{
  "case": "2019-05-02",
  "captured_at": "2026-09-22T19:40:55.675Z",
  "url": "[local-instance]",
  "analysis_id": "d4027bcf-0ef6-4e3c-a68a-68dfe35adb33",
  "summary_id": "investigation-summary:0808d9fa-3047-47fe-89f5-25072e6b0b60",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "41c9c4db17a58581eed3fc7f0bbebfe93c68034e2457afe131503c1a9eafac56",
  "native_summary_saved": true,
  "source_sha256": "24024eaf0a98da3a67a66db76c8c861830cac16c9ad9ad06bce9bfee5576a64c",
  "screenshot_sha256": "6458a2fc21ce1bba92c54bce16ed3a18a3d3f0a7ddd823ecf93292a794a2223b",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 814,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2019-05-02-traffic-analysis-exercise.pcap\n\nThe workstation Breaux-Win7-PC (10.0.0.227) participated in standard directory service protocol communication with 10.0.0.10, consistent with normal Windows logon activity and not by itself indicative of compromise.\n\nBreaux-Win7-PC (10.0.0.227) established sustained external TCP connections on port 21 to several public IPs, including 145.14.144.10, using protocols that could not be fully decoded; this is an investigation lead but does not alone establish malicious activity or compromise.\n\nWho was involved\nBreaux-Win7-PC was the primary host participating in the observed external and directory service network activity, bound to IP 10.0.0.227.\nAccount adriana.breaux was active on 10.0.0.227 during the capture window.\nIP address 10.0.0.227 is the source of the relevant connections and protocol activity.\nWhat remains uncertain\nIt remains unknown whether any malicious payload was downloaded or executed, as no file transfers or application-layer protocol payloads were observed or recoverable in the decrypted stream coverage.\nNext check\nReview the unidentified external TCP conversations to determine whether they correspond to legitimate FTP usage or potentially malicious activity by inspecting deeper payloads if available.\n\nModel: gpt-4.1-2025-04-14 · 159 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: 41c9c4db17a58581eed3fc7f0bbebfe93c68034e2457afe131503c1a9eafac56\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:50:28.582346+00:00",
    "image_sha256": "6458a2fc21ce1bba92c54bce16ed3a18a3d3f0a7ddd823ecf93292a794a2223b",
    "notes": "Viewed final screenshot at native width: text readable, no overlap or cropping, filename and SHA visible. StingrayAhoy correctly shows no saved summary. Presentation pass is not semantic approval.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
