{
  "case": "2020-03-14",
  "captured_at": "2026-09-22T19:40:37.379Z",
  "url": "[local-instance]",
  "analysis_id": "246dbce6-c561-4434-bedb-dd496ba758d2",
  "summary_id": "investigation-summary:a0b8e16c-23db-409b-9382-043a4e1c3fde",
  "model": "gpt-4.1-2025-04-14",
  "capture_sha256": "8df815a53e873e01803010c33752080414b0975709c1c02327e12661eec883a4",
  "native_summary_saved": true,
  "source_sha256": "5ae1200063689ec1118bd894b8fb566b12f308aac2184ec0e0c89322f15144e7",
  "screenshot_sha256": "d994407567e27144e374fefa5415ffe36d65ed2baa5f80dffdcfb8f96f8ec7a2",
  "all_claim_texts_present": true,
  "live_summary_matches_saved": true,
  "stale": false,
  "width": 1100,
  "height": 884,
  "overflow": [],
  "narrativeFont": "17px",
  "text": "ADVERSARYGRAPH · PCAP INVESTIGATION\nANALYST REVIEW REQUIRED\nWhat happened in this capture?\n\n2020-03-14-traffic-analysis-exercise.pcap\n\nThe host at 10.3.11.194 downloaded three files with PE (Windows executable) content from http://64.44.133.131/images/cursor.png and http://64.44.133.131/images/imgpaper.png during the capture window; these files were served with non-executable URL extensions, which is suspicious but does not prove execution or compromise.\n\nWho was involved\nThe device 10.3.11.194 is observed as an active host in these transfers.\nKey indicators and why they matter\nThe file with SHA-256 68798ccf8e2a5f9682a4e011bec288ad9b3f900244f82c6ae5e8ca538725f92e was downloaded by 10.3.11.194 from 64.44.133.131, matching a PE file signature.\nThe file with SHA-256 8aa9c596dd3eb7560bc7416ba181e858f1174fcbcb5432050f3f9a663ed1ffa2 was downloaded by 10.3.11.194 from 64.44.133.131, matching a PE file signature.\nThe file with SHA-256 fef9b646dba5c7372fe92b6a9d227833c1d15d8cc3a73fd22be9d1869b21cd67 was downloaded by 10.3.11.194 from 64.44.133.131, matching a PE file signature.\nWhat remains uncertain\nIt is not established whether any of the suspicious PE files downloaded by 10.3.11.194 were executed or led to compromise.\nNext check\nReview endpoint logs or behavioral telemetry for 10.3.11.194 to determine if any of the downloaded executables were run.\n\nModel: gpt-4.1-2025-04-14 · 136 claim-text words · 2026-09-22 · pcap-investigation-summary-v5\n\nCapture SHA-256: 8df815a53e873e01803010c33752080414b0975709c1c02327e12661eec883a4\n\nExact citations and reputation coverage are available separately. A downloaded file is not proof of execution.\n\n1 optional entry was omitted after validation; see the evidence details.",
  "browser_errors": [],
  "overlapping_fixed_elements": [],
  "visual_review": {
    "status": "passed",
    "reviewer": "assistant visual image inspection",
    "reviewed_at": "2026-09-22T19:43:40.751217+00:00",
    "image_sha256": "d994407567e27144e374fefa5415ffe36d65ed2baa5f80dffdcfb8f96f8ec7a2",
    "notes": "Reopened the final overlay-free image after capture completed. Full case title, narrative, indicators and footer are readable without cropping, overlap or clipping. No floating startup notification is present; semantic correctness is reviewed separately.",
    "scope": "Image presentation only: readable text, complete frame, consistent case identity, no overlap/clipping. Investigation correctness is evaluated separately against evidence and answers."
  }
}
