{
  "case": "2019-03-19",
  "captured_at": "2026-09-22T19:40:59.624Z",
  "url": "[local-instance]",
  "analysis_id": "bd9602ed-341a-4123-aae3-9fafa5731518",
  "summary_id": "investigation-summary:9e228f2a-4391-46bf-98a8-95be922c970f",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "257ba51a573232f7c2a8b43b55e127e793abe0bf067bd55f40dbee398fde6520",
  "native_summary_saved": true,
  "source_sha256": "696f94d14ca75007f111ceb0db88203c166e8e063fabc3f0bf4b6135ec9f2683",
  "screenshot_sha256": "1f1183b9319e485f6a7352589b7460230716ce4d846c326f528df7fd71e7b8d7",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 846,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2019-03-19-traffic-analysis-exercise.pcap\n\nThe host 10.0.90.215 (Bobby-Tiger-PC) downloaded two executable files via HTTP from external servers 209.141.34.8 and 217.23.14.81, with SHA-256 hashes 2a9b0ed40f1f0bc0c13ff35d304689e9cadd633781cbcad1c2d2b92ced3f1c85 and 5865e801e6324166d6d05b39a14f2a8a798c6eb652831f78c2634f2b7a400eaf respectively.\n\nThese downloads correspond to transfers of potential PE (Portable Executable) files named test1.exe and f4.exe, suggesting a candidate for ingress tool transfer (ATT&CK T1105), but there is no evidence establishing whether the files were executed, nor proof of malicious purpose or system compromise during the capture.\n\nWho was involved\nThe main device involved is Bobby-Tiger-PC (10.0.90.215), with observed Windows accounts bobby-tiger-pc$ and bobby.tiger.\nSupported technique candidates\nIngress Tool Transfer is a candidate technique due to observed executable downloads (ATT&CK T1105), but adversary presence is not confirmed.\nWhat remains uncertain\nIt remains unknown whether either of the downloaded executables were launched or if any further action was taken on the host.\nNext check\nCheck endpoint telemetry on 10.0.90.215 to determine if the files 2a9b0ed40f1f0bc0c13ff35d304689e9cadd633781cbcad1c2d2b92ced3f1c85 and 5865e801e6324166d6d05b39a14f2a8a798c6eb652831f78c2634f2b7a400eaf were executed or triggered further activity.\n\nModel: gpt-4.1-2025-04-14 · 143 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: 257ba51a573232f7c2a8b43b55e127e793abe0bf067bd55f40dbee398fde6520\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:38.168676+00:00",
    "image_sha256": "1f1183b9319e485f6a7352589b7460230716ce4d846c326f528df7fd71e7b8d7",
    "notes": "Inspected complete final image: narrative, evidence limits and provenance are legible, case matches, no clipping or overlay. Story omissions and redundancy are recorded in answer comparison.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
