Active Directory Takeover Intrusion Case Hub

DFIR Case File: SHIELDBASE.COM Enterprise Incident Triage & Volatile Memory Analysis

Critical Compromise
Case ID: INC-2023-01-24

🔬 Forensic Simulation Platform

Testing Notice: This is sample forensics used by AI to test AI capabilities.

Executive Correlation

Consolidated Incident Report

A unified correlation of browser history, security event logs, and kernel-level physical memory artifacts mapping the complete domain-wide takeover lifecycle.

  • Combines workstation staging and controller capture
  • Integrated Chronological Timeline (11 events)
  • Complete enterprise incident remediation playbook
Directory Services Triage

Active Directory Compromise

Deep dive analysis of the primary Domain Controller focusing on compromised administrative sessions and default GPO object manipulation indicators.

  • GPO GUID verified: {31B2F340-016D...}
  • Interactive Group Policy Editor process isolation
  • Analysis of hijacked admin account (rsydow-a)
Core Memory Volatility

Memory Forensics Dashboard

Interactive volatile memory analytics on the 9.4GB raw RAM dump, revealing active kernel-level processes, sockets, loaded hives, and malfind scans.

  • 125 active kernel-level processes parsed
  • 6,396 network sockets table with search controls
  • PAGE_EXECUTE_READWRITE code injection analysis
Event Log Auditing

Lateral Movement & Pivoting

Security event log reconstruction from the mounted client workstation, tracking how hijacked administrative credentials were used to gain access.

  • Audit of 85 remote network logons (Logon Type 3)
  • Interactive remote RDP tracking (Logon Type 10)
  • Account escalation timeline for 'wacsvc'
Staging Area Analysis

Browser History Forensics

Disk analysis of SQLite web browser databases on the client, revealing download history, sources, and staging configurations of attacker utility kits.

  • Edge & Chrome sqlite download database parsed
  • NirSoft BrowsingHistoryView config parameters isolated
  • Download tracing for staged PsExec and Process Hacker