Twenty malware PCAPs: reports and evidence

Published by Andrey Pautov on 23 September 2026. Tests recorded 22 September 2026.

Read the article · 20 concise reviewed explanations · Download all public evidence · Bundle SHA-256

The native result is 12 partial stories, four missed or misinterpreted scenarios, and four withheld reports. Sixteen summaries were saved; four screenshots explicitly show no validated saved summary. This is not 80% detection accuracy. The official references sometimes include IDS alerts, emails and host artifacts that were absent from the PCAP-only model input.

What can be inspected

The full article embeds every case screenshot beside the unchanged native narrative (or explicit withheld status), the reference-assisted explanation and links to the detailed record. Screenshots are not composites or generated mock-ups. Each has its analysis ID, original image hash and individual visual-inspection record. The cover supplied by the author is a conceptual illustration, not investigation evidence.

Public evidence boundaries

This is an explicitly labelled public derivative of the preserved experiment. Original local files were not overwritten. Native screenshot PNGs and the supplied cover are byte-identical; text and JSON remove workstation paths and loopback URLs. Lab hostnames, accounts and historical indicators from the public exercises remain evidence. Session UUIDs are correlation identifiers, not credentials or working public sessions.

Complete packet extraction records, short-report citations, qualification reasons, provider statuses, test logs and exact selected payload hashes are retained. Provider evidence is bounded to concise assertions and hash/signature metadata; unrelated prior-session details are replaced by overlap counts. Proprietary bulk responses, duplicated private audit payloads, implementation source snapshots, PCAP binaries, recovered malware, credentials and publisher answer PDFs are not redistributed. Follow the original publisher links for their materials. Current reputation is not incident-time reputation; not-found or rate-limited does not mean benign.

The recorded original snapshot and pre-answer hashes describe the retained source files, not the formatted public derivatives. PUBLIC-PROVENANCE.json maps original to public file hashes. Those original hashes cannot reconstruct or independently validate omitted data. Use SHA256SUMS for public payload integrity; rendered HTML is excluded because the site release process adds shared navigation and metadata. DOWNLOAD.sha256 covers the downloadable archive.

Verify the public download

unzip adversarygraph-pcap-stories-public.zip -d pcap-study
cd pcap-study
sha256sum -c SHA256SUMS

Read the supplied scripts and records as evidence, not instructions to run recovered content. Do not visit captured malicious URLs or execute payloads. These historical indicators are not a current blocklist. No human-equivalent accuracy, calibrated confidence or measured analyst speedup is claimed.

Six-case AI-agent experiment · Ten-case deterministic experiment · AdversaryGraph · Malware analysis