 | 5586 | blake2b:cbe3d803... |
4 findings |
| volatility.psscan | volatility3 | 98 | blake2b:cf1caac5... |
12 findings |
| volatility.svcscan | volatility3 | 913 | blake2b:77edf96c... |
— |
| volatility.netscan | volatility3 | 171 | blake2b:33f98d24... |
25 findings |
| forensic.timestomping | timestomp_detector | 7 | blake2b:6f80f559... |
— |
| volatility.malfind | volatility3 | 31 | blake2b:8e4dd810... |
9 findings |
| volatility.psscan | volatility3 | 92 | blake2b:d351d701... |
12 findings |
| volatility.modscan | volatility3 | 229 | blake2b:75f99d42... |
— |
| binary.triage | rabin2 | 30 | blake2b:bcc741fe... |
— |
| volatility.psscan | volatility3 | 245 | blake2b:b23af332... |
12 findings |
| volatility.dlllist | volatility3 | 9419 | blake2b:cb55e58d... |
4 findings |
| volatility.svcscan | volatility3 | 1286 | blake2b:b07bdef9... |
— |
| volatility.modscan | volatility3 | 248 | blake2b:bf5f18d4... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| volatility.pslist | volatility3 | 118 | blake2b:d934d1a0... |
5 findings |
| volatility.pslist | volatility3 | 154 | blake2b:89fa6a52... |
5 findings |
| volatility.pslist | volatility3 | 67 | blake2b:98c3b901... |
5 findings |
| volatility.pslist | volatility3 | 135 | blake2b:7fb6bbc7... |
5 findings |
| volatility.pstree | volatility3 | 67 | blake2b:ba272194... |
12 findings |
| volatility.pstree | volatility3 | 118 | blake2b:fbdfc669... |
12 findings |
| volatility.pstree | volatility3 | 154 | blake2b:1b049bf4... |
12 findings |
| volatility.pstree | volatility3 | 135 | blake2b:a297ca8c... |
12 findings |
| volatility.cmdline | volatility3 | 67 | blake2b:8f0d1d12... |
13 findings |
| volatility.cmdline | volatility3 | 135 | blake2b:5fa78570... |
13 findings |
| volatility.cmdline | volatility3 | 154 | blake2b:becf274a... |
13 findings |
| volatility.cmdline | volatility3 | 118 | blake2b:c51f4930... |
13 findings |
| volatility.netscan | volatility3 | 129 | blake2b:6957d1b7... |
25 findings |
| volatility.malfind | volatility3 | 27 | blake2b:c11f2eb4... |
9 findings |
| volatility.psscan | volatility3 | 98 | blake2b:2c163c46... |
12 findings |
| volatility.dlllist | volatility3 | 3647 | blake2b:a0fbbf49... |
4 findings |
| volatility.svcscan | volatility3 | 916 | blake2b:1cf52994... |
— |
| volatility.netscan | volatility3 | 1017 | blake2b:2aced46a... |
25 findings |
| volatility.netscan | volatility3 | 138 | blake2b:08c45b22... |
25 findings |
| volatility.netscan | volatility3 | 250 | blake2b:efa8afac... |
25 findings |
| volatility.malfind | volatility3 | 4 | blake2b:f4ea7371... |
9 findings |
| volatility.malfind | volatility3 | 17 | blake2b:37d567a2... |
9 findings |
| volatility.malfind | volatility3 | 313 | blake2b:0444dc6f... |
9 findings |
| volatility.psscan | volatility3 | 132 | blake2b:91e525a7... |
12 findings |
| volatility.dlllist | volatility3 | 7051 | blake2b:1f73727f... |
4 findings |
| volatility.psscan | volatility3 | 202 | blake2b:ac687953... |
12 findings |
| volatility.psscan | volatility3 | 139 | blake2b:bdf1e97a... |
12 findings |
| volatility.dlllist | volatility3 | 6116 | blake2b:7ebccf44... |
4 findings |
| volatility.svcscan | volatility3 | 1336 | blake2b:cf6ec1b0... |
— |
| volatility.svcscan | volatility3 | 1290 | blake2b:f337f9db... |
— |
| volatility.dlllist | volatility3 | 15349 | blake2b:151b3641... |
4 findings |
| volatility.svcscan | volatility3 | 1364 | blake2b:4c8cb470... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| volatility.pslist | volatility3 | 59 | blake2b:2fd2499f... |
5 findings |
| volatility.pstree | volatility3 | 59 | blake2b:1e40bd20... |
12 findings |
| volatility.cmdline | volatility3 | 59 | blake2b:5ae17d2d... |
13 findings |
| volatility.netscan | volatility3 | 112 | blake2b:0bfe276f... |
25 findings |
| volatility.netscan | volatility3 | 280 | blake2b:dc129b3c... |
25 findings |
| volatility.malfind | volatility3 | 4 | blake2b:52ef31a6... |
9 findings |
| volatility.psscan | volatility3 | 67 | blake2b:0b10e60c... |
12 findings |
| volatility.dlllist | volatility3 | 3176 | blake2b:2cd76fac... |
4 findings |
| volatility.psscan | volatility3 | 92 | blake2b:e0f38056... |
12 findings |
| volatility.svcscan | volatility3 | 913 | blake2b:7c2d1cb2... |
— |
| volatility.netscan | volatility3 | 120 | blake2b:616c3ccf... |
25 findings |
| volatility.modscan | volatility3 | 149 | blake2b:e5c0dbf1... |
— |
| volatility.psscan | volatility3 | 129 | blake2b:d531035a... |
12 findings |
| volatility.psscan | volatility3 | 155 | blake2b:c943e0f0... |
12 findings |
| volatility.pslist | volatility3 | 77 | blake2b:0713186c... |
5 findings |
| volatility.pstree | volatility3 | 77 | blake2b:b5407860... |
12 findings |
| volatility.cmdline | volatility3 | 77 | blake2b:d5fb83ee... |
13 findings |
| volatility.netscan | volatility3 | 134 | blake2b:efafec82... |
25 findings |
| volatility.psscan | volatility3 | 79 | blake2b:aee3e6bf... |
12 findings |
| volatility.modscan | volatility3 | 255 | blake2b:4468f27a... |
— |
| volatility.modscan | volatility3 | 255 | blake2b:61aa9578... |
— |
| volatility.modscan | volatility3 | 162 | blake2b:363a5a60... |
— |
| volatility.netscan | volatility3 | 132 | blake2b:2ac0a43c... |
25 findings |
| volatility.malfind | volatility3 | 12 | blake2b:4391a57d... |
9 findings |
| volatility.psscan | volatility3 | 85 | blake2b:3adb059b... |
12 findings |
| volatility.dlllist | volatility3 | 3934 | blake2b:b58fc03a... |
4 findings |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| volatility.svcscan | volatility3 | 1286 | blake2b:28b2e791... |
— |
| composite.suspicious_processes | composite | 1585 | blake2b:67146af5... |
— |
| yara.memory | yara | 9206 | blake2b:f475b9fd... |
3 findings |
| composite.correlation | composite | 1 | blake2b:ccbe0b82... |
— |
| composite.correlation | composite | 1 | blake2b:f77109d9... |
— |
| composite.correlation | composite | 1 | blake2b:b462e39c... |
— |
| composite.correlation | composite | 1 | blake2b:e094365f... |
— |
| composite.correlation | composite | 1 | blake2b:f0e571f1... |
— |
| composite.persistence | composite | 37508 | blake2b:e69d7f75... |
— |
| composite.exfil | composite | 467160 | blake2b:6bf3d9f3... |
— |
| composite.exfil | composite | 467160 | blake2b:6bf3d9f3... |
— |
| composite.defense_evasion | composite | 277 | blake2b:a90e661d... |
— |
| composite.suspicious_processes | composite | 1585 | blake2b:67146af5... |
— |
| composite.execution | composite | 558 | blake2b:cbc462e6... |
— |
| composite.timeline | composite | 418 | blake2b:5ffdc2cb... |
— |
| composite.file_staging | composite | 32672 | blake2b:afe37fd0... |
— |
| composite.exfil | composite | 467160 | blake2b:6bf3d9f3... |
— |
| composite.recovery | composite | 7 | blake2b:c5fcd372... |
— |
| composite.correlation | composite | 1 | blake2b:01c33aa5... |
— |
| composite.correlation | composite | 1 | blake2b:c9353f0f... |
— |
| composite.correlation | composite | 1 | blake2b:cac63622... |
— |
Investigation Performance
| Input Tokens | 159,989 |
| Output Tokens | 538,377 |
| Total Tokens | 698,366 |
| Per-Model Breakdown | |
| claude-haiku-4-5@20251001 | 1,678 |
| claude-opus-4-6 | 696,688 |
| Model | Input | Output | Total | Share |
|---|---|---|---|---|
| claude-haiku-4-5@20251001 | 34 | 1,644 | 1,678 | 0% |
| claude-opus-4-6 | 159,955 | 536,733 | 696,688 | 99% |
Audit Trail
| ID | Tool | Duration | Timestamp | Actions |
|---|---|---|---|---|
| tc_c4910a21 | scan_evidence | 164829ms | 2026-06-06T06:19:22 | |
| tc_54036483 | extract_archive | 5ms | 2026-06-06T06:19:38 | |
| tc_56a0812b | extract_archive | 4ms | 2026-06-06T06:19:38 | |
| tc_55e920e9 | extract_archive | 5ms | 2026-06-06T06:19:38 | |
| tc_903f3ab8 | extract_archive | 8ms | 2026-06-06T06:19:38 | |
| tc_759371d2 | extract_archive | 2ms | 2026-06-06T06:19:38 | |
| tc_a06c0128 | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_9a6bb776 | start_extraction_batch | 10ms | 2026-06-06T06:19:38 | |
| tc_ff45b070 | extract_archive | 2ms | 2026-06-06T06:19:38 | |
| tc_b7c2a225 | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_4692938f | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_75e8324d | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_bc1abeac | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_b7ad57de | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_1c68bb4c | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_011fb101 | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_9a75d6ae | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_3de9b9e3 | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_ef86902e | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_9f994a54 | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_c63723ab | extract_archive | 0ms | 2026-06-06T06:19:38 | |
| tc_49dbff40 | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_4016f0e6 | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_184972fb | extract_archive | 1ms | 2026-06-06T06:19:38 | |
| tc_b9a74ed0 | list_directory | 16ms | 2026-06-06T06:19:53 | |
| tc_efd2fb79 | start_extraction_batch | 3ms | 2026-06-06T06:20:10 | |
| tc_15b549e1 | extract_archive | 45790ms | 2026-06-06T06:20:56 | |
| tc_6f8b059f | extract_archive | 90799ms | 2026-06-06T06:21:41 | |
| tc_77aab7b3 | extract_archive | 145963ms | 2026-06-06T06:22:36 | |
| tc_d96bf91b | extract_archive | 154003ms | 2026-06-06T06:22:44 | |
| tc_479b5e6e | extract_archive | 163726ms | 2026-06-06T06:22:54 | |
| tc_b01c1d15 | extract_archive | 165832ms | 2026-06-06T06:22:56 | |
| tc_1b7e83b8 | extract_archive | 130902ms | 2026-06-06T06:23:07 | |
| tc_71c1fa45 | extract_archive | 110857ms | 2026-06-06T06:23:32 | |
| tc_116d4733 | extract_archive | 61004ms | 2026-06-06T06:23:45 | |
| tc_a93ba578 | extract_archive | 70157ms | 2026-06-06T06:24:04 | |
| tc_c997b34d | extract_archive | 93486ms | 2026-06-06T06:24:10 | |
| tc_f2bc8c24 | extract_archive | 84845ms | 2026-06-06T06:24:21 | |
| tc_cbbcaef1 | extract_archive | 276641ms | 2026-06-06T06:24:47 | |
| tc_9f37abc4 | extract_archive | 82874ms | 2026-06-06T06:24:55 | |
| tc_b2793ec3 | extract_archive | 88073ms | 2026-06-06T06:25:13 | |
| tc_fc5c9daa | extract_archive | 138688ms | 2026-06-06T06:25:26 | |
| tc_a00763a5 | extract_archive | 77316ms | 2026-06-06T06:25:27 | |
| tc_74f5756b | extract_archive | 83532ms | 2026-06-06T06:25:28 | |
| tc_338c4860 | extract_archive | 78433ms | 2026-06-06T06:25:39 | |
| tc_e8c451b8 | extract_archive | 47126ms | 2026-06-06T06:25:42 | |
| tc_04ba7b51 | extract_archive | 58689ms | 2026-06-06T06:25:46 | |
| tc_f2dac528 | extract_archive | 360956ms | 2026-06-06T06:26:11 | |
| tc_7f561869 | get_completed_results | 0ms | 2026-06-06T06:26:18 | |
| tc_6cfe5147 | list_sources | 11ms | 2026-06-06T06:26:18 | |
| tc_1d522a3b | get_source_stats | 8ms | 2026-06-06T06:26:40 | |
| tc_aa3ba350 | scan_evidence | 46ms | 2026-06-06T06:27:31 | |
| tc_2e26f5ff | open_case | 14ms | 2026-06-06T06:27:43 | |
| tc_869844cb | scan_evidence | 43ms | 2026-06-06T06:27:59 | |
| tc_42cada6e | open_case | 14ms | 2026-06-06T06:28:06 | |
| tc_831d6827 | open_case | 14ms | 2026-06-06T06:28:33 | |
| tc_d024e222 | start_extraction_batch | 17ms | 2026-06-06T06:28:43 | |
| tc_c918de37 | run_mmls | 0ms | 2026-06-06T06:28:43 | |
| tc_fdd97a56 | yara_scan_memory | 114ms | 2026-06-06T06:28:43 | |
| tc_df7e7c41 | run_fls | 66246ms | 2026-06-06T06:29:49 | |
| tc_84af7e1e | run_volatility_batch | 599876ms | 2026-06-06T06:38:43 | |
| tc_51a0a4e7 | open_case | 47ms | 2026-06-06T06:38:57 | |
| tc_612ed1c9 | start_extraction_batch | 15ms | 2026-06-06T06:40:08 | |
| tc_2d7e3668 | run_mmls | 0ms | 2026-06-06T06:40:13 | |
| tc_b9b9d476 | run_fls | 78194ms | 2026-06-06T06:41:26 | |
| tc_12cc4415 | run_bulk_extractor | 1113578ms | 2026-06-06T06:47:16 | |
| tc_38824169 | run_volatility_batch | 644873ms | 2026-06-06T06:50:53 | |
| tc_08d052bf | run_volatility_batch | 647977ms | 2026-06-06T06:51:01 | |
| tc_a7fdec67 | get_completed_results | 0ms | 2026-06-06T06:51:14 | |
| tc_7eca21a7 | start_extraction_batch | 44ms | 2026-06-06T06:51:25 | |
| tc_622f5fa1 | run_chainsaw | 59ms | 2026-06-06T06:51:25 | |
| tc_25ef9b73 | run_hayabusa | 122ms | 2026-06-06T06:51:30 | |
| tc_c52851b0 | run_amcache_parser | 6170ms | 2026-06-06T06:51:31 | |
| tc_12289789 | run_prefetch_parser | 4650ms | 2026-06-06T06:51:34 | |
| tc_2aea2c96 | run_shimcache_parser | 42658ms | 2026-06-06T06:52:12 | |
| tc_f23e3af7 | run_evtx_parser | 122064ms | 2026-06-06T06:53:27 | |
| tc_33fdf72a | run_mft_parser | 144670ms | 2026-06-06T06:53:49 | |
| tc_095fc50a | yara_scan_memory | 139947ms | 2026-06-06T06:53:50 | |
| tc_d742062b | yara_scan_files | 162974ms | 2026-06-06T06:54:13 | |
| tc_efc72383 | run_mactime | 199315ms | 2026-06-06T06:54:50 | |
| tc_4bc77756 | run_bulk_extractor | 905793ms | 2026-06-06T06:55:19 | |
| tc_a9c26a8d | get_completed_results | 0ms | 2026-06-06T06:55:24 | |
| tc_de036d4a | start_extraction_batch | 35ms | 2026-06-06T06:55:32 | |
| tc_644ee896 | run_amcache_parser | 20023ms | 2026-06-06T06:55:52 | |
| tc_967f6cd7 | run_prefetch_parser | 20904ms | 2026-06-06T06:55:53 | |
| tc_9ba64aa2 | run_registry_parser | 274101ms | 2026-06-06T06:56:04 | |
| tc_2493c6cf | run_mft_parser | 35274ms | 2026-06-06T06:56:07 | |
| tc_07dfd450 | get_completed_results | 0ms | 2026-06-06T06:56:09 | |
| tc_4be32638 | run_shimcache_parser | 41685ms | 2026-06-06T06:56:14 | |
| tc_96b05e4e | start_extraction_batch | 2ms | 2026-06-06T06:56:14 | |
| tc_f84b9100 | run_prefetch_parser | 3665ms | 2026-06-06T06:56:18 | |
| tc_9bd2c4de | run_evtx_parser | 59436ms | 2026-06-06T06:56:32 | |
| tc_ecad047f | run_shimcache_parser | 25387ms | 2026-06-06T06:56:40 | |
| tc_c78a8b72 | run_registry_parser | 83210ms | 2026-06-06T06:56:55 | |
| tc_e2750a0b | open_case | 26ms | 2026-06-06T06:57:03 | |
| tc_0c120b66 | wait_all | 0ms | 2026-06-06T06:57:08 | |
| tc_d62ddf63 | open_case | 6ms | 2026-06-06T06:57:32 | |
| tc_d9874c14 | yara_scan_memory | 120004ms | 2026-06-06T06:57:32 | |
| tc_3018d820 | get_investigation_summary | 14ms | 2026-06-06T06:57:36 | |
| tc_aa45124a | get_completed_results | 0ms | 2026-06-06T06:57:38 | |
| tc_3782567c | start_extraction_batch | 2ms | 2026-06-06T06:57:44 | |
| tc_ce238c87 | get_source_stats | 9599ms | 2026-06-06T06:57:45 | |
| tc_1188a5e7 | run_amcache_parser | 2920ms | 2026-06-06T06:57:47 | |
| tc_8c57f05f | run_prefetch_parser | 3478ms | 2026-06-06T06:57:47 | |
| tc_d62ac10c | get_process_tree | 5ms | 2026-06-06T06:57:55 | |
| tc_f99e5054 | list_processes_from_memory | 3ms | 2026-06-06T06:57:55 | |
| tc_5449cb1b | get_raw_output | 9026ms | 2026-06-06T06:58:05 | |
| tc_9a9c872a | run_shimcache_parser | 24287ms | 2026-06-06T06:58:08 | |
| tc_383a719e | get_raw_output | 6921ms | 2026-06-06T06:58:12 | |
| tc_33fa3e8f | start_extraction_batch | 15ms | 2026-06-06T06:58:15 | |
| tc_5c3d5c75 | run_hayabusa | 18ms | 2026-06-06T06:58:15 | |
| tc_ffd7f758 | run_chainsaw | 40ms | 2026-06-06T06:58:15 | |
| tc_8bf36a1e | get_completed_results | 0ms | 2026-06-06T06:58:23 | |
| tc_26580fc9 | get_raw_output | 9083ms | 2026-06-06T06:58:24 | |
| tc_5c617e91 | open_case | 32ms | 2026-06-06T06:58:47 | |
| tc_3e0b64d1 | wait_all | 0ms | 2026-06-06T06:58:53 | |
| tc_ce81377a | get_raw_output | 9145ms | 2026-06-06T06:58:54 | |
| tc_5f05ef36 | get_raw_output | 9062ms | 2026-06-06T06:59:03 | |
| tc_c8d6c6ae | get_raw_output | 9037ms | 2026-06-06T06:59:12 | |
| tc_ce96bc23 | open_case | 18ms | 2026-06-06T06:59:15 | |
| tc_731b09fd | get_investigation_summary | 20ms | 2026-06-06T06:59:20 | |
| tc_dee3a6a2 | list_sources | 6ms | 2026-06-06T06:59:20 | |
| tc_24110a42 | get_raw_output | 11207ms | 2026-06-06T06:59:24 | |
| tc_a504c8d6 | search | 275ms | 2026-06-06T06:59:26 | |
| tc_0ee445b8 | get_source_stats | 11327ms | 2026-06-06T06:59:31 | |
| tc_066c0c53 | get_process_tree | 6ms | 2026-06-06T06:59:42 | |
| tc_1ccba11a | find_suspicious_processes._query(volatility.malfind) | 230ms | 2026-06-06T06:59:42 | |
| tc_485bc27f | find_suspicious_processes._query(volatility.cmdline) | 95ms | 2026-06-06T06:59:42 | |
| tc_1febf15a | find_suspicious_processes._query(volatility.netscan) | 90ms | 2026-06-06T06:59:42 | |
| tc_32315682 | find_suspicious_processes._query(volatility.pstree) | 97ms | 2026-06-06T06:59:42 | |
| tc_351fca78 | find_suspicious_processes._query(volatility.psscan) | 94ms | 2026-06-06T06:59:42 | |
| tc_69112dee | find_suspicious_processes._query(volatility.pslist) | 91ms | 2026-06-06T06:59:42 | |
| tc_7822e3e0 | find_suspicious_processes | 701ms | 2026-06-06T06:59:42 | |
| tc_dbd40ca6 | search | 29ms | 2026-06-06T06:59:43 | |
| tc_be132a92 | search | 23ms | 2026-06-06T06:59:43 | |
| tc_6f9991c9 | search | 1042ms | 2026-06-06T06:59:55 | |
| tc_2c193200 | search | 67ms | 2026-06-06T06:59:55 | |
| tc_db8b2247 | search | 56ms | 2026-06-06T06:59:55 | |
| tc_f5909f44 | search | 33ms | 2026-06-06T06:59:55 | |
| tc_d4f16b49 | get_raw_output | 8946ms | 2026-06-06T07:00:02 | |
| tc_dbe921be | get_raw_output | 8838ms | 2026-06-06T07:00:11 | |
| tc_157acb25 | get_raw_output | 6680ms | 2026-06-06T07:00:18 | |
| tc_96d71730 | get_raw_output | 9270ms | 2026-06-06T07:00:29 | |
| tc_8bd00bf1 | get_raw_output | 9382ms | 2026-06-06T07:00:39 | |
| tc_1df9b5ca | index_evtx_file | 23803ms | 2026-06-06T07:00:40 | |
| tc_03e34a3f | search | 33ms | 2026-06-06T07:00:40 | |
| tc_f38b5b31 | search | 1189ms | 2026-06-06T07:00:42 | |
| tc_01419099 | find_persistence_mechanisms._query(registry.system) | 379ms | 2026-06-06T07:00:42 | |
| tc_45af65fd | find_persistence_mechanisms._query(registry.software) | 96ms | 2026-06-06T07:00:42 | |
| tc_068ad67e | find_persistence_mechanisms._query(volatility.svcscan) | 90ms | 2026-06-06T07:00:42 | |
| tc_78405528 | find_persistence_mechanisms._search(all) | 32ms | 2026-06-06T07:00:42 | |
| tc_0693ff51 | find_persistence_mechanisms._search(all) | 24ms | 2026-06-06T07:00:42 | |
| tc_8a86fd62 | find_persistence_mechanisms._query(ez.amcache) | 98ms | 2026-06-06T07:00:42 | |
| tc_7a22b531 | find_persistence_mechanisms._search(all) | 29ms | 2026-06-06T07:00:42 | |
| tc_0dbdff21 | find_persistence_mechanisms._query(tsk.filelist) | 259ms | 2026-06-06T07:00:43 | |
| tc_3adfda9e | find_persistence_mechanisms | 1083ms | 2026-06-06T07:00:43 | |
| tc_9a940650 | search | 69ms | 2026-06-06T07:01:03 | |
| tc_7fedefbb | search | 1754ms | 2026-06-06T07:01:06 | |
| tc_2c56204c | search | 68ms | 2026-06-06T07:01:06 | |
| tc_61e163bd | get_raw_output | 11258ms | 2026-06-06T07:01:10 | |
| tc_6d56b84a | search | 1959ms | 2026-06-06T07:01:12 | |
| tc_0a2d549e | search | 173ms | 2026-06-06T07:01:12 | |
| tc_f4cb513a | search | 49ms | 2026-06-06T07:01:12 | |
| tc_42fee88d | get_raw_output | 11675ms | 2026-06-06T07:01:17 | |
| tc_03e40ce0 | search | 90ms | 2026-06-06T07:01:39 | |
| tc_5e2b911e | search | 86ms | 2026-06-06T07:01:40 | |
| tc_430ba9c3 | search | 146ms | 2026-06-06T07:01:41 | |
| tc_3b14a8b3 | search | 19ms | 2026-06-06T07:01:41 | |
| tc_7668da1f | search | 194ms | 2026-06-06T07:01:42 | |
| tc_233bc7a9 | search | 1006ms | 2026-06-06T07:01:42 | |
| tc_53223348 | search | 54ms | 2026-06-06T07:01:42 | |
| tc_174eda4c | search | 438ms | 2026-06-06T07:01:43 | |
| tc_0e91e644 | detect_timestomping | 1761ms | 2026-06-06T07:01:45 | |
| tc_6ce6a9f9 | get_raw_output | 8151ms | 2026-06-06T07:02:07 | |
| tc_7b489cf1 | search | 33ms | 2026-06-06T07:02:07 | |
| tc_5cf3818c | search | 23ms | 2026-06-06T07:02:07 | |
| tc_71623731 | find_persistence_mechanisms._query(registry.system) | 291ms | 2026-06-06T07:02:07 | |
| tc_2d9ff6c4 | find_persistence_mechanisms._query(registry.software) | 92ms | 2026-06-06T07:02:07 | |
| tc_cce5b8f7 | find_persistence_mechanisms._query(volatility.svcscan) | 90ms | 2026-06-06T07:02:07 | |
| tc_2d539659 | find_persistence_mechanisms._search(all) | 33ms | 2026-06-06T07:02:07 | |
| tc_189b4519 | find_persistence_mechanisms._search(all) | 26ms | 2026-06-06T07:02:07 | |
| tc_a4ed0d4c | find_persistence_mechanisms._query(ez.amcache) | 94ms | 2026-06-06T07:02:07 | |
| tc_ad38f677 | find_persistence_mechanisms._search(all) | 37ms | 2026-06-06T07:02:07 | |
| tc_bc0123ed | find_persistence_mechanisms._query(tsk.filelist) | 250ms | 2026-06-06T07:02:08 | |
| tc_654af30c | find_persistence_mechanisms | 994ms | 2026-06-06T07:02:08 | |
| tc_b9e0603a | submit_finding | 16ms | 2026-06-06T07:02:17 | |
| tc_0d956c30 | search | 24ms | 2026-06-06T07:02:26 | |
| tc_c89cd899 | search | 82ms | 2026-06-06T07:02:27 | |
| tc_1772186a | submit_finding | 13ms | 2026-06-06T07:02:36 | |
| tc_3f7c0a29 | index_evtx_file | 12284ms | 2026-06-06T07:02:42 | |
| tc_2fb9bdc4 | index_evtx_file | 372ms | 2026-06-06T07:02:42 | |
| tc_3d0707d9 | submit_finding | 19ms | 2026-06-06T07:02:51 | |
| tc_ac837510 | search | 589ms | 2026-06-06T07:03:03 | |
| tc_b0c1a819 | search | 127ms | 2026-06-06T07:03:03 | |
| tc_b11ae175 | search | 459ms | 2026-06-06T07:03:04 | |
| tc_1431c1b4 | submit_finding | 18ms | 2026-06-06T07:03:08 | |
| tc_fcf6ff23 | search | 4538ms | 2026-06-06T07:03:09 | |
| tc_acc3892a | search | 113ms | 2026-06-06T07:03:22 | |
| tc_5846ce2f | search | 51ms | 2026-06-06T07:03:23 | |
| tc_a2e5cbb9 | scan_hidden_processes | 9ms | 2026-06-06T07:03:24 | |
| tc_8fded848 | submit_finding | 11ms | 2026-06-06T07:03:25 | |
| tc_4d6e3bdc | submit_finding | 13ms | 2026-06-06T07:03:55 | |
| tc_99fd42de | index_evtx_file | 13065ms | 2026-06-06T07:05:35 | |
| tc_132ca3e2 | search | 437ms | 2026-06-06T07:05:35 | |
| tc_34a710e3 | detect_timestomping | 1439ms | 2026-06-06T07:05:37 | |
| tc_66383a7b | get_raw_output | 7662ms | 2026-06-06T07:05:52 | |
| tc_78870068 | search | 102ms | 2026-06-06T07:05:53 | |
| tc_12cd035f | search | 31ms | 2026-06-06T07:05:53 | |
| tc_e8cb79b2 | search | 98ms | 2026-06-06T07:06:06 | |
| tc_adeee493 | search | 910ms | 2026-06-06T07:06:07 | |
| tc_15cfa05e | submit_finding | 0ms | 2026-06-06T07:06:12 | |
| tc_1cb6496c | search | 29ms | 2026-06-06T07:06:19 | |
| tc_b83a24d3 | scan_hidden_processes | 15ms | 2026-06-06T07:06:19 | |
| tc_d9eff5a7 | search | 925ms | 2026-06-06T07:06:20 | |
| tc_929bb36b | search | 24ms | 2026-06-06T07:06:20 | |
| tc_571b63ae | search | 525ms | 2026-06-06T07:06:22 | |
| tc_492eb01e | search | 151ms | 2026-06-06T07:06:22 | |
| tc_18f35d85 | search | 472ms | 2026-06-06T07:06:25 | |
| tc_37a409ca | search | 36ms | 2026-06-06T07:06:26 | |
| tc_ac657197 | search | 42ms | 2026-06-06T07:06:26 | |
| tc_9a2617bb | search | 119ms | 2026-06-06T07:06:33 | |
| tc_049f2680 | search | 44ms | 2026-06-06T07:06:34 | |
| tc_f91b8518 | search | 116ms | 2026-06-06T07:06:34 | |
| tc_9acf695f | get_carved_iocs | 2297ms | 2026-06-06T07:06:39 | |
| tc_7823e1f4 | search | 150ms | 2026-06-06T07:06:39 | |
| tc_19d26c14 | update_finding | 8ms | 2026-06-06T07:06:52 | |
| tc_765d81e1 | search | 67ms | 2026-06-06T07:06:52 | |
| tc_9b859299 | search | 31ms | 2026-06-06T07:06:52 | |
| tc_f23d00d5 | search | 29ms | 2026-06-06T07:07:04 | |
| tc_a615ccff | search | 363ms | 2026-06-06T07:07:05 | |
| tc_85604c9b | submit_finding | 19ms | 2026-06-06T07:07:08 | |
| tc_2cc6b105 | submit_finding | 14ms | 2026-06-06T07:07:18 | |
| tc_55b9fa13 | submit_finding | 16ms | 2026-06-06T07:07:26 | |
| tc_5df21172 | search | 56ms | 2026-06-06T07:07:34 | |
| tc_1e007ec4 | search | 34ms | 2026-06-06T07:07:35 | |
| tc_dd06c588 | search | 30ms | 2026-06-06T07:07:36 | |
| tc_65920a52 | submit_finding | 10ms | 2026-06-06T07:07:42 | |
| tc_8c475b87 | get_raw_output | 4370ms | 2026-06-06T07:07:48 | |
| tc_fc7bb189 | search | 26ms | 2026-06-06T07:07:48 | |
| tc_567ba7bb | submit_finding | 15ms | 2026-06-06T07:07:54 | |
| tc_a88af352 | submit_finding | 14ms | 2026-06-06T07:08:08 | |
| tc_6d1e338e | submit_finding | 14ms | 2026-06-06T07:08:17 | |
| tc_839221cf | extract_file_by_inode | 240ms | 2026-06-06T07:08:24 | |
| tc_3a5dd6c1 | submit_finding | 17ms | 2026-06-06T07:08:32 | |
| tc_f32cd0ee | update_finding | 20ms | 2026-06-06T07:08:41 | |
| tc_34aa4eb0 | submit_finding | 12ms | 2026-06-06T07:08:44 | |
| tc_65ace770 | extract_file_by_inode | 219ms | 2026-06-06T07:08:51 | |
| tc_1b5613db | search | 22ms | 2026-06-06T07:08:51 | |
| tc_51a3cc65 | triage_binary | 0ms | 2026-06-06T07:08:59 | |
| tc_6b7975af | search | 23ms | 2026-06-06T07:08:59 | |
| tc_12d392c3 | track_progress | 15ms | 2026-06-06T07:09:03 | |
| tc_7a1d45e9 | update_finding | 17ms | 2026-06-06T07:09:27 | |
| tc_131c6b04 | get_investigation_summary | 10ms | 2026-06-06T07:09:27 | |
| tc_17230d98 | submit_finding | 15ms | 2026-06-06T07:09:42 | |
| tc_fec62523 | scan_evidence | 45ms | 2026-06-06T07:09:43 | |
| tc_207f8349 | open_case | 20ms | 2026-06-06T07:09:51 | |
| tc_24e3ced6 | list_sources | 11ms | 2026-06-06T07:09:55 | |
| tc_c75997a9 | submit_finding | 14ms | 2026-06-06T07:10:01 | |
| tc_786efb43 | submit_finding | 15ms | 2026-06-06T07:10:12 | |
| tc_aad5dbb4 | search | 785ms | 2026-06-06T07:10:19 | |
| tc_869e320b | search | 21ms | 2026-06-06T07:10:19 | |
| tc_13623596 | get_findings | 3ms | 2026-06-06T07:10:19 | |
| tc_97d35469 | submit_finding | 17ms | 2026-06-06T07:10:38 | |
| tc_0ad4a865 | track_progress | 16ms | 2026-06-06T07:10:51 | |
| tc_736035a3 | open_case | 16ms | 2026-06-06T07:10:57 | |
| tc_8351c0c2 | extract_archive | 1ms | 2026-06-06T07:11:02 | |
| tc_0f60fa26 | list_directory | 8ms | 2026-06-06T07:11:08 | |
| tc_733a9902 | get_investigation_summary | 10ms | 2026-06-06T07:11:10 | |
| tc_e6851326 | list_directory | 5ms | 2026-06-06T07:11:12 | |
| tc_0eb6fcce | list_directory | 8ms | 2026-06-06T07:11:16 | |
| tc_94f1c026 | list_directory | 10ms | 2026-06-06T07:11:22 | |
| tc_2f688ebd | list_directory | 6ms | 2026-06-06T07:11:26 | |
| tc_9a2b2881 | list_sources | 11ms | 2026-06-06T07:11:31 | |
| tc_351a0c94 | scan_evidence | 37ms | 2026-06-06T07:11:31 | |
| tc_c51c1ce6 | open_case | 11ms | 2026-06-06T07:11:38 | |
| tc_e982ab92 | run_mmls | 0ms | 2026-06-06T07:11:45 | |
| tc_a4dbb75e | start_extraction_batch | 15ms | 2026-06-06T07:11:54 | |
| tc_26a4b9ab | run_fls | 120849ms | 2026-06-06T07:13:54 | |
| tc_04873e99 | yara_scan_memory | 174460ms | 2026-06-06T07:14:48 | |
| tc_da1e30ab | run_volatility_batch | 563563ms | 2026-06-06T07:21:17 | |
| tc_70ea556a | open_case | 45ms | 2026-06-06T07:22:34 | |
| tc_9e224c76 | run_mmls | 0ms | 2026-06-06T07:24:10 | |
| tc_2f90888e | start_extraction_batch | 39ms | 2026-06-06T07:24:10 | |
| tc_94e90243 | run_fls | 185321ms | 2026-06-06T07:27:15 | |
| tc_7e099bff | get_completed_results | 0ms | 2026-06-06T07:31:43 | |
| tc_ec318e20 | run_volatility_batch | 755591ms | 2026-06-06T07:36:45 | |
| tc_9c4093f1 | start_extraction_batch | 32ms | 2026-06-06T07:36:58 | |
| tc_0132ac8a | start_extraction_batch | 102ms | 2026-06-06T07:42:12 | |
| tc_14476796 | run_bulk_extractor | 1332458ms | 2026-06-06T07:46:22 | |
| tc_077a44df | run_hayabusa | 92ms | 2026-06-06T07:47:15 | |
| tc_0e2ff9cc | run_chainsaw | 132ms | 2026-06-06T07:47:15 | |
| tc_69fa8522 | run_amcache_parser | 27041ms | 2026-06-06T07:47:42 | |
| tc_349b0dff | run_prefetch_parser | 72560ms | 2026-06-06T07:48:27 | |
| tc_44cccbf2 | run_shimcache_parser | 88096ms | 2026-06-06T07:48:43 | |
| tc_90490fa1 | run_evtx_parser | 126110ms | 2026-06-06T07:49:21 | |
| tc_19262983 | get_completed_results | 0ms | 2026-06-06T07:50:59 | |
| tc_aa452396 | run_mft_parser | 66786ms | 2026-06-06T07:52:08 | |
| tc_61fc080e | run_registry_parser | 302019ms | 2026-06-06T07:52:17 | |
| tc_4619939b | yara_scan_memory | 130774ms | 2026-06-06T07:53:10 | |
| tc_5e17dbc3 | start_extraction_batch | 41ms | 2026-06-06T07:53:34 | |
| tc_bc5ff211 | run_chainsaw | 9628ms | 2026-06-06T07:53:43 | |
| tc_fad23b3f | run_amcache_parser | 64973ms | 2026-06-06T07:54:39 | |
| tc_681da70a | yara_scan_files | 231184ms | 2026-06-06T07:54:52 | |
| tc_8f8a42d2 | run_prefetch_parser | 90442ms | 2026-06-06T07:55:10 | |
| tc_49b6cad0 | run_hayabusa | 97190ms | 2026-06-06T07:55:17 | |
| tc_cf4d956c | run_shimcache_parser | 110807ms | 2026-06-06T07:55:24 | |
| tc_cfbb1cd8 | run_evtx_parser | 124827ms | 2026-06-06T07:55:38 | |
| tc_d3715b14 | run_bulk_extractor | 1074862ms | 2026-06-06T07:55:53 | |
| tc_f83d2940 | run_mft_parser | 140012ms | 2026-06-06T07:55:54 | |
| tc_5716c34a | wait_all | 516413ms | 2026-06-06T07:55:57 | |
| tc_ddef9a22 | get_completed_results | 0ms | 2026-06-06T07:56:03 | |
| tc_d6a8a4a6 | get_completed_results | 0ms | 2026-06-06T07:56:04 | |
| tc_e3e4d2b3 | start_extraction_batch | 2ms | 2026-06-06T07:56:16 | |
| tc_79e3ad9f | start_extraction_batch | 1ms | 2026-06-06T07:56:21 | |
| tc_926f02a4 | index_evtx_file | 0ms | 2026-06-06T07:56:21 | |
| tc_23b9b7dd | index_evtx_file | 532ms | 2026-06-06T07:56:21 | |
| tc_e6098ebc | index_evtx_file | 919ms | 2026-06-06T07:56:22 | |
| tc_2493d7e7 | index_evtx_file | 2162ms | 2026-06-06T07:56:23 | |
| tc_107b349a | index_evtx_file | 8509ms | 2026-06-06T07:56:29 | |
| tc_7e7d9309 | index_evtx_file | 22826ms | 2026-06-06T07:56:44 | |
| tc_c7f3a745 | run_prefetch_parser | 33978ms | 2026-06-06T07:56:50 | |
| tc_ad7860ff | yara_scan_files | 192908ms | 2026-06-06T07:56:56 | |
| tc_54f9949d | run_shimcache_parser | 41988ms | 2026-06-06T07:56:58 | |
| tc_949300c1 | wait_all | 35012ms | 2026-06-06T07:57:01 | |
| tc_ff6f4eb5 | get_completed_results | 0ms | 2026-06-06T07:57:09 | |
| tc_200687a5 | open_case | 29ms | 2026-06-06T07:57:38 | |
| tc_c424d938 | wait_all | 0ms | 2026-06-06T07:57:38 | |
| tc_74f1aa64 | run_registry_parser | 254948ms | 2026-06-06T07:57:55 | |
| tc_cd871425 | open_case | 18ms | 2026-06-06T07:58:00 | |
| tc_acc49fd0 | get_completed_results | 0ms | 2026-06-06T07:58:04 | |
| tc_b37744eb | get_investigation_summary | 31ms | 2026-06-06T07:58:06 | |
| tc_0e52f953 | start_extraction_batch | 5ms | 2026-06-06T07:58:11 | |
| tc_17adfcb9 | get_source_stats | 18239ms | 2026-06-06T07:58:25 | |
| tc_e9724578 | list_processes_from_memory | 6ms | 2026-06-06T07:58:25 | |
| tc_15ff72ef | get_process_tree | 4ms | 2026-06-06T07:58:25 | |
| tc_d8f20c69 | run_amcache_parser | 13874ms | 2026-06-06T07:58:25 | |
| tc_b3553a3e | get_findings | 3ms | 2026-06-06T07:58:36 | |
| tc_843ebb83 | search | 26ms | 2026-06-06T07:58:36 | |
| tc_31423290 | search | 29ms | 2026-06-06T07:58:37 | |
| tc_faa26eae | search | 69ms | 2026-06-06T07:58:39 | |
| tc_eae5e395 | run_prefetch_parser | 35260ms | 2026-06-06T07:58:46 | |
| tc_7735dfee | run_shimcache_parser | 42114ms | 2026-06-06T07:58:53 | |
| tc_6193313e | search | 507ms | 2026-06-06T07:58:56 | |
| tc_c43dec86 | search | 55ms | 2026-06-06T07:58:56 | |
| tc_ec862127 | get_raw_output | 17346ms | 2026-06-06T07:59:13 | |
| tc_3fb49fa5 | search | 90ms | 2026-06-06T07:59:31 | |
| tc_776f6314 | search | 69ms | 2026-06-06T07:59:32 | |
| tc_3ebf6520 | open_case | 18ms | 2026-06-06T07:59:33 | |
| tc_f81e7890 | get_investigation_summary | 30ms | 2026-06-06T07:59:38 | |
| tc_b8b432ec | get_raw_output | 29053ms | 2026-06-06T08:00:02 | |
| tc_3e148e1b | get_source_stats | 23526ms | 2026-06-06T08:00:02 | |
| tc_fccb7f85 | list_sources | 9ms | 2026-06-06T08:00:02 | |
| tc_bc449d8d | search | 56ms | 2026-06-06T08:00:02 | |
| tc_f33f86fd | get_findings | 4ms | 2026-06-06T08:00:12 | |
| tc_387959f2 | get_process_tree | 7ms | 2026-06-06T08:00:13 | |
| tc_b309e502 | find_suspicious_processes._query(volatility.malfind) | 566ms | 2026-06-06T08:00:13 | |
| tc_80366d87 | find_suspicious_processes._query(volatility.cmdline) | 164ms | 2026-06-06T08:00:13 | |
| tc_bc79a051 | find_suspicious_processes._query(volatility.netscan) | 171ms | 2026-06-06T08:00:14 | |
| tc_60dc0a55 | find_suspicious_processes._query(volatility.pstree) | 161ms | 2026-06-06T08:00:14 | |
| tc_42106ca0 | find_suspicious_processes._query(volatility.psscan) | 166ms | 2026-06-06T08:00:14 | |
| tc_be2e17a1 | find_suspicious_processes._query(volatility.pslist) | 164ms | 2026-06-06T08:00:14 | |
| tc_6a8a6b38 | find_suspicious_processes._query(volatility.dlllist) | 178ms | 2026-06-06T08:00:14 | |
| tc_a6337c2e | find_suspicious_processes | 1577ms | 2026-06-06T08:00:14 | |
| tc_dc48ae34 | search | 59ms | 2026-06-06T08:00:22 | |
| tc_2a4f3c66 | search | 70ms | 2026-06-06T08:00:23 | |
| tc_164e59be | get_raw_output | 499ms | 2026-06-06T08:00:24 | |
| tc_b2b6a298 | search | 111ms | 2026-06-06T08:00:24 | |
| tc_43c5be6b | search | 214ms | 2026-06-06T08:00:28 | |
| tc_ae5d200c | search | 165ms | 2026-06-06T08:00:29 | |
| tc_0365387f | search | 70ms | 2026-06-06T08:00:29 | |
| tc_14a2773c | search | 78ms | 2026-06-06T08:00:46 | |
| tc_fdd44c03 | search | 144ms | 2026-06-06T08:00:52 | |
| tc_9e6ee71e | search | 2638ms | 2026-06-06T08:00:55 | |
| tc_05460dde | search | 2869ms | 2026-06-06T08:00:58 | |
| tc_ba83b29d | get_raw_output | 18482ms | 2026-06-06T08:01:04 | |
| tc_a65f39e7 | search | 82ms | 2026-06-06T08:01:11 | |
| tc_e401b5bd | search | 755ms | 2026-06-06T08:01:13 | |
| tc_a4e96dec | search | 449ms | 2026-06-06T08:01:13 | |
| tc_aeaea42b | search | 78ms | 2026-06-06T08:01:17 | |
| tc_2229c88a | search | 58ms | 2026-06-06T08:01:18 | |
| tc_a3430288 | search | 62ms | 2026-06-06T08:01:18 | |
| tc_0a1336c6 | list_directory | 9ms | 2026-06-06T08:01:23 | |
| tc_c4f12402 | get_raw_output | 409ms | 2026-06-06T08:01:26 | |
| tc_43e6f0f8 | get_raw_output | 155ms | 2026-06-06T08:01:29 | |
| tc_b59a0c0c | search | 36ms | 2026-06-06T08:01:29 | |
| tc_ae4a459d | list_directory | 10ms | 2026-06-06T08:01:38 | |
| tc_957b132a | list_directory | 8ms | 2026-06-06T08:01:39 | |
| tc_c9bf9959 | list_directory | 8ms | 2026-06-06T08:01:53 | |
| tc_ea5a3740 | search | 707ms | 2026-06-06T08:01:59 | |
| tc_2f7a0a15 | search | 31ms | 2026-06-06T08:01:59 | |
| tc_dbfab581 | search | 25ms | 2026-06-06T08:02:00 | |
| tc_f93001ec | search | 52ms | 2026-06-06T08:02:01 | |
| tc_7749bf6a | search | 42ms | 2026-06-06T08:02:01 | |
| tc_6a33fc05 | search | 42ms | 2026-06-06T08:02:02 | |
| tc_27fb59ed | get_raw_output | 7097ms | 2026-06-06T08:02:21 | |
| tc_9490b109 | get_raw_output | 7167ms | 2026-06-06T08:02:28 | |
| tc_4a21d712 | get_raw_output | 7250ms | 2026-06-06T08:02:36 | |
| tc_739b3134 | submit_finding | 33ms | 2026-06-06T08:02:38 | |
| tc_3f2a7413 | submit_finding | 18ms | 2026-06-06T08:02:57 | |
| tc_dcc40157 | submit_finding | 17ms | 2026-06-06T08:03:19 | |
| tc_fa4a8753 | get_raw_output | 16700ms | 2026-06-06T08:03:35 | |
| tc_e31d4bd8 | search | 70ms | 2026-06-06T08:03:35 | |
| tc_21676b66 | search | 52ms | 2026-06-06T08:03:35 | |
| tc_c6f14406 | search | 766ms | 2026-06-06T08:04:02 | |
| tc_cb9433b1 | search | 30ms | 2026-06-06T08:04:02 | |
| tc_ddc8b2e9 | search | 751ms | 2026-06-06T08:04:03 | |
| tc_72ac69de | search | 55ms | 2026-06-06T08:04:15 | |
| tc_a94819e6 | search | 695ms | 2026-06-06T08:04:17 | |
| tc_acbbe6cc | get_raw_output | 16304ms | 2026-06-06T08:04:33 | |
| tc_662460ae | search | 97ms | 2026-06-06T08:04:45 | |
| tc_baebf015 | search | 50ms | 2026-06-06T08:04:46 | |
| tc_1447f7a3 | search | 767ms | 2026-06-06T08:04:47 | |
| tc_3cce3174 | search | 54ms | 2026-06-06T08:04:58 | |
| tc_3f8a74fb | search | 60ms | 2026-06-06T08:04:59 | |
| tc_2ae9c6eb | search | 22ms | 2026-06-06T08:04:59 | |
| tc_924f269b | search | 732ms | 2026-06-06T08:05:02 | |
| tc_40079482 | search | 64ms | 2026-06-06T08:05:02 | |
| tc_a5f16f8e | search | 345ms | 2026-06-06T08:05:03 | |
| tc_906401ea | search | 25ms | 2026-06-06T08:05:06 | |
| tc_570b004f | search | 63ms | 2026-06-06T08:05:07 | |
| tc_58f8e305 | search | 302ms | 2026-06-06T08:05:07 | |
| tc_c034bef0 | list_sources | 12ms | 2026-06-06T08:05:13 | |
| tc_c769b531 | search | 24ms | 2026-06-06T08:05:20 | |
| tc_0f7c1e8b | search | 25ms | 2026-06-06T08:05:20 | |
| tc_dd5b51dc | search | 37ms | 2026-06-06T08:05:30 | |
| tc_8c2bc049 | search | 106ms | 2026-06-06T08:05:30 | |
| tc_8283766f | search | 363ms | 2026-06-06T08:05:32 | |
| tc_52486421 | get_raw_output | 7009ms | 2026-06-06T08:05:39 | |
| tc_82b41ad4 | search | 51ms | 2026-06-06T08:05:42 | |
| tc_eca43fd9 | search | 60ms | 2026-06-06T08:05:42 | |
| tc_29656fb7 | search | 80ms | 2026-06-06T08:05:47 | |
| tc_b913a22e | search | 128ms | 2026-06-06T08:05:48 | |
| tc_df019bee | submit_finding | 15ms | 2026-06-06T08:06:14 | |
| tc_10c7b485 | submit_finding | 14ms | 2026-06-06T08:06:29 | |
| tc_5a1b743e | search | 29ms | 2026-06-06T08:06:34 | |
| tc_d92b6f32 | search | 97ms | 2026-06-06T08:06:35 | |
| tc_ea3f5c27 | submit_finding | 16ms | 2026-06-06T08:06:59 | |
| tc_2bb544be | search | 787ms | 2026-06-06T08:07:05 | |
| tc_24ecd44f | search | 44ms | 2026-06-06T08:07:06 | |
| tc_532a33a9 | search | 47ms | 2026-06-06T08:07:11 | |
| tc_294f8623 | search | 2210ms | 2026-06-06T08:07:13 | |
| tc_36de8666 | get_findings | 15ms | 2026-06-06T08:07:36 | |
| tc_2e8d4fc5 | search | 94ms | 2026-06-06T08:07:37 | |
| tc_9cc41026 | search | 93ms | 2026-06-06T08:07:38 | |
| tc_20c4055c | submit_finding | 16ms | 2026-06-06T08:07:38 | |
| tc_1be2bcb5 | submit_finding | 13ms | 2026-06-06T08:07:57 | |
| tc_cc60869f | search | 52ms | 2026-06-06T08:08:02 | |
| tc_cd6817fa | search | 718ms | 2026-06-06T08:08:04 | |
| tc_0ccf2abb | search | 36ms | 2026-06-06T08:08:08 | |
| tc_d61aeaff | get_deleted_files | 2365ms | 2026-06-06T08:08:11 | |
| tc_d5782820 | search | 124ms | 2026-06-06T08:08:16 | |
| tc_8ee551fc | update_finding | 18ms | 2026-06-06T08:08:17 | |
| tc_a2a12f1b | get_findings | 10ms | 2026-06-06T08:08:18 | |
| tc_dffb31fb | search | 63ms | 2026-06-06T08:08:18 | |
| tc_3b42b30a | get_findings | 10ms | 2026-06-06T08:08:22 | |
| tc_ebe8dbc9 | track_progress | 27ms | 2026-06-06T08:08:49 | |
| tc_6d1b30b6 | update_finding | 15ms | 2026-06-06T08:08:50 | |
| tc_0964161e | update_finding | 15ms | 2026-06-06T08:09:05 | |
| tc_f227f0ff | get_investigation_summary | 13ms | 2026-06-06T08:09:12 | |
| tc_aaad0fad | update_finding | 13ms | 2026-06-06T08:09:17 | |
| tc_df008f5b | update_finding | 13ms | 2026-06-06T08:09:34 | |
| tc_76ddebba | update_finding | 16ms | 2026-06-06T08:09:35 | |
| tc_7b50c82f | update_finding | 13ms | 2026-06-06T08:09:36 | |
| tc_5aaa051d | update_finding | 16ms | 2026-06-06T08:09:36 | |
| tc_b570eac1 | update_finding | 19ms | 2026-06-06T08:09:38 | |
| tc_be58548c | update_finding | 13ms | 2026-06-06T08:09:38 | |
| tc_ad6b5e9b | search | 44ms | 2026-06-06T08:09:55 | |
| tc_65f75871 | search | 42ms | 2026-06-06T08:09:56 | |
| tc_810bce4c | submit_finding | 12ms | 2026-06-06T08:10:14 | |
| tc_706eb13c | open_case | 18ms | 2026-06-06T08:10:30 | |
| tc_4dfca2a9 | track_progress | 16ms | 2026-06-06T08:10:47 | |
| tc_d45e1af9 | search | 45ms | 2026-06-06T08:10:54 | |
| tc_5591ac88 | search | 104ms | 2026-06-06T08:11:01 | |
| tc_61bf3361 | open_case | 26ms | 2026-06-06T08:11:29 | |
| tc_18aab753 | get_investigation_summary | 14ms | 2026-06-06T08:11:35 | |
| tc_825b845c | start_extraction_batch | 18ms | 2026-06-06T08:11:37 | |
| tc_af97f313 | start_extraction_batch | 13ms | 2026-06-06T08:11:39 | |
| tc_35c4b86f | run_mmls | 0ms | 2026-06-06T08:11:39 | |
| tc_1f3eeabe | run_fls | 167642ms | 2026-06-06T08:14:27 | |
| tc_4eeb764c | yara_scan_memory | 171567ms | 2026-06-06T08:14:29 | |
| tc_e04b3d9d | scan_evidence | 115ms | 2026-06-06T08:16:57 | |
| tc_57bb866a | open_case | 52ms | 2026-06-06T08:22:06 | |
| tc_d4e2bbac | open_case | 16ms | 2026-06-06T08:23:04 | |
| tc_3204d99b | start_extraction_batch | 31ms | 2026-06-06T08:23:14 | |
| tc_758be7a0 | run_mmls | 0ms | 2026-06-06T08:23:14 | |
| tc_616c1dd2 | run_fls | 66020ms | 2026-06-06T08:24:20 | |
| tc_03e21bf1 | run_volatility_batch | 855938ms | 2026-06-06T08:25:53 | |
| tc_9857f16b | yara_scan_memory | 218475ms | 2026-06-06T08:26:58 | |
| tc_d406bc2d | run_volatility_batch | 998135ms | 2026-06-06T08:28:15 | |
| tc_b69fb26b | run_volatility_batch | 396131ms | 2026-06-06T08:29:50 | |
| tc_4096bae3 | run_bulk_extractor | 1223697ms | 2026-06-06T08:32:03 | |
| tc_8e60cf23 | wait_all | 1222342ms | 2026-06-06T08:32:06 | |
| tc_47fb25d5 | get_completed_results | 0ms | 2026-06-06T08:37:12 | |
| tc_d049c462 | get_completed_results | 0ms | 2026-06-06T08:41:08 | |
| tc_dee89a98 | start_extraction_batch | 97ms | 2026-06-06T08:41:18 | |
| tc_da29d2d4 | run_hayabusa | 34ms | 2026-06-06T08:41:18 | |
| tc_43bfe21c | run_chainsaw | 123ms | 2026-06-06T08:41:23 | |
| tc_a1a6fa5a | run_amcache_parser | 60864ms | 2026-06-06T08:42:23 | |
| tc_b2edff08 | run_prefetch_parser | 91904ms | 2026-06-06T08:42:54 | |
| tc_2b716b21 | run_mft_parser | 110540ms | 2026-06-06T08:43:13 | |
| tc_bd39f3f6 | run_evtx_parser | 128335ms | 2026-06-06T08:43:31 | |
| tc_cf801298 | run_shimcache_parser | 151757ms | 2026-06-06T08:43:54 | |
| tc_da3036a5 | run_bulk_extractor | 1462108ms | 2026-06-06T08:47:41 | |
| tc_52b66b04 | get_completed_results | 0ms | 2026-06-06T08:47:48 | |
| tc_8ab4888c | start_extraction_batch | 56ms | 2026-06-06T08:47:57 | |
| tc_220f1062 | run_chainsaw | 130ms | 2026-06-06T08:47:57 | |
| tc_7a7a3d16 | run_hayabusa | 137ms | 2026-06-06T08:47:57 | |
| tc_a278957e | open_case | 85ms | 2026-06-06T08:56:05 | |
| tc_7ae07cf8 | get_source_stats | 50127ms | 2026-06-06T08:57:02 | |
| tc_b056c57d | run_mft_parser | 548421ms | 2026-06-06T08:57:06 | |
| tc_418b5d68 | run_amcache_parser | 558142ms | 2026-06-06T08:57:15 | |
| tc_75f06782 | run_prefetch_parser | 575344ms | 2026-06-06T08:57:32 | |
| tc_249a3d57 | start_extraction_batch | 33ms | 2026-06-06T08:57:51 | |
| tc_43efc609 | run_hayabusa | 52ms | 2026-06-06T08:57:51 | |
| tc_f968569a | run_evtx_parser | 595292ms | 2026-06-06T08:57:52 | |
| tc_28e00d00 | yara_scan_files | 601684ms | 2026-06-06T08:57:59 | |
| tc_d2b0fe5d | run_shimcache_parser | 615271ms | 2026-06-06T08:58:12 | |
| tc_e0529ae1 | run_prefetch_parser | 51198ms | 2026-06-06T08:58:47 | |
| tc_d4088db1 | run_shimcache_parser | 89437ms | 2026-06-06T08:59:21 | |
| tc_b8dfe856 | get_completed_results | 0ms | 2026-06-06T08:59:25 | |
| tc_70d4d37c | index_evtx_file | 1535ms | 2026-06-06T08:59:33 | |
| tc_5325314a | index_evtx_file | 378ms | 2026-06-06T08:59:33 | |
| tc_f3442962 | index_evtx_file | 370ms | 2026-06-06T08:59:34 | |
| tc_c8906627 | open_case | 12ms | 2026-06-06T09:00:24 | |
| tc_72e6767a | get_investigation_summary | 24ms | 2026-06-06T09:00:29 | |
| tc_0a10984d | get_source_stats | 24141ms | 2026-06-06T09:00:54 | |
| tc_350face7 | list_sources | 11ms | 2026-06-06T09:00:56 | |
| tc_f5ad2dd6 | get_findings | 4ms | 2026-06-06T09:01:07 | |
| tc_d03a6962 | get_process_tree | 9ms | 2026-06-06T09:01:09 | |
| tc_19d42dbc | find_suspicious_processes._query(volatility.malfind) | 753ms | 2026-06-06T09:01:10 | |
| tc_339d6b34 | find_suspicious_processes._query(volatility.cmdline) | 248ms | 2026-06-06T09:01:10 | |
| tc_781644ca | find_suspicious_processes._query(volatility.netscan) | 244ms | 2026-06-06T09:01:11 | |
| tc_126b182a | find_suspicious_processes._query(volatility.pstree) | 250ms | 2026-06-06T09:01:11 | |
| tc_b5e3f2db | find_suspicious_processes._query(volatility.psscan) | 208ms | 2026-06-06T09:01:11 | |
| tc_8f7c5714 | find_suspicious_processes._query(volatility.pslist) | 213ms | 2026-06-06T09:01:11 | |
| tc_ef1daf6a | find_suspicious_processes._query(volatility.dlllist) | 256ms | 2026-06-06T09:01:12 | |
| tc_dec900ce | find_suspicious_processes | 2180ms | 2026-06-06T09:01:12 | |
| tc_35746b03 | search | 413ms | 2026-06-06T09:01:43 | |
| tc_1d767543 | search | 172ms | 2026-06-06T09:01:43 | |
| tc_307398ac | run_registry_parser | 835515ms | 2026-06-06T09:01:53 | |
| tc_281c02ec | get_completed_results | 0ms | 2026-06-06T09:02:02 | |
| tc_cfff6fbb | get_raw_output | 23801ms | 2026-06-06T09:02:07 | |
| tc_00c85f2f | start_extraction_batch | 3ms | 2026-06-06T09:02:09 | |
| tc_c9a551e5 | run_amcache_parser | 25097ms | 2026-06-06T09:02:34 | |
| tc_35b64691 | search | 363ms | 2026-06-06T09:02:39 | |
| tc_ac8c179c | search | 894ms | 2026-06-06T09:02:40 | |
| tc_69511331 | get_raw_output | 10556ms | 2026-06-06T09:02:51 | |
| tc_88979068 | run_prefetch_parser | 62048ms | 2026-06-06T09:03:11 | |
| tc_75e2b12a | run_shimcache_parser | 88425ms | 2026-06-06T09:03:37 | |
| tc_a6ea3d9d | search | 671ms | 2026-06-06T09:03:56 | |
| tc_24f459bd | search | 311ms | 2026-06-06T09:03:56 | |
| tc_e29f965b | search | 1269ms | 2026-06-06T09:03:57 | |
| tc_7977b3d2 | open_case | 50ms | 2026-06-06T09:04:01 | |
| tc_aaba6a88 | wait_all | 0ms | 2026-06-06T09:04:05 | |
| tc_8a710a80 | get_raw_output | 734ms | 2026-06-06T09:04:16 | |
| tc_10f7aec5 | search | 318ms | 2026-06-06T09:04:17 | |
| tc_294d05c9 | search | 73ms | 2026-06-06T09:04:17 | |
| tc_30c01c77 | open_case | 20ms | 2026-06-06T09:04:27 | |
| tc_943b43ec | get_investigation_summary | 28ms | 2026-06-06T09:04:32 | |
| tc_05b0129b | search | 340ms | 2026-06-06T09:04:41 | |
| tc_41d39d5d | search | 1949ms | 2026-06-06T09:04:44 | |
| tc_efaaec20 | search | 598ms | 2026-06-06T09:04:44 | |
| tc_8b75c34a | get_source_stats | 25015ms | 2026-06-06T09:04:58 | |
| tc_c6187020 | list_sources | 15ms | 2026-06-06T09:05:00 | |
| tc_d86c96fb | search | 159ms | 2026-06-06T09:05:12 | |
| tc_38a21ae6 | search | 67ms | 2026-06-06T09:05:12 | |
| tc_9768ef79 | get_findings | 7ms | 2026-06-06T09:05:12 | |
| tc_a41c6625 | get_findings | 5ms | 2026-06-06T09:05:20 | |
| tc_3c313619 | search | 92ms | 2026-06-06T09:05:20 | |
| tc_64d7eca2 | search | 72ms | 2026-06-06T09:05:21 | |
| tc_7ef18f8d | search | 328ms | 2026-06-06T09:05:31 | |
| tc_12a40aeb | list_directory | 4ms | 2026-06-06T09:05:31 | |
| tc_41ea2b2f | search | 61ms | 2026-06-06T09:05:49 | |
| tc_32113eb8 | search | 159ms | 2026-06-06T09:06:01 | |
| tc_219c5208 | search | 86ms | 2026-06-06T09:06:01 | |
| tc_9f8bf3f2 | search | 86ms | 2026-06-06T09:06:02 | |
| tc_ecf4e55e | search | 82ms | 2026-06-06T09:06:02 | |
| tc_0a821c5a | search | 68ms | 2026-06-06T09:06:12 | |
| tc_b4fea2de | search | 143ms | 2026-06-06T09:06:12 | |
| tc_9da77de3 | search | 94ms | 2026-06-06T09:06:13 | |
| tc_21b031b8 | search | 645ms | 2026-06-06T09:06:30 | |
| tc_a8a9cc62 | search | 335ms | 2026-06-06T09:06:31 | |
| tc_2e16c9e4 | search | 308ms | 2026-06-06T09:06:31 | |
| tc_9d1c6325 | search | 768ms | 2026-06-06T09:06:42 | |
| tc_ce2e634b | run_evtx_parser | 0ms | 2026-06-06T09:06:42 | |
| tc_66186a53 | decode_payload | 26ms | 2026-06-06T09:06:42 | |
| tc_dd8768a7 | search | 27ms | 2026-06-06T09:06:43 | |
| tc_fc085250 | search | 336ms | 2026-06-06T09:06:44 | |
| tc_4e21d89f | search | 507ms | 2026-06-06T09:06:59 | |
| tc_f2377d73 | search | 1121ms | 2026-06-06T09:07:00 | |
| tc_b85c6533 | get_raw_output | 21436ms | 2026-06-06T09:07:22 | |
| tc_e404a23e | get_raw_output | 31517ms | 2026-06-06T09:07:22 | |
| tc_5fb52880 | list_directory | 37ms | 2026-06-06T09:07:36 | |
| tc_25b53971 | search | 663ms | 2026-06-06T09:07:37 | |
| tc_cd819765 | list_directory | 6ms | 2026-06-06T09:07:41 | |
| tc_5852e067 | list_directory | 10ms | 2026-06-06T09:07:47 | |
| tc_f554bd0e | get_raw_output | 6906ms | 2026-06-06T09:07:53 | |
| tc_be9033ac | search | 128ms | 2026-06-06T09:07:53 | |
| tc_e368fb48 | get_raw_output | 14189ms | 2026-06-06T09:08:07 | |
| tc_afe3d00b | search | 95ms | 2026-06-06T09:08:07 | |
| tc_bf8833b3 | search | 78ms | 2026-06-06T09:08:42 | |
| tc_751f561e | search | 44ms | 2026-06-06T09:08:42 | |
| tc_ca244314 | search | 21ms | 2026-06-06T09:08:43 | |
| tc_16f074f5 | search | 40ms | 2026-06-06T09:08:56 | |
| tc_371efca6 | search | 93ms | 2026-06-06T09:08:56 | |
| tc_ef30fea3 | search | 819ms | 2026-06-06T09:08:58 | |
| tc_7886512f | find_suspicious_processes._query(volatility.malfind) | 779ms | 2026-06-06T09:09:11 | |
| tc_fa9bed31 | find_suspicious_processes._query(volatility.cmdline) | 240ms | 2026-06-06T09:09:11 | |
| tc_0d4ca29d | find_suspicious_processes._query(volatility.netscan) | 242ms | 2026-06-06T09:09:12 | |
| tc_bfba5ed5 | find_suspicious_processes._query(volatility.pstree) | 231ms | 2026-06-06T09:09:12 | |
| tc_23252f51 | find_suspicious_processes._query(volatility.psscan) | 238ms | 2026-06-06T09:09:12 | |
| tc_53d0cdd2 | find_suspicious_processes._query(volatility.pslist) | 228ms | 2026-06-06T09:09:12 | |
| tc_82046ceb | find_suspicious_processes._query(volatility.dlllist) | 235ms | 2026-06-06T09:09:13 | |
| tc_d339af1e | find_suspicious_processes | 2203ms | 2026-06-06T09:09:13 | |
| tc_3bf5d403 | get_process_tree | 4ms | 2026-06-06T09:09:13 | |
| tc_7421e7e0 | search | 45ms | 2026-06-06T09:09:13 | |
| tc_c461a7a8 | submit_finding | 22ms | 2026-06-06T09:09:30 | |
| tc_822957a2 | submit_finding | 22ms | 2026-06-06T09:09:37 | |
| tc_a3b2c92a | get_raw_output | 14177ms | 2026-06-06T09:09:40 | |
| tc_405e5e4e | submit_finding | 22ms | 2026-06-06T09:09:47 | |
| tc_49a65d26 | get_raw_output | 14095ms | 2026-06-06T09:09:57 | |
| tc_815054ce | submit_finding | 24ms | 2026-06-06T09:10:03 | |
| tc_2aa15451 | get_raw_output | 13914ms | 2026-06-06T09:10:11 | |
| tc_33087f7f | submit_finding | 31ms | 2026-06-06T09:10:12 | |
| tc_8624dc96 | submit_finding | 19ms | 2026-06-06T09:10:19 | |
| tc_093a9dab | search | 338ms | 2026-06-06T09:10:27 | |
| tc_28e83ea3 | search | 57ms | 2026-06-06T09:10:27 | |
| tc_0f1c97cf | search | 2179ms | 2026-06-06T09:10:30 | |
| tc_d368a531 | search | 35ms | 2026-06-06T09:10:46 | |
| tc_266162f2 | search | 666ms | 2026-06-06T09:10:48 | |
| tc_3d8e5b7f | list_sources | 7ms | 2026-06-06T09:10:48 | |
| tc_b1f9b1bd | search | 237ms | 2026-06-06T09:11:04 | |
| tc_7f3846b7 | search | 387ms | 2026-06-06T09:11:06 | |
| tc_b4fab9f2 | search | 80ms | 2026-06-06T09:11:06 | |
| tc_98db80e4 | search | 684ms | 2026-06-06T09:11:09 | |
| tc_eb9eb4e7 | search | 1287ms | 2026-06-06T09:11:11 | |
| tc_f94c5119 | search | 58ms | 2026-06-06T09:11:11 | |
| tc_a28b47d0 | submit_finding | 15ms | 2026-06-06T09:11:28 | |
| tc_275824ac | get_investigation_summary | 20ms | 2026-06-06T09:11:39 | |
| tc_da959893 | get_findings | 4ms | 2026-06-06T09:11:39 | |
| tc_b23db012 | get_raw_output | 6845ms | 2026-06-06T09:11:53 | |
| tc_b4b6bae6 | search | 392ms | 2026-06-06T09:11:53 | |
| tc_c9a5610d | search | 413ms | 2026-06-06T09:11:54 | |
| tc_2c8a4e14 | track_progress | 19ms | 2026-06-06T09:12:05 | |
| tc_9d545bf4 | search | 58ms | 2026-06-06T09:12:34 | |
| tc_63252390 | search | 38ms | 2026-06-06T09:12:35 | |
| tc_e616e35e | search | 84ms | 2026-06-06T09:12:35 | |
| tc_32f9ac26 | search | 1096ms | 2026-06-06T09:12:37 | |
| tc_b7cdbdc6 | get_investigation_summary | 17ms | 2026-06-06T09:12:42 | |
| tc_53652403 | scan_evidence | 49ms | 2026-06-06T09:12:58 | |
| tc_8d704b31 | open_case | 20ms | 2026-06-06T09:13:02 | |
| tc_acd9391a | search | 47ms | 2026-06-06T09:13:05 | |
| tc_2ffb899b | search | 52ms | 2026-06-06T09:13:05 | |
| tc_7a7a412b | search | 472ms | 2026-06-06T09:13:06 | |
| tc_62970d7a | search | 53ms | 2026-06-06T09:13:42 | |
| tc_925b5942 | open_case | 16ms | 2026-06-06T09:13:42 | |
| tc_22c06ccc | search | 51ms | 2026-06-06T09:13:43 | |
| tc_a207f355 | search | 43ms | 2026-06-06T09:13:43 | |
| tc_a98411de | start_extraction_batch | 27ms | 2026-06-06T09:13:49 | |
| tc_f19cd01d | run_mmls | 0ms | 2026-06-06T09:13:49 | |
| tc_b53f321a | get_raw_output | 10605ms | 2026-06-06T09:14:24 | |
| tc_3368a415 | run_fls | 76999ms | 2026-06-06T09:15:06 | |
| tc_3ec26e83 | search | 3588ms | 2026-06-06T09:19:28 | |
| tc_c9109378 | submit_finding | 35ms | 2026-06-06T09:23:47 | |
| tc_c418671b | submit_finding | 1ms | 2026-06-06T09:26:20 | |
| tc_2e46e9f9 | search | 655ms | 2026-06-06T09:26:29 | |
| tc_2c5eaec1 | search | 126ms | 2026-06-06T09:26:29 | |
| tc_71a308b5 | search | 308ms | 2026-06-06T09:26:30 | |
| tc_bb9cfc71 | submit_finding | 11ms | 2026-06-06T09:26:53 | |
| tc_4c6de672 | search | 285ms | 2026-06-06T09:26:59 | |
| tc_12eee7d7 | search | 860ms | 2026-06-06T09:27:00 | |
| tc_c151316c | search | 2724ms | 2026-06-06T09:27:11 | |
| tc_44119bd7 | search | 137ms | 2026-06-06T09:27:11 | |
| tc_559ed9c6 | search | 104ms | 2026-06-06T09:27:24 | |
| tc_b82b5dbd | get_deleted_files | 7842ms | 2026-06-06T09:27:32 | |
| tc_13c19c2e | search | 246ms | 2026-06-06T09:27:43 | |
| tc_70e34cab | search | 74ms | 2026-06-06T09:27:44 | |
| tc_2f5cdab9 | submit_finding | 11ms | 2026-06-06T09:28:07 | |
| tc_1c1f42e1 | search | 91ms | 2026-06-06T09:28:14 | |
| tc_bc392e2d | search | 1006ms | 2026-06-06T09:28:25 | |
| tc_ec404e38 | submit_finding | 18ms | 2026-06-06T09:28:57 | |
| tc_d6451e84 | track_progress | 14ms | 2026-06-06T09:29:18 | |
| tc_735e508b | get_investigation_summary | 24ms | 2026-06-06T09:30:13 | |
| tc_d31236ba | open_case | 20ms | 2026-06-06T09:30:55 | |
| tc_644c9105 | list_directory | 11ms | 2026-06-06T09:31:00 | |
| tc_34684894 | list_sources | 13ms | 2026-06-06T09:31:00 | |
| tc_6788c8c7 | search | 40ms | 2026-06-06T09:31:25 | |
| tc_e2de1ddd | search | 803ms | 2026-06-06T09:31:26 | |
| tc_1ca065d5 | search | 132ms | 2026-06-06T09:31:27 | |
| tc_33a9590c | search | 33ms | 2026-06-06T09:31:27 | |
| tc_bf615fa0 | list_directory | 16ms | 2026-06-06T09:31:44 | |
| tc_cb5dc5af | list_directory | 11ms | 2026-06-06T09:31:49 | |
| tc_88dcc576 | list_directory | 3ms | 2026-06-06T09:31:49 | |
| tc_98ad60ab | list_directory | 3ms | 2026-06-06T09:31:50 | |
| tc_99013df5 | list_directory | 2ms | 2026-06-06T09:31:50 | |
| tc_c55e2d10 | open_case | 17ms | 2026-06-06T09:33:00 | |
| tc_d090caa5 | run_bulk_extractor | 1154344ms | 2026-06-06T09:33:03 | |
| tc_69d493ef | get_completed_results | 0ms | 2026-06-06T09:33:08 | |
| tc_645ecd62 | start_extraction_batch | 40ms | 2026-06-06T09:33:09 | |
| tc_074540a3 | start_extraction_batch | 31ms | 2026-06-06T09:33:16 | |
| tc_2bbe2ba7 | run_amcache_parser | 99362ms | 2026-06-06T09:34:55 | |
| tc_90393917 | run_mft_parser | 117814ms | 2026-06-06T09:35:13 | |
| tc_ad932d60 | run_prefetch_parser | 163596ms | 2026-06-06T09:35:59 | |
| tc_713f69d2 | run_evtx_parser | 211232ms | 2026-06-06T09:36:47 | |
| tc_2b4a5fbc | run_shimcache_parser | 237169ms | 2026-06-06T09:37:13 | |
| tc_faf6c1b5 | run_registry_parser | 489445ms | 2026-06-06T09:41:25 | |
| tc_a3ade1ba | get_completed_results | 0ms | 2026-06-06T09:41:31 | |
| tc_579dee78 | start_extraction_batch | 33ms | 2026-06-06T09:41:38 | |
| tc_db164f00 | run_hayabusa | 90ms | 2026-06-06T09:41:38 | |
| tc_8c4a284d | run_chainsaw | 200ms | 2026-06-06T09:41:38 | |
| tc_b72bbaa1 | yara_scan_files | 115874ms | 2026-06-06T09:43:34 | |
| tc_d69ad83a | get_completed_results | 0ms | 2026-06-06T09:43:39 | |
| tc_54fc3219 | open_case | 40ms | 2026-06-06T09:44:04 | |
| tc_fd616d95 | wait_all | 0ms | 2026-06-06T09:44:08 | |
| tc_7bdf2dda | open_case | 12ms | 2026-06-06T09:44:34 | |
| tc_76980d17 | run_volatility_batch | 691769ms | 2026-06-06T09:44:41 | |
| tc_d0426e09 | get_investigation_summary | 25ms | 2026-06-06T09:44:42 | |
| tc_9a6fd114 | get_source_stats | 33431ms | 2026-06-06T09:45:16 | |
| tc_d871216f | list_sources | 44ms | 2026-06-06T09:45:18 | |
| tc_bb20a5b6 | search | 162ms | 2026-06-06T09:45:28 | |
| tc_d657f96a | search | 336ms | 2026-06-06T09:45:29 | |
| tc_a0161694 | search | 16ms | 2026-06-06T09:45:29 | |
| tc_b04cfa14 | search | 75ms | 2026-06-06T09:45:56 | |
| tc_556664bc | search | 119ms | 2026-06-06T09:45:57 | |
| tc_e1e7a8af | search | 97ms | 2026-06-06T09:45:57 | |
| tc_131fa565 | search | 543ms | 2026-06-06T09:45:58 | |
| tc_96b935fa | search | 61ms | 2026-06-06T09:46:06 | |
| tc_e4af112e | get_raw_output | 34470ms | 2026-06-06T09:46:41 | |
| tc_17612d38 | search | 90ms | 2026-06-06T09:46:44 | |
| tc_ed842d68 | get_raw_output | 3510ms | 2026-06-06T09:46:56 | |
| tc_7c2abe8c | search | 806ms | 2026-06-06T09:46:57 | |
| tc_7a398143 | search | 318ms | 2026-06-06T09:46:57 | |
| tc_4f7f2bef | search | 61ms | 2026-06-06T09:46:57 | |
| tc_9a7e94f6 | search | 268ms | 2026-06-06T09:47:12 | |
| tc_5cba6078 | search | 3380ms | 2026-06-06T09:47:16 | |
| tc_a19152b0 | search | 110ms | 2026-06-06T09:47:32 | |
| tc_e5fc73e7 | search | 41ms | 2026-06-06T09:47:33 | |
| tc_3266235d | search | 37ms | 2026-06-06T09:47:33 | |
| tc_2b68df97 | search | 42ms | 2026-06-06T09:47:33 | |
| tc_6b948bf9 | search | 336ms | 2026-06-06T09:48:05 | |
| tc_6cb3e6c6 | get_raw_output | 31400ms | 2026-06-06T09:48:36 | |
| tc_5dcc2763 | search | 815ms | 2026-06-06T09:48:37 | |
| tc_cb33e02b | search | 35ms | 2026-06-06T09:48:50 | |
| tc_5efe7b9a | search | 2625ms | 2026-06-06T09:48:52 | |
| tc_d7949753 | get_raw_output | 926ms | 2026-06-06T09:49:03 | |
| tc_e0b86d84 | search | 69ms | 2026-06-06T09:49:03 | |
| tc_e8b2f175 | search | 35ms | 2026-06-06T09:49:03 | |
| tc_06e8ff8e | search | 26ms | 2026-06-06T09:49:26 | |
| tc_3ecae655 | search | 261ms | 2026-06-06T09:49:27 | |
| tc_4a8309da | search | 709ms | 2026-06-06T09:49:28 | |
| tc_ba235578 | search | 91ms | 2026-06-06T09:49:58 | |
| tc_c083512f | search | 59ms | 2026-06-06T09:49:58 | |
| tc_4c4b6a93 | search | 23ms | 2026-06-06T09:49:58 | |
| tc_577a6d84 | detect_timestomping | 9534ms | 2026-06-06T09:50:08 | |
| tc_d6d6040c | get_raw_output | 24391ms | 2026-06-06T09:50:41 | |
| tc_1d805e0a | search | 94ms | 2026-06-06T09:50:41 | |
| tc_8b677aaa | get_deleted_files | 7309ms | 2026-06-06T09:50:48 | |
| tc_1d6e7b11 | get_findings | 30ms | 2026-06-06T09:51:17 | |
| tc_6492ef7f | search | 112ms | 2026-06-06T09:51:28 | |
| tc_6fe1de22 | search | 548ms | 2026-06-06T09:51:30 | |
| tc_b02416fa | search | 34ms | 2026-06-06T09:51:30 | |
| tc_796b4828 | triage_binary | 302ms | 2026-06-06T09:53:30 | |
| tc_29561007 | search | 608ms | 2026-06-06T09:53:31 | |
| tc_cfba6703 | search | 49ms | 2026-06-06T09:53:31 | |
| tc_d3126b8b | extract_file_by_inode | 328ms | 2026-06-06T09:53:58 | |
| tc_56b81ec0 | run_volatility_batch | 1266932ms | 2026-06-06T09:54:16 | |
| tc_0a181906 | get_raw_output | 37906ms | 2026-06-06T09:54:36 | |
| tc_6edabdcc | search | 268ms | 2026-06-06T09:54:36 | |
| tc_ab2a13f3 | search | 208ms | 2026-06-06T09:55:12 | |
| tc_f3b1d43d | search | 11055ms | 2026-06-06T09:55:23 | |
| tc_f456c2e7 | search | 151ms | 2026-06-06T09:55:32 | |
| tc_16188147 | search | 25ms | 2026-06-06T09:55:32 | |
| tc_cd399173 | submit_finding | 8ms | 2026-06-06T09:56:14 | |
| tc_4e069cdf | submit_finding | 15ms | 2026-06-06T09:56:24 | |
| tc_c65e851a | submit_finding | 8ms | 2026-06-06T09:56:41 | |
| tc_14b522c1 | submit_finding | 7ms | 2026-06-06T09:56:50 | |
| tc_b06ebd7c | submit_finding | 7ms | 2026-06-06T09:57:06 | |
| tc_d3ee5963 | submit_finding | 8ms | 2026-06-06T09:57:19 | |
| tc_c48e48c8 | submit_finding | 7ms | 2026-06-06T09:57:39 | |
| tc_6a5544ea | search | 150ms | 2026-06-06T09:57:39 | |
| tc_c6714440 | run_volatility_batch | 1474346ms | 2026-06-06T09:57:44 | |
| tc_7cd6b96f | search | 223ms | 2026-06-06T09:57:48 | |
| tc_ec68fab4 | search | 121ms | 2026-06-06T09:57:49 | |
| tc_3f734ef1 | search | 343ms | 2026-06-06T09:57:49 | |
| tc_66105ca8 | search | 693ms | 2026-06-06T09:57:59 | |
| tc_312d150b | search | 48ms | 2026-06-06T09:57:59 | |
| tc_42304342 | search | 1884ms | 2026-06-06T09:58:01 | |
| tc_88f94100 | search | 51ms | 2026-06-06T09:58:12 | |
| tc_7a5f7db9 | search | 2461ms | 2026-06-06T09:58:15 | |
| tc_6c385b23 | submit_finding | 16ms | 2026-06-06T09:58:41 | |
| tc_beae086f | run_volatility_batch | 1541895ms | 2026-06-06T09:58:51 | |
| tc_144e6aa9 | get_completed_results | 0ms | 2026-06-06T09:58:57 | |
| tc_a72c8a43 | submit_finding | 12ms | 2026-06-06T09:58:59 | |
| tc_8b5110c0 | track_progress | 11ms | 2026-06-06T09:59:22 | |
| tc_7321b41a | get_investigation_summary | 21ms | 2026-06-06T10:00:09 | |
| tc_c4696c33 | yara_scan_memory | 101293ms | 2026-06-06T10:00:42 | |
| tc_4d2a49d6 | open_case | 23ms | 2026-06-06T10:00:47 | |
| tc_6aa9179d | get_investigation_summary | 33ms | 2026-06-06T10:00:52 | |
| tc_4d6ffb1d | list_sources | 10ms | 2026-06-06T10:00:52 | |
| tc_f1a903c2 | search | 456ms | 2026-06-06T10:01:00 | |
| tc_561d2e69 | open_case | 43ms | 2026-06-06T10:01:03 | |
| tc_6a37f932 | wait_all | 0ms | 2026-06-06T10:01:03 | |
| tc_fdd5b9b0 | search | 70ms | 2026-06-06T10:01:10 | |
| tc_5f0fc523 | open_case | 22ms | 2026-06-06T10:01:23 | |
| tc_ec4e7479 | get_investigation_summary | 45ms | 2026-06-06T10:01:27 | |
| tc_685d5637 | list_sources | 11ms | 2026-06-06T10:01:27 | |
| tc_fe0646d8 | search | 140ms | 2026-06-06T10:01:36 | |
| tc_9096ff34 | search | 2122ms | 2026-06-06T10:01:39 | |
| tc_03b4c266 | search | 343ms | 2026-06-06T10:01:40 | |
| tc_8815f683 | search | 104ms | 2026-06-06T10:01:40 | |
| tc_a87b431c | get_source_stats | 30373ms | 2026-06-06T10:01:40 | |
| tc_9e034750 | list_directory | 18ms | 2026-06-06T10:01:55 | |
| tc_6e6aafd4 | list_directory | 16ms | 2026-06-06T10:02:02 | |
| tc_e7744506 | get_source_stats | 29020ms | 2026-06-06T10:02:16 | |
| tc_43fea313 | search | 129ms | 2026-06-06T10:02:52 | |
| tc_4cbbb36a | search | 79ms | 2026-06-06T10:02:52 | |
| tc_aacc9f1a | search | 78ms | 2026-06-06T10:02:53 | |
| tc_d5219ff9 | search | 76ms | 2026-06-06T10:02:54 | |
| tc_fce2032b | search | 88ms | 2026-06-06T10:02:54 | |
| tc_80882858 | list_sources | 25ms | 2026-06-06T10:02:59 | |
| tc_749736d2 | search | 2467ms | 2026-06-06T10:03:02 | |
| tc_0e72fb11 | search | 62ms | 2026-06-06T10:03:02 | |
| tc_c248043c | search | 6ms | 2026-06-06T10:03:02 | |
| tc_bc650ee2 | search | 6ms | 2026-06-06T10:03:02 | |
| tc_d5c0a356 | search | 6ms | 2026-06-06T10:03:02 | |
| tc_4c6faf82 | search | 1093ms | 2026-06-06T10:03:03 | |
| tc_37b47d67 | search | 1013ms | 2026-06-06T10:03:04 | |
| tc_66fe0fcf | search | 222ms | 2026-06-06T10:03:05 | |
| tc_2eca78ff | search | 8ms | 2026-06-06T10:03:05 | |
| tc_7b148889 | search | 857ms | 2026-06-06T10:03:05 | |
| tc_78350b5c | search | 31025ms | 2026-06-06T10:03:05 | |
| tc_dbafa152 | search | 385ms | 2026-06-06T10:03:05 | |
| tc_08023a85 | search | 46ms | 2026-06-06T10:03:05 | |
| tc_55effc9b | search | 294ms | 2026-06-06T10:03:05 | |
| tc_0ffed909 | search | 73ms | 2026-06-06T10:03:06 | |
| tc_39c403ca | search | 60ms | 2026-06-06T10:03:06 | |
| tc_dc53a579 | search | 82ms | 2026-06-06T10:03:06 | |
| tc_7b033701 | search | 84ms | 2026-06-06T10:03:07 | |
| tc_0d9fc57b | search | 50ms | 2026-06-06T10:03:07 | |
| tc_97de55e5 | search | 70ms | 2026-06-06T10:03:07 | |
| tc_1d5a7a0a | search | 32ms | 2026-06-06T10:03:07 | |
| tc_06326d5b | search | 79ms | 2026-06-06T10:03:08 | |
| tc_cd71fc63 | search | 28ms | 2026-06-06T10:03:08 | |
| tc_2c1be445 | get_findings | 14ms | 2026-06-06T10:03:08 | |
| tc_e2adfed7 | search | 36ms | 2026-06-06T10:03:08 | |
| tc_716fdd0c | search | 5ms | 2026-06-06T10:03:09 | |
| tc_8ebec980 | search | 5ms | 2026-06-06T10:03:09 | |
| tc_69ea0394 | search | 5ms | 2026-06-06T10:03:10 | |
| tc_8bde66ac | search | 6ms | 2026-06-06T10:03:10 | |
| tc_30c27baa | search | 7ms | 2026-06-06T10:03:10 | |
| tc_7f3cc489 | scan_hidden_processes | 32ms | 2026-06-06T10:03:10 | |
| tc_80a4cbc4 | scan_kernel_modules | 20ms | 2026-06-06T10:03:11 | |
| tc_0272f7e9 | search | 3343ms | 2026-06-06T10:03:11 | |
| tc_f0cc944d | list_sources | 26ms | 2026-06-06T10:03:14 | |
| tc_e9a95985 | search | 161ms | 2026-06-06T10:03:16 | |
| tc_f2df639f | list_sources | 27ms | 2026-06-06T10:03:19 | |
| tc_b396d3d3 | get_raw_output | 1893ms | 2026-06-06T10:03:19 | |
| tc_833ce6ae | search | 82ms | 2026-06-06T10:03:19 | |
| tc_bdb783fd | search | 86ms | 2026-06-06T10:03:19 | |
| tc_a13cd137 | search | 9ms | 2026-06-06T10:03:19 | |
| tc_7fab7a0f | list_directory | 6ms | 2026-06-06T10:03:19 | |
| tc_14497df1 | search | 220ms | 2026-06-06T10:03:20 | |
| tc_09c472fe | list_directory | 6ms | 2026-06-06T10:03:20 | |
| tc_21073175 | search | 100ms | 2026-06-06T10:03:20 | |
| tc_65bceb37 | search | 95ms | 2026-06-06T10:03:20 | |
| tc_eae53dd5 | get_process_tree | 58ms | 2026-06-06T10:03:21 | |
| tc_f71aacff | list_processes_from_memory | 24ms | 2026-06-06T10:03:21 | |
| tc_157c85fa | search | 4850ms | 2026-06-06T10:03:25 | |
| tc_14a026bc | search | 365ms | 2026-06-06T10:03:28 | |
| tc_cf37c3d6 | search | 13ms | 2026-06-06T10:03:29 | |
| tc_9ab468c6 | search | 26ms | 2026-06-06T10:03:29 | |
| tc_021512e3 | list_directory | 9ms | 2026-06-06T10:03:32 | |
| tc_ce9b2750 | search | 17723ms | 2026-06-06T10:03:34 | |
| tc_a2be401f | search | 130ms | 2026-06-06T10:03:34 | |
| tc_00c26494 | run_volatility_batch | 0ms | 2026-06-06T10:03:39 | |
| tc_23aaf781 | search | 19102ms | 2026-06-06T10:03:40 | |
| tc_8576ee3d | search | 466ms | 2026-06-06T10:03:43 | |
| tc_a27adb93 | search | 37ms | 2026-06-06T10:03:43 | |
| tc_f9897235 | get_investigation_summary | 15ms | 2026-06-06T10:03:43 | |
| tc_82177d7b | open_case | 38ms | 2026-06-06T10:03:44 | |
| tc_7ccb52cf | extract_archive | 5ms | 2026-06-06T10:03:44 | |
| tc_2d353007 | extract_archive | 3ms | 2026-06-06T10:03:45 | |
| tc_f5582e2b | extract_archive | 2ms | 2026-06-06T10:03:45 | |
| tc_8663d127 | get_raw_output | 1260ms | 2026-06-06T10:03:48 | |
| tc_1e3a6b78 | search | 155ms | 2026-06-06T10:03:48 | |
| tc_3ae24443 | search | 17ms | 2026-06-06T10:03:48 | |
| tc_dbd19020 | search | 19ms | 2026-06-06T10:03:49 | |
| tc_dbd24d1c | search | 3093ms | 2026-06-06T10:03:49 | |
| tc_fdcde275 | search | 89ms | 2026-06-06T10:03:50 | |
| tc_cab780ab | search | 796ms | 2026-06-06T10:03:50 | |
| tc_ade941c6 | search | 7ms | 2026-06-06T10:03:50 | |
| tc_12514556 | search | 99ms | 2026-06-06T10:03:50 | |
| tc_de8b5656 | search | 125ms | 2026-06-06T10:03:50 | |
| tc_9241208c | search | 6ms | 2026-06-06T10:03:51 | |
| tc_5e1cbf3d | search | 11ms | 2026-06-06T10:03:51 | |
| tc_bc66baf6 | search | 1179ms | 2026-06-06T10:03:52 | |
| tc_3219ef27 | list_directory | 5ms | 2026-06-06T10:03:52 | |
| tc_ff263cbb | search | 36ms | 2026-06-06T10:03:52 | |
| tc_aeaa4cb2 | start_extraction_batch | 147ms | 2026-06-06T10:03:57 | |
| tc_0c1b7b1c | get_raw_output | 1552ms | 2026-06-06T10:04:00 | |
| tc_08933611 | get_raw_output | 78ms | 2026-06-06T10:04:00 | |
| tc_90cc1c7e | search | 170ms | 2026-06-06T10:04:00 | |
| tc_dba2d114 | search | 69ms | 2026-06-06T10:04:00 | |
| tc_6c130500 | get_raw_output | 83ms | 2026-06-06T10:04:00 | |
| tc_f808bd64 | search | 12ms | 2026-06-06T10:04:00 | |
| tc_018f3b6e | list_directory | 5ms | 2026-06-06T10:04:01 | |
| tc_4908e26e | search | 12ms | 2026-06-06T10:04:01 | |
| tc_c9b68406 | list_directory | 4ms | 2026-06-06T10:04:01 | |
| tc_4adb620a | list_directory | 10ms | 2026-06-06T10:04:08 | |
| tc_295ab417 | get_raw_output | 76ms | 2026-06-06T10:04:08 | |
| tc_c75f1805 | search | 77ms | 2026-06-06T10:04:09 | |
| tc_3db43a2f | search | 6ms | 2026-06-06T10:04:09 | |
| tc_c90d0e14 | get_raw_output | 76ms | 2026-06-06T10:04:09 | |
| tc_c1b0a556 | search | 26ms | 2026-06-06T10:04:09 | |
| tc_a64bd7a8 | search | 465ms | 2026-06-06T10:04:15 | |
| tc_4a62d77d | get_raw_output | 43939ms | 2026-06-06T10:04:29 | |
| tc_981d2942 | get_source_stats | 42399ms | 2026-06-06T10:04:29 | |
| tc_a70489d3 | get_raw_output | 79ms | 2026-06-06T10:04:29 | |
| tc_a059436c | list_directory | 8ms | 2026-06-06T10:04:32 | |
| tc_7fb18fd4 | get_raw_output | 1848ms | 2026-06-06T10:04:33 | |
| tc_847b771a | get_raw_output | 3765ms | 2026-06-06T10:04:33 | |
| tc_540525c3 | get_source_stats | 18077ms | 2026-06-06T10:04:33 | |
| tc_bf37c2b3 | get_raw_output | 270ms | 2026-06-06T10:04:34 | |
| tc_68d09d35 | list_directory | 44ms | 2026-06-06T10:04:38 | |
| tc_87025930 | list_directory | 4ms | 2026-06-06T10:04:38 | |
| tc_d4be05c6 | search | 153ms | 2026-06-06T10:04:39 | |
| tc_257f5fed | search | 118ms | 2026-06-06T10:04:43 | |
| tc_c4f1dda0 | search | 41ms | 2026-06-06T10:04:44 | |
| tc_2dd9aeac | list_directory | 11ms | 2026-06-06T10:04:46 | |
| tc_1bbd1cf9 | search | 2629ms | 2026-06-06T10:04:47 | |
| tc_82b01a67 | search | 232ms | 2026-06-06T10:04:47 | |
| tc_57d37375 | run_volatility_batch | 0ms | 2026-06-06T10:04:53 | |
| tc_c99ca150 | search | 309ms | 2026-06-06T10:04:55 | |
| tc_0281669a | search | 139ms | 2026-06-06T10:04:56 | |
| tc_476c9c61 | search | 7ms | 2026-06-06T10:04:57 | |
| tc_0aa5781a | search | 5951ms | 2026-06-06T10:05:04 | |
| tc_401f23b8 | get_raw_output | 1483ms | 2026-06-06T10:05:12 | |
| tc_dd4280ae | search | 762ms | 2026-06-06T10:05:13 | |
| tc_040b221a | search | 378ms | 2026-06-06T10:05:14 | |
| tc_ec703c4d | get_raw_output | 32063ms | 2026-06-06T10:05:20 | |
| tc_e5000cad | search | 1631ms | 2026-06-06T10:05:25 | |
| tc_e2945dd0 | get_raw_output | 31584ms | 2026-06-06T10:05:56 | |
| tc_f948ee98 | get_raw_output | 27999ms | 2026-06-06T10:05:56 | |
| tc_4048fe94 | search | 710ms | 2026-06-06T10:06:00 | |
| tc_9d25e588 | search | 296ms | 2026-06-06T10:06:00 | |
| tc_51f7511a | search | 136ms | 2026-06-06T10:06:00 | |
| tc_8c95f7e6 | search | 196ms | 2026-06-06T10:06:07 | |
| tc_45b15c7f | search | 76ms | 2026-06-06T10:06:08 | |
| tc_08b0c2a4 | search | 235ms | 2026-06-06T10:06:09 | |
| tc_dbc1fe1f | search | 1113ms | 2026-06-06T10:06:10 | |
| tc_d9029b81 | search | 190ms | 2026-06-06T10:06:18 | |
| tc_11f1b786 | search | 3205ms | 2026-06-06T10:06:21 | |
| tc_488523dc | run_volatility_batch | 122465ms | 2026-06-06T10:07:00 | |
| tc_47fe06d8 | search | 85ms | 2026-06-06T10:07:08 | |
| tc_b5f4aa01 | search | 24ms | 2026-06-06T10:07:08 | |
| tc_f7323eb2 | search | 31ms | 2026-06-06T10:07:08 | |
| tc_299f1b7c | search | 11ms | 2026-06-06T10:07:28 | |
| tc_0fe91c77 | get_raw_output | 30609ms | 2026-06-06T10:07:59 | |
| tc_09f62339 | search | 885ms | 2026-06-06T10:08:47 | |
| tc_6643d924 | get_raw_output | 42467ms | 2026-06-06T10:09:30 | |
| tc_c77ea118 | get_raw_output | 2542ms | 2026-06-06T10:09:42 | |
| tc_f5b4775f | get_raw_output | 31530ms | 2026-06-06T10:10:14 | |
| tc_feacba0b | search | 805ms | 2026-06-06T10:10:25 | |
| tc_cf7df671 | search | 202ms | 2026-06-06T10:10:25 | |
| tc_ee55499e | search | 3010ms | 2026-06-06T10:10:28 | |
| tc_6a045b01 | search | 133ms | 2026-06-06T10:10:37 | |
| tc_5fce4d87 | search | 49ms | 2026-06-06T10:10:38 | |
| tc_2bb01a39 | search | 45ms | 2026-06-06T10:10:38 | |
| tc_555bbf4a | run_volatility_batch | 424834ms | 2026-06-06T10:11:02 | |
| tc_19489c7d | open_case | 15ms | 2026-06-06T10:12:28 | |
| tc_502d8b7f | get_investigation_summary | 23ms | 2026-06-06T10:12:34 | |
| tc_e941c650 | get_findings | 5ms | 2026-06-06T10:12:34 | |
| tc_5b080140 | get_source_stats | 29452ms | 2026-06-06T10:13:03 | |
| tc_e411bc09 | get_findings | 5ms | 2026-06-06T10:13:12 | |
| tc_68261b80 | get_findings | 5ms | 2026-06-06T10:13:12 | |
| tc_d2203371 | get_bookmarks | 5ms | 2026-06-06T10:13:24 | |
| tc_c7d4184c | search | 38ms | 2026-06-06T10:13:24 | |
| tc_5a675fcb | search | 112ms | 2026-06-06T10:13:34 | |
| tc_b8c927e5 | search | 72ms | 2026-06-06T10:13:34 | |
| tc_9af581b0 | search | 33ms | 2026-06-06T10:13:44 | |
| tc_62d62ffd | search | 2856ms | 2026-06-06T10:13:47 | |
| tc_19c435b0 | search | 793ms | 2026-06-06T10:14:02 | |
| tc_66808333 | search | 230ms | 2026-06-06T10:14:02 | |
| tc_b685a0a5 | search | 95ms | 2026-06-06T10:14:24 | |
| tc_885cf743 | search | 28ms | 2026-06-06T10:14:26 | |
| tc_67037ef5 | search | 46ms | 2026-06-06T10:14:38 | |
| tc_d9ef5d3c | search | 315ms | 2026-06-06T10:14:39 | |
| tc_aeae3c99 | get_raw_output | 720ms | 2026-06-06T10:14:50 | |
| tc_3808d8ea | search | 171ms | 2026-06-06T10:14:50 | |
| tc_2e69cfc8 | search | 370ms | 2026-06-06T10:15:18 | |
| tc_2b4ffb94 | search | 45ms | 2026-06-06T10:15:19 | |
| tc_94019da7 | get_raw_output | 748ms | 2026-06-06T10:15:27 | |
| tc_a99601d8 | search | 89ms | 2026-06-06T10:15:27 | |
| tc_d750604e | update_finding | 12ms | 2026-06-06T10:16:08 | |
| tc_63ec0187 | update_finding | 10ms | 2026-06-06T10:16:08 | |
| tc_cf11ebb6 | update_finding | 12ms | 2026-06-06T10:16:09 | |
| tc_b81c0eeb | submit_finding | 10ms | 2026-06-06T10:16:29 | |
| tc_12d8de90 | submit_finding | 8ms | 2026-06-06T10:16:48 | |
| tc_c280846d | submit_finding | 10ms | 2026-06-06T10:17:09 | |
| tc_a51aced2 | update_finding | 12ms | 2026-06-06T10:17:15 | |
| tc_30405990 | submit_finding | 9ms | 2026-06-06T10:17:43 | |
| tc_7b5ab96c | update_finding | 8ms | 2026-06-06T10:17:49 | |
| tc_bf294aee | search | 73ms | 2026-06-06T10:17:50 | |
| tc_9f2ba1ed | search | 70ms | 2026-06-06T10:17:59 | |
| tc_5b5cc5bb | search | 370ms | 2026-06-06T10:17:59 | |
| tc_14375e22 | get_raw_output | 776ms | 2026-06-06T10:18:14 | |
| tc_8982d31b | search | 862ms | 2026-06-06T10:18:15 | |
| tc_d9425d94 | submit_finding | 9ms | 2026-06-06T10:18:44 | |
| tc_a3674760 | search | 834ms | 2026-06-06T10:20:35 | |
| tc_58e4dd0d | search | 369ms | 2026-06-06T10:20:36 | |
| tc_72083e0e | search | 376ms | 2026-06-06T10:20:36 | |
| tc_a6cca9b9 | update_finding | 11ms | 2026-06-06T10:20:44 | |
| tc_e38defe1 | get_source_stats | 28993ms | 2026-06-06T10:21:13 | |
| tc_dfd5eccd | search | 234ms | 2026-06-06T10:21:23 | |
| tc_7b9c3efc | search | 607ms | 2026-06-06T10:21:24 | |
| tc_00920e2c | search | 851ms | 2026-06-06T10:21:45 | |
| tc_f998a908 | search | 68ms | 2026-06-06T10:21:45 | |
| tc_52762417 | search | 258ms | 2026-06-06T10:22:17 | |
| tc_46254594 | search | 1339ms | 2026-06-06T10:22:18 | |
| tc_aaae333d | get_raw_output | 4078ms | 2026-06-06T10:22:41 | |
| tc_0dcee2c9 | search | 381ms | 2026-06-06T10:23:02 | |
| tc_52f7599d | decode_payload | 0ms | 2026-06-06T10:25:00 | |
| tc_b48924db | search | 62ms | 2026-06-06T10:25:14 | |
| tc_ed6dcd46 | search | 344ms | 2026-06-06T10:25:15 | |
| tc_8b5703fa | submit_finding | 14ms | 2026-06-06T10:25:57 | |
| tc_69bf6e17 | run_volatility_batch | 1323744ms | 2026-06-06T10:26:01 | |
| tc_ebd773a5 | get_raw_output | 727ms | 2026-06-06T10:26:06 | |
| tc_80506846 | submit_finding | 9ms | 2026-06-06T10:26:39 | |
| tc_08547015 | update_finding | 10ms | 2026-06-06T10:26:59 | |
| tc_0428ec25 | run_volatility_batch | 1388673ms | 2026-06-06T10:27:05 | |
| tc_a0b4b81f | track_progress | 11ms | 2026-06-06T10:27:17 | |
| tc_2223d1b8 | get_investigation_summary | 19ms | 2026-06-06T10:27:34 | |
| tc_de4075cb | run_volatility_batch | 1432907ms | 2026-06-06T10:27:50 | |
| tc_3c6a00be | get_completed_results | 0ms | 2026-06-06T10:27:56 | |
| tc_bc35685e | open_case | 13ms | 2026-06-06T10:28:03 | |
| tc_41c463cf | list_directory | 6ms | 2026-06-06T10:28:10 | |
| tc_ecf1b02c | list_directory | 4ms | 2026-06-06T10:28:15 | |
| tc_304d8b35 | list_sources | 14ms | 2026-06-06T10:28:25 | |
| tc_06bc283d | list_directory | 4ms | 2026-06-06T10:28:27 | |
| tc_80954be6 | list_directory | 4ms | 2026-06-06T10:28:33 | |
| tc_a0c02f68 | list_directory | 4ms | 2026-06-06T10:28:34 | |
| tc_6fd2ec9b | list_directory | 4ms | 2026-06-06T10:28:35 | |
| tc_1b3839a4 | list_directory | 4ms | 2026-06-06T10:28:35 | |
| tc_bb55cd7c | search | 113ms | 2026-06-06T10:28:42 | |
| tc_485a6000 | search | 110ms | 2026-06-06T10:28:42 | |
| tc_54b4c351 | search | 52ms | 2026-06-06T10:28:43 | |
| tc_e44c8bee | search | 42ms | 2026-06-06T10:28:43 | |
| tc_cccb3900 | get_source_stats | 30474ms | 2026-06-06T10:29:25 | |
| tc_e2d5ea7a | yara_scan_memory | 103533ms | 2026-06-06T10:29:44 | |
| tc_7575ca10 | open_case | 44ms | 2026-06-06T10:30:00 | |
| tc_4b4c3154 | wait_all | 0ms | 2026-06-06T10:30:01 | |
| tc_0bd326e8 | open_case | 22ms | 2026-06-06T10:30:25 | |
| tc_ac37ab37 | get_investigation_summary | 40ms | 2026-06-06T10:30:29 | |
| tc_a83a3f04 | open_case | 25ms | 2026-06-06T10:30:49 | |
| tc_6cd295ba | get_source_stats | 27113ms | 2026-06-06T10:30:56 | |
| tc_b2ce3910 | start_extraction_batch | 34ms | 2026-06-06T10:30:58 | |
| tc_8229494b | search | 378ms | 2026-06-06T10:31:07 | |
| tc_8ce30e07 | search | 139ms | 2026-06-06T10:31:08 | |
| tc_aed187fa | search | 134ms | 2026-06-06T10:31:08 | |
| tc_5c9cfdae | search | 139ms | 2026-06-06T10:31:09 | |
| tc_912529b3 | list_sources | 15ms | 2026-06-06T10:31:15 | |
| tc_05a33f0d | search | 344ms | 2026-06-06T10:31:30 | |
| tc_7587fac6 | get_raw_output | 26590ms | 2026-06-06T10:32:17 | |
| tc_e56fa5ec | search | 102ms | 2026-06-06T10:32:35 | |
| tc_d9208dec | search | 86ms | 2026-06-06T10:32:36 | |
| tc_0f12456a | search | 54ms | 2026-06-06T10:32:36 | |
| tc_9070c1cb | search | 37ms | 2026-06-06T10:32:51 | |
| tc_4d47022d | search | 1534ms | 2026-06-06T10:32:53 | |
| tc_733cfb01 | search | 2541ms | 2026-06-06T10:32:56 | |
| tc_7f73be3b | get_findings | 12ms | 2026-06-06T10:33:19 | |
| tc_d30cde46 | search | 1344ms | 2026-06-06T10:33:21 | |
| tc_a56ca10e | search | 91ms | 2026-06-06T10:33:55 | |
| tc_c001fd33 | search | 141ms | 2026-06-06T10:33:56 | |
| tc_f833ab4b | search | 167ms | 2026-06-06T10:33:56 | |
| tc_ff133965 | get_raw_output | 858ms | 2026-06-06T10:34:30 | |
| tc_321deca2 | get_raw_output | 20065ms | 2026-06-06T10:34:50 | |
| tc_24e27d3c | decode_payload | 0ms | 2026-06-06T10:35:33 | |
| tc_40efe655 | search | 80ms | 2026-06-06T10:35:33 | |
| tc_c4f93619 | decode_payload | 1ms | 2026-06-06T10:35:40 | |
| tc_7896bbde | search | 106ms | 2026-06-06T10:35:40 | |
| tc_a8df8353 | search | 44ms | 2026-06-06T10:36:28 | |
| tc_f7914606 | decode_payload | 120ms | 2026-06-06T10:36:28 | |
| tc_8cac8cc4 | scan_hidden_processes | 86ms | 2026-06-06T10:37:05 | |
| tc_dd1cc8eb | search | 754ms | 2026-06-06T10:37:06 | |
| tc_33400b38 | search | 122ms | 2026-06-06T10:39:23 | |
| tc_d6159c69 | search | 116ms | 2026-06-06T10:39:24 | |
| tc_bf72b446 | search | 1803ms | 2026-06-06T10:39:26 | |
| tc_f9bfbab6 | run_volatility_batch | 520769ms | 2026-06-06T10:39:39 | |
| tc_59d084a3 | search | 107ms | 2026-06-06T10:40:01 | |
| tc_ca6a4a98 | search | 293ms | 2026-06-06T10:40:02 | |
| tc_32e6cd38 | search | 119ms | 2026-06-06T10:40:02 | |
| tc_1ec62a19 | submit_finding | 78ms | 2026-06-06T10:40:59 | |
| tc_b23fd3f0 | submit_finding | 14ms | 2026-06-06T10:41:13 | |
| tc_9625dbc4 | submit_finding | 13ms | 2026-06-06T10:41:29 | |
| tc_660586d3 | submit_finding | 9ms | 2026-06-06T10:41:44 | |
| tc_ddb139ca | submit_finding | 78ms | 2026-06-06T10:42:01 | |
| tc_0b8ecc5e | search | 1996ms | 2026-06-06T10:42:08 | |
| tc_6535f63e | search | 27374ms | 2026-06-06T10:42:36 | |
| tc_b05f90a7 | submit_finding | 10ms | 2026-06-06T10:43:11 | |
| tc_ed625f8b | submit_finding | 8ms | 2026-06-06T10:43:19 | |
| tc_7e72c60e | submit_finding | 9ms | 2026-06-06T10:43:37 | |
| tc_4e3c86a3 | search | 60ms | 2026-06-06T10:43:42 | |
| tc_0d5ab1cf | search | 493ms | 2026-06-06T10:43:43 | |
| tc_bc894c34 | get_findings | 15ms | 2026-06-06T10:43:57 | |
| tc_f5172ece | run_volatility_batch | 784880ms | 2026-06-06T10:44:03 | |
| tc_f65c6bfa | submit_finding | 30ms | 2026-06-06T10:44:23 | |
| tc_8f187757 | track_progress | 12ms | 2026-06-06T10:44:34 | |
| tc_de714144 | track_progress | 7ms | 2026-06-06T10:44:40 | |
| tc_504ca4b9 | track_progress | 9ms | 2026-06-06T10:44:45 | |
| tc_69ce26f0 | track_progress | 7ms | 2026-06-06T10:44:48 | |
| tc_ed0aad19 | get_investigation_summary | 30ms | 2026-06-06T10:45:16 | |
| tc_40ea1c9e | scan_evidence | 33ms | 2026-06-06T10:45:40 | |
| tc_d32b8f13 | list_directory | 5ms | 2026-06-06T10:47:01 | |
| tc_5418491f | list_directory | 4ms | 2026-06-06T10:47:02 | |
| tc_7463c5ce | list_directory | 4ms | 2026-06-06T10:47:07 | |
| tc_b712b051 | list_sources | 16ms | 2026-06-06T10:47:07 | |
| tc_2f696cd5 | search | 126ms | 2026-06-06T10:47:19 | |
| tc_c6166898 | search | 33ms | 2026-06-06T10:47:19 | |
| tc_98b9bdd9 | open_case | 13ms | 2026-06-06T10:48:04 | |
| tc_e3664473 | start_extraction_batch | 17ms | 2026-06-06T10:48:13 | |
| tc_ae9c90b5 | start_extraction_batch | 7ms | 2026-06-06T10:48:14 | |
| tc_f257179a | run_volatility_batch | 1277987ms | 2026-06-06T10:52:16 | |
| tc_7cdd6f99 | run_volatility_batch | 294094ms | 2026-06-06T10:53:08 | |
| tc_a23b456d | run_volatility_batch | 1355367ms | 2026-06-06T10:53:34 | |
| tc_afdb8418 | get_completed_results | 0ms | 2026-06-06T10:53:39 | |
| tc_73f03b2a | start_extraction_batch | 1ms | 2026-06-06T10:53:45 | |
| tc_4fbd9fa6 | yara_scan_memory | 104694ms | 2026-06-06T10:55:29 | |
| tc_9cedcd66 | get_completed_results | 0ms | 2026-06-06T10:55:35 | |
| tc_75a75919 | open_case | 13ms | 2026-06-06T10:55:57 | |
| tc_ea75fc72 | get_investigation_summary | 31ms | 2026-06-06T10:56:01 | |
| tc_ff6cf472 | get_source_stats | 32506ms | 2026-06-06T10:56:33 | |
| tc_b73b5753 | find_suspicious_processes._query(volatility.malfind) | 1147ms | 2026-06-06T10:56:45 | |
| tc_8d7c49cf | find_suspicious_processes._query(volatility.cmdline) | 309ms | 2026-06-06T10:56:46 | |
| tc_ce4d0f70 | find_suspicious_processes._query(volatility.netscan) | 306ms | 2026-06-06T10:56:46 | |
| tc_74f9ba4f | find_suspicious_processes._query(volatility.pstree) | 296ms | 2026-06-06T10:56:46 | |
| tc_3608e3de | find_suspicious_processes._query(volatility.psscan) | 297ms | 2026-06-06T10:56:47 | |
| tc_c2a7fc79 | find_suspicious_processes._query(volatility.pslist) | 288ms | 2026-06-06T10:56:47 | |
| tc_06e27325 | find_suspicious_processes._query(volatility.dlllist) | 476ms | 2026-06-06T10:56:47 | |
| tc_1d5fbc0a | find_suspicious_processes | 3135ms | 2026-06-06T10:56:47 | |
| tc_a1bfd54a | scan_hidden_processes | 18ms | 2026-06-06T10:56:47 | |
| tc_0e2dd863 | scan_kernel_modules | 23ms | 2026-06-06T10:56:48 | |
| tc_38db20cd | get_process_tree | 8ms | 2026-06-06T10:56:48 | |
| tc_1703568f | run_volatility_batch | 528624ms | 2026-06-06T10:57:01 | |
| tc_a7d6fd4f | search | 340ms | 2026-06-06T10:57:03 | |
| tc_893b5f27 | search | 35ms | 2026-06-06T10:57:04 | |
| tc_e33d659f | wait_all | 526746ms | 2026-06-06T10:57:06 | |
| tc_9f7ab972 | search | 4495ms | 2026-06-06T10:57:09 | |
| tc_c4cc059a | get_completed_results | 0ms | 2026-06-06T10:57:11 | |
| tc_ccf11d45 | get_completed_results | 0ms | 2026-06-06T10:57:11 | |
| tc_f6ca3eae | start_extraction_batch | 2ms | 2026-06-06T10:57:18 | |
| tc_591d2f4e | decode_payload | 0ms | 2026-06-06T10:57:26 | |
| tc_1ad04615 | search | 262ms | 2026-06-06T10:57:27 | |
| tc_5ed8bd30 | search | 2944ms | 2026-06-06T10:57:30 | |
| tc_1016aad4 | get_findings | 18ms | 2026-06-06T10:57:48 | |
| tc_1234cc57 | get_raw_output | 7675ms | 2026-06-06T10:57:56 | |
| tc_96bb9770 | get_findings | 23ms | 2026-06-06T10:58:09 | |
| tc_c42e70b6 | search | 256ms | 2026-06-06T10:58:10 | |
| tc_6bfbd5bc | get_findings | 11ms | 2026-06-06T10:58:19 | |
| tc_d8c74751 | search | 675ms | 2026-06-06T10:58:20 | |
| tc_fdcffe26 | yara_scan_memory | 100538ms | 2026-06-06T10:58:59 | |
| tc_b7c4e4e4 | get_completed_results | 0ms | 2026-06-06T10:59:03 | |
| tc_e3a9646d | open_case | 36ms | 2026-06-06T10:59:19 | |
| tc_a6e0c304 | wait_all | 0ms | 2026-06-06T10:59:19 | |
| tc_d08ad382 | open_case | 40ms | 2026-06-06T10:59:32 | |
| tc_9909e506 | get_investigation_summary | 29ms | 2026-06-06T10:59:36 | |
| tc_47eb0eb4 | list_sources | 6ms | 2026-06-06T10:59:36 | |
| tc_643ad9f1 | search | 100ms | 2026-06-06T10:59:45 | |
| tc_485d5ff0 | search | 42ms | 2026-06-06T10:59:45 | |
| tc_26239521 | search | 57ms | 2026-06-06T10:59:46 | |
| tc_27791d9c | search | 29ms | 2026-06-06T10:59:46 | |
| tc_4bce530b | get_source_stats | 27838ms | 2026-06-06T11:00:20 | |
| tc_b76fbf1a | search | 237ms | 2026-06-06T11:00:27 | |
| tc_39e0d78b | search | 190ms | 2026-06-06T11:00:27 | |
| tc_404a87e2 | search | 60ms | 2026-06-06T11:00:35 | |
| tc_dfcb0f68 | search | 47ms | 2026-06-06T11:00:35 | |
| tc_52f9dda3 | search | 54ms | 2026-06-06T11:00:35 | |
| tc_aa5c57a1 | search | 60ms | 2026-06-06T11:00:36 | |
| tc_7453df17 | get_raw_output | 817ms | 2026-06-06T11:00:53 | |
| tc_bc36392e | get_raw_output | 200ms | 2026-06-06T11:00:53 | |
| tc_0b5bea30 | search | 61ms | 2026-06-06T11:01:03 | |
| tc_3c53397f | search | 27ms | 2026-06-06T11:01:03 | |
| tc_6b6edb55 | search | 423ms | 2026-06-06T11:01:14 | |
| tc_f7d37834 | search | 249ms | 2026-06-06T11:01:42 | |
| tc_85169414 | search | 1868ms | 2026-06-06T11:01:44 | |
| tc_abe2c884 | search | 2368ms | 2026-06-06T11:01:46 | |
| tc_680895e6 | get_raw_output | 28511ms | 2026-06-06T11:01:46 | |
| tc_fdca035b | search | 197ms | 2026-06-06T11:02:16 | |
| tc_0eb9ba08 | search | 757ms | 2026-06-06T11:02:17 | |
| tc_12bcc4dd | get_raw_output | 27764ms | 2026-06-06T11:02:30 | |
| tc_2b13d181 | get_raw_output | 1553ms | 2026-06-06T11:02:45 | |
| tc_ad9401aa | search | 3738ms | 2026-06-06T11:02:49 | |
| tc_90c42a95 | get_raw_output | 20075ms | 2026-06-06T11:02:53 | |
| tc_b3de379c | search | 1915ms | 2026-06-06T11:03:23 | |
| tc_825e18aa | get_raw_output | 28610ms | 2026-06-06T11:03:24 | |
| tc_af127c6b | get_raw_output | 1210ms | 2026-06-06T11:03:24 | |
| tc_331b14d7 | get_raw_output | 6453ms | 2026-06-06T11:03:32 | |
| tc_c7614a06 | search | 2215ms | 2026-06-06T11:03:46 | |
| tc_5e0d937a | search | 84ms | 2026-06-06T11:03:46 | |
| tc_bff17e5c | search | 60ms | 2026-06-06T11:03:46 | |
| tc_1e2f0885 | search | 355ms | 2026-06-06T11:03:46 | |
| tc_a016152c | search | 352ms | 2026-06-06T11:04:02 | |
| tc_2961a14c | search | 259ms | 2026-06-06T11:04:02 | |
| tc_b811da6f | search | 202ms | 2026-06-06T11:04:03 | |
| tc_c923ab2d | search | 71ms | 2026-06-06T11:04:05 | |
| tc_98e68c1e | search | 50ms | 2026-06-06T11:04:06 | |
| tc_5b1fe50b | search | 28ms | 2026-06-06T11:04:06 | |
| tc_1254b33f | search | 972ms | 2026-06-06T11:04:19 | |
| tc_097f363f | search | 82ms | 2026-06-06T11:04:19 | |
| tc_eb5e6b69 | decode_payload | 2ms | 2026-06-06T11:04:25 | |
| tc_3a32c805 | scan_hidden_processes | 24ms | 2026-06-06T11:04:25 | |
| tc_98d2bf03 | search | 49ms | 2026-06-06T11:04:26 | |
| tc_f70a7d55 | search | 31ms | 2026-06-06T11:04:26 | |
| tc_20a2f3ee | search | 434ms | 2026-06-06T11:04:55 | |
| tc_44b5269e | search | 230ms | 2026-06-06T11:04:55 | |
| tc_5888f2c4 | get_raw_output | 686ms | 2026-06-06T11:04:56 | |
| tc_8c87be03 | submit_finding | 21ms | 2026-06-06T11:05:20 | |
| tc_3168c4d4 | submit_finding | 16ms | 2026-06-06T11:05:44 | |
| tc_633899f6 | get_findings | 17ms | 2026-06-06T11:05:47 | |
| tc_9be1c5b1 | search | 84ms | 2026-06-06T11:05:48 | |
| tc_2be2ca6e | submit_finding | 15ms | 2026-06-06T11:06:04 | |
| tc_20be659f | get_findings | 12ms | 2026-06-06T11:06:33 | |
| tc_f6c98bd4 | search | 248ms | 2026-06-06T11:06:34 | |
| tc_d2d2060a | search | 890ms | 2026-06-06T11:06:41 | |
| tc_6f993ee2 | search | 70ms | 2026-06-06T11:06:41 | |
| tc_9afbec68 | get_raw_output | 703ms | 2026-06-06T11:07:09 | |
| tc_33ba5844 | get_findings | 23ms | 2026-06-06T11:08:40 | |
| tc_2728a7ed | list_sources | 13ms | 2026-06-06T11:08:40 | |
| tc_30873166 | get_findings | 9ms | 2026-06-06T11:08:50 | |
| tc_5c10a69d | search | 83ms | 2026-06-06T11:09:07 | |
| tc_ca6adb56 | search | 28ms | 2026-06-06T11:09:07 | |
| tc_1cdd895e | get_source_stats | 27517ms | 2026-06-06T11:09:43 | |
| tc_d29b904f | search | 420ms | 2026-06-06T11:09:48 | |
| tc_91cea853 | search | 51ms | 2026-06-06T11:09:48 | |
| tc_5880fc44 | get_raw_output | 673ms | 2026-06-06T11:10:16 | |
| tc_77d906a0 | search | 195ms | 2026-06-06T11:10:16 | |
| tc_287cc0bf | search | 177ms | 2026-06-06T11:10:55 | |
| tc_c3c902c7 | search | 50ms | 2026-06-06T11:10:55 | |
| tc_99349433 | submit_finding | 17ms | 2026-06-06T11:11:07 | |
| tc_9d7d16e2 | track_progress | 16ms | 2026-06-06T11:11:20 | |
| tc_8d4bff6c | track_progress | 16ms | 2026-06-06T11:11:26 | |
| tc_7c00cab7 | track_progress | 16ms | 2026-06-06T11:11:30 | |
| tc_9070d6e6 | track_progress | 12ms | 2026-06-06T11:11:33 | |
| tc_83e0936f | get_raw_output | 228ms | 2026-06-06T11:11:43 | |
| tc_c1b348a4 | search | 2584ms | 2026-06-06T11:11:47 | |
| tc_14a57b65 | get_investigation_summary | 20ms | 2026-06-06T11:12:31 | |
| tc_2fed88d5 | search | 115ms | 2026-06-06T11:13:01 | |
| tc_9ec85f58 | search | 85ms | 2026-06-06T11:13:02 | |
| tc_11f47952 | search | 28ms | 2026-06-06T11:13:12 | |
| tc_ccaff221 | search | 27ms | 2026-06-06T11:13:12 | |
| tc_c0090a5e | search | 186ms | 2026-06-06T11:13:23 | |
| tc_833d340e | search | 138ms | 2026-06-06T11:13:23 | |
| tc_84df7239 | search | 1280ms | 2026-06-06T11:13:49 | |
| tc_63b64e47 | get_raw_output | 700ms | 2026-06-06T11:13:49 | |
| tc_8dd53546 | submit_finding | 22ms | 2026-06-06T11:14:50 | |
| tc_1ac54180 | submit_finding | 15ms | 2026-06-06T11:15:14 | |
| tc_ce1ce787 | submit_finding | 14ms | 2026-06-06T11:15:44 | |
| tc_b13fb556 | search | 44ms | 2026-06-06T11:17:44 | |
| tc_4abd8c0a | scan_hidden_processes | 36ms | 2026-06-06T11:17:44 | |
| tc_cdb728e6 | search | 631ms | 2026-06-06T11:17:45 | |
| tc_028a9484 | search | 212ms | 2026-06-06T11:17:45 | |
| tc_6b5931e5 | search | 93ms | 2026-06-06T11:18:05 | |
| tc_7da335ae | search | 51ms | 2026-06-06T11:18:05 | |
| tc_96531f90 | search | 813ms | 2026-06-06T11:18:07 | |
| tc_a4de5c67 | search | 397ms | 2026-06-06T11:18:15 | |
| tc_fcd06883 | track_progress | 14ms | 2026-06-06T11:18:47 | |
| tc_b05bbd67 | track_progress | 15ms | 2026-06-06T11:18:53 | |
| tc_4a5d2e1f | get_investigation_summary | 22ms | 2026-06-06T11:19:19 | |
| tc_7ee7a3e8 | open_case | 22ms | 2026-06-06T11:19:31 | |
| tc_80616df8 | get_findings | 15ms | 2026-06-06T11:19:35 | |
| tc_1431a169 | get_investigation_summary | 27ms | 2026-06-06T11:19:36 | |
| tc_5463b892 | get_source_stats | 27796ms | 2026-06-06T11:20:04 | |
| tc_79cf68dd | get_bookmarks | 4ms | 2026-06-06T11:20:06 | |
| tc_95dfe2b7 | get_findings | 10ms | 2026-06-06T11:20:13 | |
| tc_7e5afe35 | get_findings | 9ms | 2026-06-06T11:20:13 | |
| tc_5e5aebcd | get_findings | 9ms | 2026-06-06T11:20:13 | |
| tc_fe1cf1a6 | get_timeline | 1692ms | 2026-06-06T11:20:16 | |
| tc_802b9021 | list_sources | 13ms | 2026-06-06T11:20:16 | |
| tc_323c0cb3 | get_ioc_summary | 21865ms | 2026-06-06T11:21:10 | |
| tc_16f783b6 | open_case | 22ms | 2026-06-06T11:22:42 | |
| tc_d5c62e06 | correlate_across_sources | 270ms | 2026-06-06T11:22:48 | |
| tc_158cc432 | correlate_across_sources | 1060ms | 2026-06-06T11:22:49 | |
| tc_b1efd0f0 | correlate_across_sources | 149ms | 2026-06-06T11:22:52 | |
| tc_57e20305 | correlate_across_sources | 73ms | 2026-06-06T11:22:52 | |
| tc_e3da7bfa | correlate_across_sources | 298ms | 2026-06-06T11:22:52 | |
| tc_24853f2b | find_lateral_movement_indicators._search(all) | 107ms | 2026-06-06T11:22:52 | |
| tc_41d92d21 | find_lateral_movement_indicators._search(all) | 34ms | 2026-06-06T11:22:52 | |
| tc_f9383e7e | find_lateral_movement_indicators._search(all) | 48ms | 2026-06-06T11:22:52 | |
| tc_4096eafd | find_lateral_movement_indicators._query(volatility.netscan) | 592ms | 2026-06-06T11:22:53 | |
| tc_d4882a38 | find_lateral_movement_indicators._search(all) | 45ms | 2026-06-06T11:22:53 | |
| tc_7174a1e5 | find_lateral_movement_indicators._search(all) | 25ms | 2026-06-06T11:22:53 | |
| tc_8e005962 | find_lateral_movement_indicators._search(all) | 61ms | 2026-06-06T11:22:53 | |
| tc_58375581 | find_lateral_movement_indicators | 922ms | 2026-06-06T11:22:53 | |
| tc_b6e1ae9b | find_persistence_mechanisms._query(registry.system) | 758ms | 2026-06-06T11:22:54 | |
| tc_4cb5d031 | find_persistence_mechanisms._query(registry.software) | 423ms | 2026-06-06T11:22:54 | |
| tc_b8f824dd | find_persistence_mechanisms._query(volatility.svcscan) | 329ms | 2026-06-06T11:22:55 | |
| tc_bc6b8226 | find_persistence_mechanisms._search(all) | 38ms | 2026-06-06T11:22:55 | |
| tc_845feccc | find_persistence_mechanisms._search(all) | 29ms | 2026-06-06T11:22:55 | |
| tc_22479b9d | find_persistence_mechanisms._query(ez.amcache) | 276ms | 2026-06-06T11:22:55 | |
| tc_56470c5f | find_persistence_mechanisms._search(all) | 45ms | 2026-06-06T11:22:55 | |
| tc_803e7145 | find_persistence_mechanisms._query(tsk.filelist) | 1662ms | 2026-06-06T11:22:57 | |
| tc_9d6b7343 | find_persistence_mechanisms | 3927ms | 2026-06-06T11:22:57 | |
| tc_da6f0c80 | find_data_exfiltration_indicators._query(bulk.url) | 7270ms | 2026-06-06T11:23:10 | |
| tc_802a38db | find_data_exfiltration_indicators._query(bulk.email) | 1720ms | 2026-06-06T11:23:21 | |
| tc_6f871dde | find_data_exfiltration_indicators._query(bulk.domain) | 4090ms | 2026-06-06T11:23:25 | |
| tc_7ba60897 | find_data_exfiltration_indicators._query(volatility.netscan) | 341ms | 2026-06-06T11:23:31 | |
| tc_35e5b123 | find_data_exfiltration_indicators._search(all) | 82ms | 2026-06-06T11:23:31 | |
| tc_d60adc32 | find_data_exfiltration_indicators | 28488ms | 2026-06-06T11:23:31 | |
| tc_14529128 | open_case | 47ms | 2026-06-06T11:24:08 | |
| tc_f541f830 | find_data_exfiltration_indicators._query(bulk.url) | 6760ms | 2026-06-06T11:24:24 | |
| tc_06681b96 | find_data_exfiltration_indicators._query(bulk.email) | 1663ms | 2026-06-06T11:24:35 | |
| tc_15c9672c | find_data_exfiltration_indicators._query(bulk.domain) | 4188ms | 2026-06-06T11:24:39 | |
| tc_919d27f8 | find_data_exfiltration_indicators._query(volatility.netscan) | 347ms | 2026-06-06T11:24:45 | |
| tc_77a25f16 | find_data_exfiltration_indicators._search(all) | 58ms | 2026-06-06T11:24:45 | |
| tc_c370fca9 | find_data_exfiltration_indicators | 27998ms | 2026-06-06T11:24:45 | |
| tc_3b340190 | open_case | 45ms | 2026-06-06T11:25:15 | |
| tc_7f83a47b | find_defense_evasion._search(all) | 39ms | 2026-06-06T11:25:20 | |
| tc_3fb8a25b | find_defense_evasion._search(ez.mft) | 21ms | 2026-06-06T11:25:20 | |
| tc_031230b8 | find_defense_evasion._search(all) | 26ms | 2026-06-06T11:25:20 | |
| tc_610d9906 | find_defense_evasion._search(all) | 12ms | 2026-06-06T11:25:20 | |
| tc_27d61159 | find_defense_evasion._query(volatility.psscan) | 286ms | 2026-06-06T11:25:21 | |
| tc_ef779b6b | find_defense_evasion._query(volatility.pslist) | 280ms | 2026-06-06T11:25:21 | |
| tc_0d2feddc | find_defense_evasion._search(all) | 25ms | 2026-06-06T11:25:21 | |
| tc_a7dc09fc | find_defense_evasion._query(volatility.cmdline) | 274ms | 2026-06-06T11:25:21 | |
| tc_147b731e | find_defense_evasion | 970ms | 2026-06-06T11:25:21 | |
| tc_db6e03b4 | find_suspicious_processes._query(volatility.malfind) | 322ms | 2026-06-06T11:25:26 | |
| tc_b0e1c20b | find_suspicious_processes._query(volatility.cmdline) | 282ms | 2026-06-06T11:25:27 | |
| tc_649dd7f2 | find_suspicious_processes._query(volatility.netscan) | 284ms | 2026-06-06T11:25:27 | |
| tc_d6c41391 | find_suspicious_processes._query(volatility.pstree) | 295ms | 2026-06-06T11:25:27 | |
| tc_c5db7b13 | find_suspicious_processes._query(volatility.psscan) | 277ms | 2026-06-06T11:25:27 | |
| tc_c46dc0fd | find_suspicious_processes._query(volatility.pslist) | 273ms | 2026-06-06T11:25:28 | |
| tc_01fa5372 | find_suspicious_processes._query(volatility.dlllist) | 415ms | 2026-06-06T11:25:28 | |
| tc_6873efbd | find_suspicious_processes | 2168ms | 2026-06-06T11:25:28 | |
| tc_18e402b0 | reconstruct_execution_chains._query(volatility.pstree) | 330ms | 2026-06-06T11:25:34 | |
| tc_e52be2d3 | reconstruct_execution_chains._query(volatility.cmdline) | 285ms | 2026-06-06T11:25:34 | |
| tc_b94ac69e | reconstruct_execution_chains._query(volatility.netscan) | 282ms | 2026-06-06T11:25:34 | |
| tc_1dccb69b | reconstruct_execution_chains._query(volatility.malfind) | 285ms | 2026-06-06T11:25:35 | |
| tc_c292a272 | reconstruct_execution_chains._query(volatility.dlllist) | 332ms | 2026-06-06T11:25:35 | |
| tc_bce334e9 | reconstruct_execution_chains | 1525ms | 2026-06-06T11:25:35 | |
| tc_5d167450 | find_execution_evidence._query(ez.amcache) | 318ms | 2026-06-06T11:25:40 | |
| tc_2762ceaf | find_execution_evidence._query(volatility.pstree) | 277ms | 2026-06-06T11:25:40 | |
| tc_e878a530 | find_execution_evidence | 603ms | 2026-06-06T11:25:40 | |
| tc_65cfd05b | analyze_execution_timeline._query(ez.amcache) | 286ms | 2026-06-06T11:25:47 | |
| tc_3dbe656e | analyze_execution_timeline | 348ms | 2026-06-06T11:25:47 | |
| tc_58288a36 | find_file_staging._search(tsk.filelist) | 24ms | 2026-06-06T11:25:53 | |
| tc_a0c14bd0 | find_file_staging._search(ez.mft) | 12ms | 2026-06-06T11:25:53 | |
| tc_3557b964 | find_file_staging._query(tsk.filelist) | 1039ms | 2026-06-06T11:25:54 | |
| tc_6dc52e55 | find_file_staging._query(ez.mft) | 5497ms | 2026-06-06T11:26:01 | |
| tc_f79e5ac8 | find_file_staging._search(ez.mft) | 85ms | 2026-06-06T11:26:04 | |
| tc_1ba9d440 | find_file_staging._search(ez.mft) | 34ms | 2026-06-06T11:26:04 | |
| tc_9d7b5e06 | find_file_staging | 11481ms | 2026-06-06T11:26:04 | |
| tc_c0d7bb5c | find_data_exfiltration_indicators._query(bulk.url) | 6744ms | 2026-06-06T11:26:21 | |
| tc_a1bb19eb | find_data_exfiltration_indicators._query(bulk.email) | 1565ms | 2026-06-06T11:26:33 | |
| tc_eb76e6ce | find_data_exfiltration_indicators._query(bulk.domain) | 4176ms | 2026-06-06T11:26:37 | |
| tc_d7bcb918 | find_data_exfiltration_indicators._query(volatility.netscan) | 336ms | 2026-06-06T11:26:42 | |
| tc_fe6c027d | find_data_exfiltration_indicators._search(all) | 53ms | 2026-06-06T11:26:42 | |
| tc_f27093bf | find_data_exfiltration_indicators | 27850ms | 2026-06-06T11:26:42 | |
| tc_3d4c91e7 | open_case | 44ms | 2026-06-06T11:27:08 | |
| tc_30d9c9ad | assess_recovery._query(tsk.filelist) | 1088ms | 2026-06-06T11:27:14 | |
| tc_f7411768 | assess_recovery._query(ez.amcache) | 290ms | 2026-06-06T11:27:15 | |
| tc_dee8dd3c | assess_recovery | 1445ms | 2026-06-06T11:27:15 | |
| tc_302fe7f1 | open_case | 27ms | 2026-06-06T11:27:48 | |
| tc_8c8e986d | get_investigation_summary | 29ms | 2026-06-06T11:27:52 | |
| tc_12c6d32f | get_findings | 7ms | 2026-06-06T11:27:52 | |
| tc_c3b3a5d0 | get_findings | 13ms | 2026-06-06T11:27:58 | |
| tc_3398c111 | get_findings | 8ms | 2026-06-06T11:27:59 | |
| tc_3dc764c6 | get_findings | 9ms | 2026-06-06T11:27:59 | |
| tc_d5ada384 | get_source_stats | 7420ms | 2026-06-06T11:28:07 | |
| tc_4b86da2a | get_raw_output | 5340ms | 2026-06-06T11:28:24 | |
| tc_62c039de | get_raw_output | 5770ms | 2026-06-06T11:28:32 | |
| tc_ae4fb9de | get_raw_output | 2021ms | 2026-06-06T11:28:34 | |
| tc_052d6977 | get_raw_output | 5663ms | 2026-06-06T11:28:42 | |
| tc_2b9a42c4 | get_raw_output | 5722ms | 2026-06-06T11:28:54 | |
| tc_af18430f | get_raw_output | 5388ms | 2026-06-06T11:28:59 | |
| tc_357b3d4d | get_raw_output | 5604ms | 2026-06-06T11:29:05 | |
| tc_3cb7bcf2 | get_raw_output | 5619ms | 2026-06-06T11:29:10 | |
| tc_2af66614 | deduplicate_findings | 240ms | 2026-06-06T11:29:29 | |
| tc_a0f5fa3b | get_ioc_summary | 12771ms | 2026-06-06T11:29:42 | |
| tc_d2732e48 | lookup_attack_technique | 167ms | 2026-06-06T11:29:42 | |
| tc_2be887c9 | deduplicate_findings | 320ms | 2026-06-06T11:29:57 | |
| tc_c10f5388 | search | 880ms | 2026-06-06T11:31:25 | |
| tc_a217d119 | search | 541ms | 2026-06-06T11:31:26 | |
| tc_d4c18198 | search | 26ms | 2026-06-06T11:31:26 | |
| tc_480dcd7b | search | 59ms | 2026-06-06T11:31:26 | |
| tc_3b68cd88 | search | 152ms | 2026-06-06T11:31:34 | |
| tc_782e4ed1 | search | 66ms | 2026-06-06T11:31:34 | |
| tc_57843b2b | search | 47ms | 2026-06-06T11:31:35 | |
| tc_66c827bb | search | 96ms | 2026-06-06T11:31:54 | |
| tc_c0650def | search | 208ms | 2026-06-06T11:31:54 | |
| tc_2dcacf45 | submit_finding | 19ms | 2026-06-06T11:32:23 | |
| tc_421e9c52 | submit_finding | 17ms | 2026-06-06T11:32:30 | |
| tc_d0dcd445 | submit_finding | 11ms | 2026-06-06T11:32:42 | |
| tc_e870cd4c | submit_finding | 10ms | 2026-06-06T11:32:50 | |
| tc_e5a4cfc8 | get_findings | 10ms | 2026-06-06T11:32:57 | |
| tc_b1fd395c | get_findings | 5ms | 2026-06-06T11:32:57 | |
| tc_74ec245e | get_findings | 6ms | 2026-06-06T11:32:57 | |
| tc_3ead028a | get_findings | 11ms | 2026-06-06T11:33:04 | |
| tc_f6bc1d73 | deduplicate_findings | 172ms | 2026-06-06T11:33:19 | |
| tc_7272efb0 | deduplicate_findings | 174ms | 2026-06-06T11:33:37 | |
| tc_cdfd34f4 | delete_finding | 5ms | 2026-06-06T11:33:37 | |
| tc_05fe0c27 | delete_finding | 15ms | 2026-06-06T11:33:38 | |
| tc_5aa5894d | delete_finding | 11ms | 2026-06-06T11:33:38 | |
| tc_58c91e02 | delete_finding | 14ms | 2026-06-06T11:33:50 | |
| tc_fa31b025 | delete_finding | 11ms | 2026-06-06T11:33:51 | |
| tc_ed8354c6 | update_finding | 23ms | 2026-06-06T11:33:52 | |
| tc_9b3fcd0e | update_finding | 14ms | 2026-06-06T11:33:53 | |
| tc_49c64fd2 | delete_finding | 10ms | 2026-06-06T11:34:04 | |
| tc_67e4fbe3 | update_finding | 19ms | 2026-06-06T11:34:25 | |
| tc_4c1feb51 | get_investigation_summary | 31ms | 2026-06-06T11:35:04 | |
| tc_addeb2f0 | update_finding | 16ms | 2026-06-06T11:35:18 | |
| tc_97eb2506 | update_finding | 17ms | 2026-06-06T11:35:18 | |
| tc_3c856548 | update_finding | 17ms | 2026-06-06T11:35:19 | |
| tc_aaeb53d5 | update_finding | 18ms | 2026-06-06T11:35:19 | |
| tc_706c2770 | update_finding | 17ms | 2026-06-06T11:35:20 | |
| tc_3e2ca87e | update_finding | 16ms | 2026-06-06T11:35:34 | |
| tc_21f22799 | update_finding | 18ms | 2026-06-06T11:35:35 | |
| tc_b7876a19 | update_finding | 23ms | 2026-06-06T11:35:36 | |
| tc_6c50eaa4 | update_finding | 11ms | 2026-06-06T11:35:36 | |
| tc_1c67ec9f | update_finding | 18ms | 2026-06-06T11:35:37 | |
| tc_76518afb | track_progress | 20ms | 2026-06-06T11:36:06 | |
| tc_61c9bb95 | get_investigation_summary | 18ms | 2026-06-06T11:36:27 | |
| tc_06b7f6a5 | open_case | 25ms | 2026-06-06T11:36:41 | |
| tc_5fb2d2f2 | get_findings | 16ms | 2026-06-06T11:36:45 | |
| tc_f41d5c17 | get_investigation_summary | 26ms | 2026-06-06T11:36:48 | |
| tc_7252b895 | list_sources | 8ms | 2026-06-06T11:36:48 | |
| tc_d61f3e35 | get_source_stats | 7632ms | 2026-06-06T11:37:08 | |
| tc_d760f4cb | get_findings | 8ms | 2026-06-06T11:37:16 | |
| tc_5ff90817 | get_timeline | 860ms | 2026-06-06T11:37:18 | |
| tc_f27b170d | open_case | 53ms | 2026-06-06T11:40:17 | |
| tc_cd0356ff | search | 736ms | 2026-06-06T11:40:24 | |
| tc_a26bd704 | search | 64ms | 2026-06-06T11:40:24 | |
| tc_c808ec26 | search | 82ms | 2026-06-06T11:40:24 | |
| tc_ab6417bb | search | 52ms | 2026-06-06T11:40:25 | |
| tc_c0acb15f | search | 53ms | 2026-06-06T11:40:26 | |
| tc_93850a34 | search | 43ms | 2026-06-06T11:40:26 | |
| tc_00701064 | search | 646ms | 2026-06-06T11:40:28 | |
| tc_89e38835 | search | 42ms | 2026-06-06T11:40:28 | |
| tc_a20e4200 | search | 339ms | 2026-06-06T11:40:29 | |
| tc_a1cee6d4 | search | 25ms | 2026-06-06T11:40:29 | |
| tc_f4ba8aba | search | 29ms | 2026-06-06T11:40:29 | |
| tc_fce8320a | search | 38ms | 2026-06-06T11:40:30 | |
| tc_a4e458a8 | search | 29ms | 2026-06-06T11:40:31 | |
| tc_625e5254 | search | 75ms | 2026-06-06T11:40:31 | |
| tc_00cbe93f | search | 35ms | 2026-06-06T11:40:32 | |
| tc_9c6ddce6 | search | 34ms | 2026-06-06T11:40:33 | |
| tc_8acd8cce | search | 87ms | 2026-06-06T11:40:33 | |
| tc_61122b91 | search | 201ms | 2026-06-06T11:40:34 | |
| tc_4ee83e78 | search | 181ms | 2026-06-06T11:40:35 | |
| tc_4114917b | search | 174ms | 2026-06-06T11:40:35 | |
| tc_fe6151ad | search | 34ms | 2026-06-06T11:40:36 | |
| tc_66643fdb | search | 928ms | 2026-06-06T11:40:38 | |
| tc_bb0c3035 | search | 42ms | 2026-06-06T11:40:38 | |
| tc_32c5f412 | search | 36ms | 2026-06-06T11:40:38 | |
| tc_8e4a62bf | search | 29ms | 2026-06-06T11:40:39 | |
| tc_49c20841 | search | 173ms | 2026-06-06T11:40:40 | |
| tc_5bb9a5c2 | search | 647ms | 2026-06-06T11:40:40 | |
| tc_0936e47d | correlate_across_sources | 299ms | 2026-06-06T11:40:50 | |
| tc_7942fd70 | correlate_across_sources | 33ms | 2026-06-06T11:40:50 | |
| tc_e5880213 | correlate_across_sources | 44ms | 2026-06-06T11:40:51 | |
| tc_8ec00495 | audit_evidence_coverage | 50131ms | 2026-06-06T11:41:42 | |
| tc_658f4219 | audit_tool_coverage | 9ms | 2026-06-06T11:41:44 | |
| tc_03363eb8 | deduplicate_findings | 122ms | 2026-06-06T11:41:45 | |
| tc_e20971da | check_finalize_readiness | 14ms | 2026-06-06T11:41:45 | |
| tc_f1302cc3 | open_case | 37ms | 2026-06-06T11:42:23 | |
| tc_bae74a8b | get_findings | 12ms | 2026-06-06T11:42:24 | |
| tc_0096f9ff | get_findings | 12ms | 2026-06-06T11:42:29 | |
| tc_c1c73b5a | get_findings | 5ms | 2026-06-06T11:42:29 | |
| tc_704fa783 | search | 66ms | 2026-06-06T11:43:18 | |
| tc_40f1e98b | search | 48ms | 2026-06-06T11:43:18 | |
| tc_5d94d271 | search | 36ms | 2026-06-06T11:43:19 | |
| tc_fde07b21 | search | 25ms | 2026-06-06T11:43:19 | |
| tc_47e08b46 | search | 49ms | 2026-06-06T11:43:26 | |
| tc_659471d6 | search | 16ms | 2026-06-06T11:43:26 | |
| tc_b0339770 | search | 41ms | 2026-06-06T11:43:27 | |
| tc_a490d0c7 | search | 67ms | 2026-06-06T11:43:27 | |
| tc_1b522a45 | search | 40ms | 2026-06-06T11:43:36 | |
| tc_f5079c54 | search | 39ms | 2026-06-06T11:43:36 | |
| tc_d44a9882 | search | 48ms | 2026-06-06T11:43:37 | |
| tc_d4383fee | search | 141ms | 2026-06-06T11:44:07 | |
| tc_5ff0c40e | search | 233ms | 2026-06-06T11:44:08 | |
| tc_c60eff1e | deduplicate_findings | 147ms | 2026-06-06T11:44:09 | |
| tc_a1c23d0f | get_raw_output | 249ms | 2026-06-06T11:44:59 | |
| tc_745592f2 | search | 56ms | 2026-06-06T11:44:59 | |
| tc_2b5457b7 | update_finding | 23ms | 2026-06-06T11:45:57 | |
| tc_b77fdd69 | update_finding | 14ms | 2026-06-06T11:46:20 | |
| tc_7a27dfe0 | update_finding | 10ms | 2026-06-06T11:46:33 | |
| tc_5fdb37ea | update_finding | 18ms | 2026-06-06T11:47:01 | |
| tc_ab06a77c | update_finding | 18ms | 2026-06-06T11:47:13 | |
| tc_e0e7554a | update_finding | 17ms | 2026-06-06T11:47:42 | |
| tc_b4995764 | update_finding | 16ms | 2026-06-06T11:47:55 | |
| tc_a4abca92 | update_finding | 12ms | 2026-06-06T11:48:30 | |
| tc_fdeb1512 | update_finding | 15ms | 2026-06-06T11:48:45 | |
| tc_9355194b | update_finding | 18ms | 2026-06-06T11:48:58 | |
| tc_6e85d151 | update_finding | 17ms | 2026-06-06T11:49:09 | |
| tc_a837fa9a | audit_evidence_coverage | 48072ms | 2026-06-06T11:50:03 | |
| tc_5589278a | audit_tool_coverage | 11ms | 2026-06-06T11:50:05 | |
| tc_d816800f | check_finalize_readiness | 16ms | 2026-06-06T11:50:05 | |
| tc_2c4e2bc3 | track_progress | 21ms | 2026-06-06T11:50:57 | |
| tc_1309acf1 | get_investigation_summary | 19ms | 2026-06-06T11:51:41 | |
| tc_8603b871 | check_finalize_readiness | 15ms | 2026-06-06T11:51:41 | |
| tc_1e7ffd5b | open_case | 16ms | 2026-06-06T11:51:54 | |
| tc_f0b358c2 | get_findings | 16ms | 2026-06-06T11:52:00 | |
| tc_e7ad7d1f | get_investigation_summary | 18ms | 2026-06-06T11:52:03 | |
| tc_46670e69 | get_ioc_summary | 14359ms | 2026-06-06T11:52:17 | |
| tc_53c93eab | get_bookmarks | 51ms | 2026-06-06T11:52:17 | |
| tc_e7a7116e | get_source_stats | 10357ms | 2026-06-06T11:52:28 | |
| tc_c6c9dcae | get_findings | 8ms | 2026-06-06T11:52:47 | |
| tc_ef07eca7 | submit_narrative | 19ms | 2026-06-06T11:56:47 | |
| tc_a981ade2 | check_finalize_readiness | 32ms | 2026-06-06T11:56:53 |
Each finding traces back to the specific tool calls that produced the supporting evidence.