Comprehensive Security Event Correlation on Mounted Windows 11 Image E:\
Correlated across Security, System, LocalSessionManager, and WMI-Activity event logs.
2023-01-16 17:01:03 to 2023-01-17 19:01:34 | User: rsydow-a | Vector: Network (Type 3)
The attacker established 85 Network Logons (Type 3) using the compromised credentials of account rsydow-a, originating from pivot host 172.16.6.18.
2023-01-17 14:43:03 | User: wacsvc | Vector: RDP (Type 10)
The attacker logged in remotely as service account wacsvc via RDP (Type 10) from the pivot host 172.16.6.18.
2023-01-17 18:00:27 | User: wacsvc | Vector: System
Under the wacsvc session, the attacker executed the browser history gathering tool bhv.exe exactly once, creating bhv.cfg, dumping the logs, and subsequently deleting the executable.
2023-01-23 20:53:05 | User: wacsvc | Vector: RDP (Type 10)
A new RDP session was established for the service account wacsvc originating from 172.16.4.9, staging `ph.exe` and `px.exe` in the Downloads directory.
2023-01-24 18:04:57 | User: cbarton-a | Vector: Network (Type 3)
Forensic analyst `cbarton-a` logged in remotely from the incident response server `172.16.5.25` using Kerberos to triage the compromised system.
2023-01-24 18:04:59 | User: System | Vector: System
The DFIR team installed the **`F-Response Subject Service`** and loaded the **`mnemosyne`** (Mnemosyne.sys) kernel memory acquisition driver to capture physical memory and preserve volatile evidence.
| User Account | Logon Mechanism | Source IP Address | Session Count | First Logon Time | Last Logon Time |
|---|---|---|---|---|---|
| tdungan | 3 - Network (SMB/WinRM) | 172.16.30.20 |
4 | 2023-01-05 20:49:46 | 2023-01-09 16:57:23 |
| UMFD-5 | 2 - Interactive (Local) | - |
2 | 2023-01-05 20:49:47 | 2023-01-24 14:17:12 |
| DWM-5 | 2 - Interactive (Local) | - |
4 | 2023-01-05 20:49:47 | 2023-01-24 14:17:12 |
| tdungan | 10 - RDP (Remote) | 172.16.30.20 |
2 | 2023-01-05 20:49:49 | 2023-01-09 16:57:25 |
| tdungan | 11 - Unknown | ::1 |
1 | 2023-01-05 21:41:01 | 2023-01-05 21:41:01 |
| UMFD-6 | 2 - Interactive (Local) | - |
1 | 2023-01-09 16:57:23 | 2023-01-09 16:57:23 |
| DWM-6 | 2 - Interactive (Local) | - |
2 | 2023-01-09 16:57:24 | 2023-01-09 16:57:24 |
| rsydow-a | 3 - Network (SMB/WinRM) | 172.16.4.4 |
25 | 2023-01-12 05:02:19 | 2023-01-13 22:07:03 |
| tdungan | 3 - Network (SMB/WinRM) | 172.16.30.8 |
14 | 2023-01-12 06:19:41 | 2023-01-24 14:17:11 |
| UMFD-7 | 2 - Interactive (Local) | - |
1 | 2023-01-12 06:19:41 | 2023-01-12 06:19:41 |
| DWM-7 | 2 - Interactive (Local) | - |
2 | 2023-01-12 06:19:41 | 2023-01-12 06:19:41 |
| tdungan | 10 - RDP (Remote) | 172.16.30.8 |
7 | 2023-01-12 06:19:43 | 2023-01-24 14:17:13 |
| UMFD-8 | 2 - Interactive (Local) | - |
1 | 2023-01-12 20:40:53 | 2023-01-12 20:40:53 |
| DWM-8 | 2 - Interactive (Local) | - |
2 | 2023-01-12 20:40:53 | 2023-01-12 20:40:53 |
| UMFD-9 | 2 - Interactive (Local) | - |
1 | 2023-01-13 18:32:14 | 2023-01-13 18:32:14 |
| DWM-9 | 2 - Interactive (Local) | - |
2 | 2023-01-13 18:32:14 | 2023-01-13 18:32:14 |
| rsydow-a | 3 - Network (SMB/WinRM) | 172.16.4.7 |
42 | 2023-01-14 17:29:53 | 2023-01-23 02:09:11 |
| rsydow-a | 3 - Network (SMB/WinRM) | 172.16.6.18 |
85 | 2023-01-16 17:01:03 | 2023-01-17 19:01:34 |
| UMFD-10 | 2 - Interactive (Local) | - |
1 | 2023-01-17 00:12:36 | 2023-01-17 00:12:36 |
| DWM-10 | 2 - Interactive (Local) | - |
2 | 2023-01-17 00:12:36 | 2023-01-17 00:12:36 |
| UMFD-11 | 2 - Interactive (Local) | - |
1 | 2023-01-17 04:21:54 | 2023-01-17 04:21:54 |
| DWM-11 | 2 - Interactive (Local) | - |
2 | 2023-01-17 04:21:54 | 2023-01-17 04:21:54 |
| UMFD-12 | 2 - Interactive (Local) | - |
1 | 2023-01-17 14:42:00 | 2023-01-17 14:42:00 |
| DWM-12 | 2 - Interactive (Local) | - |
2 | 2023-01-17 14:42:00 | 2023-01-17 14:42:00 |
| wacsvc | 10 - RDP (Remote) | 172.16.6.18 |
12 | 2023-01-17 14:43:03 | 2023-01-19 14:28:14 |
| tdungan | 3 - Network (SMB/WinRM) | 172.16.30.3 |
8 | 2023-01-17 23:30:53 | 2023-01-19 18:01:58 |
| UMFD-13 | 2 - Interactive (Local) | - |
1 | 2023-01-17 23:30:54 | 2023-01-17 23:30:54 |
| DWM-13 | 2 - Interactive (Local) | - |
2 | 2023-01-17 23:30:54 | 2023-01-17 23:30:54 |
| tdungan | 10 - RDP (Remote) | 172.16.30.3 |
4 | 2023-01-17 23:30:56 | 2023-01-19 18:02:01 |
| UMFD-14 | 2 - Interactive (Local) | - |
10 | 2023-01-18 14:49:52 | 2023-01-19 18:01:59 |
| DWM-14 | 2 - Interactive (Local) | - |
20 | 2023-01-18 14:49:52 | 2023-01-19 18:01:59 |
| UMFD-15 | 2 - Interactive (Local) | - |
5 | 2023-01-19 18:45:35 | 2023-01-23 14:37:27 |
| DWM-15 | 2 - Interactive (Local) | - |
10 | 2023-01-19 18:45:36 | 2023-01-23 14:37:27 |
| tdungan | 3 - Network (SMB/WinRM) | 172.16.30.14 |
6 | 2023-01-22 23:30:58 | 2023-01-23 14:52:54 |
| tdungan | 10 - RDP (Remote) | 172.16.30.14 |
3 | 2023-01-22 23:31:01 | 2023-01-23 14:52:56 |
| UMFD-0 | 2 - Interactive (Local) | - |
3 | 2023-01-23 14:51:17 | 2023-01-25 14:38:28 |
| UMFD-1 | 2 - Interactive (Local) | - |
3 | 2023-01-23 14:51:17 | 2023-01-25 14:38:28 |
| DWM-1 | 2 - Interactive (Local) | - |
6 | 2023-01-23 14:51:17 | 2023-01-25 14:38:29 |
| UMFD-2 | 2 - Interactive (Local) | - |
3 | 2023-01-23 14:52:55 | 2023-01-25 14:38:49 |
| DWM-2 | 2 - Interactive (Local) | - |
6 | 2023-01-23 14:52:55 | 2023-01-25 14:38:49 |
| tdungan | 9 - NewCredentials (RunAs /b) | - |
2 | 2023-01-23 15:00:42 | 2023-01-25 14:50:15 |
| tdungan | 9 - NewCredentials (RunAs /b) | ::1 |
17 | 2023-01-23 15:14:05 | 2023-01-25 15:07:55 |
| wacsvc | 3 - Network (SMB/WinRM) | fe80::7e6b:763c:b405:22b4 |
1 | 2023-01-23 16:08:23 | 2023-01-23 16:08:23 |
| UMFD-3 | 2 - Interactive (Local) | - |
1 | 2023-01-23 20:52:48 | 2023-01-23 20:52:48 |
| DWM-3 | 2 - Interactive (Local) | - |
2 | 2023-01-23 20:52:48 | 2023-01-23 20:52:48 |
| wacsvc | 10 - RDP (Remote) | 172.16.4.9 |
2 | 2023-01-23 20:53:05 | 2023-01-23 20:53:05 |
| UMFD-4 | 2 - Interactive (Local) | - |
1 | 2023-01-24 03:21:29 | 2023-01-24 03:21:29 |
| DWM-4 | 2 - Interactive (Local) | - |
2 | 2023-01-24 03:21:29 | 2023-01-24 03:21:29 |
| cbarton-a | 3 - Network (SMB/WinRM) | 172.16.5.25 |
26 | 2023-01-24 18:04:57 | 2023-01-24 18:04:59 |
| tdungan | 3 - Network (SMB/WinRM) | 172.16.30.23 |
5 | 2023-01-25 07:11:09 | 2023-01-25 14:38:48 |
| tdungan | 10 - RDP (Remote) | 172.16.30.23 |
2 | 2023-01-25 14:19:26 | 2023-01-25 14:38:50 |
| slevine | 3 - Network (SMB/WinRM) | 172.16.6.18 |
1 | 2023-01-25 14:26:57 | 2023-01-25 14:26:57 |
| wacsvc | 3 - Network (SMB/WinRM) | 172.16.6.18 |
1 | 2023-01-25 14:43:02 | 2023-01-25 14:43:02 |
| Service Name | Image Path | Installation Time | Account Context | Status |
|---|---|---|---|---|
| MpKsl80b1fd2a | C:/Windows/system32/MpEngineStore/MpKslDrv.sys | 2023-01-05 02:24:41 | System Service | |
| Ec2Config | "C:/Program Files/Amazon/Ec2ConfigService/Ec2Config.exe" | 2023-01-17 14:43:59 | LocalSystem | System Service |
| MpKsle2439143 | C:/ProgramData/Microsoft/Windows Defender/Definition Updates/{1FEC7FC9-D47D-4480-85E5-AE4DD6CCA988}/MpKslDrv.sys | 2023-01-24 00:51:58 | System Service | |
| F-Response Subject Service | "C:/windows/subject_srv.exe" -s "172.16.5.25:5682" -l 3262 -v "F-Response Subject Service" -k "155522845" | 2023-01-24 18:04:59 | LocalSystem | Forensic Tool |
| mnemosyne | C:/windows/Mnemosyne.sys | 2023-01-24 18:04:59 | Forensic Tool | |
| mnemosyne | C:/windows/Mnemosyne.sys | 2023-01-25 14:38:37 | Forensic Tool |
172.16.6.18 and 172.16.4.9. Security teams must perform a sweep of these two hosts immediately, as they serve as the threat actor's active pivot points.ph.exe (Process Hacker) and px.exe (PsExec) on January 23, the Prefetch logs confirm they were never executed on this system. The attacker likely planned lateral movement *outbound* but was disrupted by the DFIR team's rapid response on January 24.