PCAP investigation summary

What happened

The host Escritorio-PC (172.16.5.203) participated in standard Kerberos authentication and directory protocol activity within a local network, involving accounts such as thiago.almeida and escritorio-pc$.

Directory protocol operations (LDAP, SAMR, DRSUAPI) were observed between Escritorio-PC and a domain controller (172.16.5.5), but this traffic matches normal Windows logon and user activity, with no evidence for credential theft, discovery, or DCSync.

Who was involved

What remains uncertain

Next check

Analyst-review draft. Exact evidence references and provider provenance are retained in the structured record.