Veritas
F023CRITICAL
PsExec and PWDumpX staging in Windows Temp directory
extract_mft_timelineget_amcacheparse_userassistrun_appcompatcacheparser
Confirmed malicious3 proofs
F004HIGH⚖ AI overruled
Suspicious executable p.exe staged in temp directory and executed
get_amcachevol_cmdlinevol_malfindvol_pstree
Suspicious50 proofs
F005MEDIUM⚖ AI overruled
PowerShell spawning cmd.exe to execute suspicious temp binary
vol_cmdlinevol_pstree
Suspicious50 proofs
F009MEDIUM⚖ AI overruled
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F015MEDIUM⚖ AI overruled
Subject_srv.exe persistent listener on port 3262 with remote connection
vol_cmdlinevol_netscanvol_pstree
Suspicious50 proofs
F027HIGH⚖ AI overruled
PowerShell spawning cmd.exe spawning staging executable (attack chain)
parse_event_logsvol_handlesvol_pstree
Suspicious50 proofs
F001MEDIUM
PowerShell process with multiple RWX memory regions indicating code injection
vol_handlesvol_malfindvol_psscanvol_pstree
Inconclusive50 proofs
F002MEDIUM
OUTLOOK.EXE process with RWX memory injection
vol_cmdlinevol_handlesvol_malfindvol_netscan+1
Inconclusive50 proofs
F003MEDIUM
UpdaterUI.exe process with RWX memory region
vol_cmdlinevol_handlesvol_malfindvol_psscan+1
Inconclusive50 proofs
F006MEDIUM
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F007MEDIUM
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F008MEDIUM
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F010MEDIUM
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F011MEDIUM
Multiple rundll32.exe instances with null command lines spawned from PowerShell child
vol_cmdlinevol_pstreevol_psxview
Suspicious50 proofs
F012MEDIUM
PsExec service infrastructure detected in registry and amcache
get_amcacheparse_registry_persistence
Inconclusive0 proofs
F014MEDIUM
PowerShell reflection-based code loading detected in event logs
parse_event_logs
Inconclusive0 proofs
F016
Multiple unowned TCP connections to 172.16.4.10 port 8080 in CLOSE_WAIT state
vol_netscan
Inconclusive0 proofs
F017
RDP lateral movement attempt to 172.16.4.5 port 3389
vol_netscan
Inconclusive0 proofs
F018
SMB connection to external host 172.16.7.15 port 445
vol_netscan
Inconclusive0 proofs
F019
SMB connection to internal host 172.16.6.14 port 445
vol_netscan
Inconclusive0 proofs
F020
DNS query to external IP 172.16.4.4 port 389 (LDAP)
vol_netscan
Inconclusive0 proofs
F021LOW
Dashlane.exe listening on localhost high port 49784
vol_cmdlinevol_handlesvol_netscanvol_pstree
Benign / FP50 proofs
F022
PsExec service registered in registry (PSEXESVC)
parse_registry_persistence
Inconclusive0 proofs
F024MEDIUM
Reflection-based PowerShell code injection detected in event logs
parse_event_logs
Inconclusive0 proofs
F025MEDIUM
Network connections to external IPs from unnamed/orphaned processes
vol_netscan
Inconclusive15 proofs
F026
SMB connections to internal network shares (lateral movement indicator)
vol_netscan
Inconclusive0 proofs
F028MEDIUM
NCPA (Nagios) monitoring agent executed from staging directory
extract_mft_timelineget_amcache
Inconclusive3 proofs
F029MEDIUM
RDP connections to multiple internal hosts from compromised system
vol_netscan
Benign / FP14 proofs
F030MEDIUM
PowerShell reflection-based code loading detected in event logs
parse_event_logs
Inconclusive0 proofs
F031CRITICAL
PsExecSvc service persistence with local system privilege
extract_mft_timelineget_amcacheparse_registry_persistencerun_appcompatcacheparser
Inconclusive3 proofs
F032MEDIUM
Explicit credential logon (Event 4648) from SYSTEM context to external accounts
parse_event_logs
Inconclusive0 proofs
F033
SafeBoot registry modification for persistence
parse_registry_persistence
Inconclusive0 proofs
F034
Conhost.exe with sensitive privileges and null command line
vol_cmdlinevol_privilegesvol_pstree
Inconclusive0 proofs
F035MEDIUM
Established connections to external IPs (13.89.220.65, 52.16.55.11) with CLOSED state
vol_netscan
Benign / FP6 proofs
F036MEDIUM
Credential dumping tool deployment (PWDumpX.exe, SysInternal tools)
extract_mft_timelineget_amcacherun_appcompatcacheparser
Inconclusive1 proofs
F037HIGH
PsExec service artifact in registry and amcache (Lateral Movement / Admin Tooling)
extract_mft_timelineget_amcacheparse_registry_persistencerun_appcompatcacheparser
Inconclusive3 proofs
F038MEDIUM
Suspicious PowerShell command with reflection load TTP (Code Evasion)
parse_event_logs
Inconclusive0 proofs
F039MEDIUM
Safe boot registry alternate shell persistence (Privilege Escalation / Persistence)
parse_registry_persistence
Inconclusive1 proofs
F040MEDIUM
Multiple DISMHOST.exe executions from temporary directories (Lateral Movement / Living off the Land)
extract_mft_timelineparse_event_logsrun_appcompatcacheparser
Inconclusive2 proofs
F041MEDIUM
WMIPrvSE.exe with SeImpersonatePrivilege enabled (Privilege Escalation / WMI Exploitation)
vol_privileges
Inconclusive0 proofs
F042MEDIUM
Conhost.exe with SeDebugPrivilege and SeImpersonatePrivilege (Privilege Escalation Context)
vol_privileges
Benign / FP0 proofs
F043
Multiple established connections to 172.16.4.10:8080 in CLOSE_WAIT state (Lateral Movement / C2 Staging)
vol_netscan
Inconclusive0 proofs
F044
Established connection to 172.16.6.14:445 (SMB lateral movement)
vol_netscan
Inconclusive0 proofs
F045
RDP connections to 172.16.4.5:3389 in CLOSED state (Lateral movement attempt)
vol_netscan
Inconclusive0 proofs
F046
Event log evidence of credential logon with SYSTEM context (Lateral Movement / Credential Theft)
parse_event_logs
Inconclusive0 proofs
F047HIGH
Multiple suspicious lolbin executions via AppCompatCache (Living off the Land / Defense Evasion)
extract_mft_timelineparse_event_logsparse_registry_persistenceparse_scheduled_tasks_disk+11
Synthesis3 proofs
F048MEDIUM
NCPA listener execution from temp directory (Lateral Movement / Living off the Land)
extract_mft_timelineget_amcacherun_appcompatcacheparser
Inconclusive3 proofs
F049MEDIUM
Setup completion script execution artifact (Persistence / Execution via Boot Scripts)
run_appcompatcacheparser
Inconclusive2 proofs
F050LOW
Jump List evidence of administrative tool access (Application Access History)
extract_mft_timelineextract_network_iocsparse_userassistrun_jlecmd+1
Benign / FP0 proofs
F051MEDIUM
Event log file clearance evidence (Anti-forensics / Defense Evasion)
parse_event_logs
Inconclusive0 proofs
F052
Summary: Multi-stage attack chain with code injection, credential theft, and lateral movement
extract_mft_timelineget_amcacheparse_event_logsparse_registry_persistence+4
Inconclusive0 proofs
F053MEDIUM
lateral movement admin share: ip:172.16.5.26
extract_network_iocsparse_event_logs
Suspicious19 proofs
F054MEDIUM
lateral movement admin share: ip:172.16.10.12
extract_network_iocsparse_event_logs
Suspicious19 proofs
F055MEDIUM
defense evasion anti forensics: event:1102 (audit log cleared) · microsoft-windows-eventlog
parse_event_logs
Suspicious1 proofs