F001MEDIUM
PowerShell process with multiple RWX memory regions indicating code injection
vol_handlesvol_malfindvol_psscanvol_pstree
Inconclusive50 proofs
F002MEDIUM
OUTLOOK.EXE process with RWX memory injection
vol_cmdlinevol_handlesvol_malfindvol_netscan+1
Inconclusive50 proofs
F003MEDIUM
UpdaterUI.exe process with RWX memory region
vol_cmdlinevol_handlesvol_malfindvol_psscan+1
Inconclusive50 proofs
F012MEDIUM
PsExec service infrastructure detected in registry and amcache
get_amcacheparse_registry_persistence
Inconclusive0 proofs
F014MEDIUM
PowerShell reflection-based code loading detected in event logs
parse_event_logs
Inconclusive0 proofs
F016
Multiple unowned TCP connections to 172.16.4.10 port 8080 in CLOSE_WAIT state
vol_netscan
Inconclusive0 proofs
F017
RDP lateral movement attempt to 172.16.4.5 port 3389
vol_netscan
Inconclusive0 proofs
F018
SMB connection to external host 172.16.7.15 port 445
vol_netscan
Inconclusive0 proofs
F019
SMB connection to internal host 172.16.6.14 port 445
vol_netscan
Inconclusive0 proofs
F020
DNS query to external IP 172.16.4.4 port 389 (LDAP)
vol_netscan
Inconclusive0 proofs
F022
PsExec service registered in registry (PSEXESVC)
parse_registry_persistence
Inconclusive0 proofs
F024MEDIUM
Reflection-based PowerShell code injection detected in event logs
parse_event_logs
Inconclusive0 proofs
F025MEDIUM
Network connections to external IPs from unnamed/orphaned processes
vol_netscan
Inconclusive15 proofs
F026
SMB connections to internal network shares (lateral movement indicator)
vol_netscan
Inconclusive0 proofs
F028MEDIUM
NCPA (Nagios) monitoring agent executed from staging directory
extract_mft_timelineget_amcache
Inconclusive3 proofs
F030MEDIUM
PowerShell reflection-based code loading detected in event logs
parse_event_logs
Inconclusive0 proofs
F031CRITICAL
PsExecSvc service persistence with local system privilege
extract_mft_timelineget_amcacheparse_registry_persistencerun_appcompatcacheparser
Inconclusive3 proofs
F032MEDIUM
Explicit credential logon (Event 4648) from SYSTEM context to external accounts
parse_event_logs
Inconclusive0 proofs
F033
SafeBoot registry modification for persistence
parse_registry_persistence
Inconclusive0 proofs
F034
Conhost.exe with sensitive privileges and null command line
vol_cmdlinevol_privilegesvol_pstree
Inconclusive0 proofs
F036MEDIUM
Credential dumping tool deployment (PWDumpX.exe, SysInternal tools)
extract_mft_timelineget_amcacherun_appcompatcacheparser
Inconclusive1 proofs
F037HIGH
PsExec service artifact in registry and amcache (Lateral Movement / Admin Tooling)
extract_mft_timelineget_amcacheparse_registry_persistencerun_appcompatcacheparser
Inconclusive3 proofs
F038MEDIUM
Suspicious PowerShell command with reflection load TTP (Code Evasion)
parse_event_logs
Inconclusive0 proofs
F039MEDIUM
Safe boot registry alternate shell persistence (Privilege Escalation / Persistence)
parse_registry_persistence
Inconclusive1 proofs
F040MEDIUM
Multiple DISMHOST.exe executions from temporary directories (Lateral Movement / Living off the Land)
extract_mft_timelineparse_event_logsrun_appcompatcacheparser
Inconclusive2 proofs
F041MEDIUM
WMIPrvSE.exe with SeImpersonatePrivilege enabled (Privilege Escalation / WMI Exploitation)
vol_privileges
Inconclusive0 proofs
F043
Multiple established connections to 172.16.4.10:8080 in CLOSE_WAIT state (Lateral Movement / C2 Staging)
vol_netscan
Inconclusive0 proofs
F044
Established connection to 172.16.6.14:445 (SMB lateral movement)
vol_netscan
Inconclusive0 proofs
F045
RDP connections to 172.16.4.5:3389 in CLOSED state (Lateral movement attempt)
vol_netscan
Inconclusive0 proofs
F046
Event log evidence of credential logon with SYSTEM context (Lateral Movement / Credential Theft)
parse_event_logs
Inconclusive0 proofs
F048MEDIUM
NCPA listener execution from temp directory (Lateral Movement / Living off the Land)
extract_mft_timelineget_amcacherun_appcompatcacheparser
Inconclusive3 proofs
F049MEDIUM
Setup completion script execution artifact (Persistence / Execution via Boot Scripts)
run_appcompatcacheparser
Inconclusive2 proofs
F051MEDIUM
Event log file clearance evidence (Anti-forensics / Defense Evasion)
parse_event_logs
Inconclusive0 proofs
F052
Summary: Multi-stage attack chain with code injection, credential theft, and lateral movement
extract_mft_timelineget_amcacheparse_event_logsparse_registry_persistence+4
Inconclusive0 proofs