1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

AdversaryGraph Deterministic PCAP Analysis

Source: 2021-12-08-ISC-Forensic-Challenge.pcap Capture SHA-256: 91e547acc39e8ef27d7ec549404157fe527e090bd5caf6fe189c2bae6d4a57ef Semantic result SHA-256: 3343d2811e62c53a10dfd853861eeb3e3316a3080f654a63017c370f005b6af8 Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 55390 packets across 756 IP endpoints and 2044 transport flows. Observed 1726 DNS events, 17 HTTP requests, 191 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 18 finding(s): 0 high, 12 medium, and 6 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — HTTP client claiming a PowerShell User-Agent

The HTTP User-Agent claims Windows PowerShell. User-Agent strings can be spoofed; this alone does not prove interpreter execution or malicious intent.

Rule: powershell-http-client@pcap-rules-v3; confidence: 0.94; evidence: frame 1743 / TCP stream 27.

Metrics: {"destination":"104.21.29.80","request_count":1,"source":"10.12.3.66","user_agent":"Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1320"}

MEDIUM — HTTP client claiming a PowerShell User-Agent

The HTTP User-Agent claims Windows PowerShell. User-Agent strings can be spoofed; this alone does not prove interpreter execution or malicious intent.

Rule: powershell-http-client@pcap-rules-v3; confidence: 0.94; evidence: frame 1771 / TCP stream 29.

Metrics: {"destination":"139.59.6.175","request_count":1,"source":"10.12.3.66","user_agent":"Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1320"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 353 / TCP stream 11, frame 355 / TCP stream 11, frame 357 / TCP stream 11, frame 359 / TCP stream 11, frame 3126 / TCP stream 32.

Metrics: {"destination":"10.12.3.66","event_count":16,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 46 / TCP stream 0, frame 52 / TCP stream 0, frame 428 / TCP stream 17, frame 433 / TCP stream 17, frame 435 / TCP stream 17.

Metrics: {"destination":"10.12.3.66","event_count":25,"operation_numbers":["1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 291 / TCP stream 8, frame 293 / TCP stream 8, frame 295 / TCP stream 8, frame 297 / TCP stream 8, frame 299 / TCP stream 8.

Metrics: {"destination":"10.12.3.66","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 352 / TCP stream 11, frame 354 / TCP stream 11, frame 356 / TCP stream 11, frame 358 / TCP stream 11, frame 3125 / TCP stream 32.

Metrics: {"destination":"10.12.3.3","event_count":16,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.12.3.66"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 43 / TCP stream 0, frame 50 / TCP stream 0, frame 53 / TCP stream 0, frame 426 / TCP stream 17, frame 431 / TCP stream 17.

Metrics: {"destination":"10.12.3.3","event_count":32,"operation_numbers":["0","2","3"],"protocol":"ldap","source":"10.12.3.66"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 290 / TCP stream 8, frame 292 / TCP stream 8, frame 294 / TCP stream 8, frame 296 / TCP stream 8, frame 298 / TCP stream 8.

Metrics: {"destination":"10.12.3.3","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.12.3.66"}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11092 / TCP stream 92.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":30.685,"packets":107,"source":"10.12.3.66","wire_bytes":73616}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11301 / TCP stream 113.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":57.532,"packets":147,"source":"10.12.3.66","wire_bytes":105748}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13057 / TCP stream 241.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":42.498,"packets":168,"source":"10.12.3.66","wire_bytes":125939}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18188 / TCP stream 443.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":33.66,"packets":583,"source":"10.12.3.66","wire_bytes":454912}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21451 / TCP stream 597.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":36.785,"packets":1049,"source":"10.12.3.66","wire_bytes":805994}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23295 / TCP stream 598.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":59.968,"packets":108,"source":"10.12.3.66","wire_bytes":73622}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 28378 / TCP stream 748.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":34.519,"packets":3721,"source":"10.12.3.66","wire_bytes":2960550}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 43910 / TCP stream 895.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":49.751,"packets":111,"source":"10.12.3.66","wire_bytes":74055}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 46108 / TCP stream 1057.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":54.922,"packets":353,"source":"10.12.3.66","wire_bytes":265548}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 47842 / TCP stream 1128.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":40.215,"packets":331,"source":"10.12.3.66","wire_bytes":262342}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 37c4030f9b25335ca7a7a8cd23b5f050fab86309243d1fc8d5d3462e90e2a5a9; recorded 2026-09-19T12:09:53.287759+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":3662,"observable_limit":5000,"observables_checked":3662,"observables_total":3662,"prior_case_limit_reached":false,"prior_cases_checked":13,"truncated":false}

Coverage and limitations