1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

AdversaryGraph Deterministic PCAP Analysis

Source: 2021-10-22-ISC-forensic-challenge-traffic.pcap Capture SHA-256: 95074aea864749524df5b0a6c9fd58a3111038157b3400902486b96d902b3455 Semantic result SHA-256: e2a781b6839946af3b4581e8fbaa850bc68bbe393fce12f786178323e0ccd04d Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 84542 packets across 216 IP endpoints and 2746 transport flows. Observed 2061 DNS events, 120 HTTP requests, 409 TLS ClientHello events, and 4 exported HTTP object(s). Deterministic rules produced 37 finding(s): 0 high, 13 medium, and 24 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 825, frame 1639, frame 2954, frame 15029, frame 17432.

Metrics: {"domain":"wpad.enemywatch.net","response_count":42,"source":"10.10.22.156"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 827, frame 1641, frame 2956, frame 15031, frame 17435.

Metrics: {"domain":"wpad.localdomain","response_count":42,"source":"10.10.22.156"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 39, frame 752, frame 1643, frame 11964, frame 22840.

Metrics: {"domain":"wpad.enemywatch.net","response_count":12,"source":"10.10.22.157"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 41, frame 754, frame 1645, frame 11966, frame 22842.

Metrics: {"domain":"wpad.localdomain","response_count":12,"source":"10.10.22.157"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 1719, frame 2522, frame 3813, frame 6217, frame 6501.

Metrics: {"domain":"wpad.enemywatch.net","response_count":16,"source":"10.10.22.158"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 1721, frame 2524, frame 3815, frame 6219, frame 6503.

Metrics: {"domain":"wpad.localdomain","response_count":16,"source":"10.10.22.158"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 999 / TCP stream 46, frame 1001 / TCP stream 46, frame 1003 / TCP stream 46, frame 1013 / TCP stream 46, frame 1015 / TCP stream 46.

Metrics: {"destination":"10.10.22.22","event_count":59,"operation_numbers":["0","1","12","13","30"],"protocol":"drsuapi","source":"10.10.22.156"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 804 / TCP stream 37, frame 965 / TCP stream 37, frame 994 / TCP stream 37, frame 1062 / TCP stream 55, frame 1069 / TCP stream 55.

Metrics: {"destination":"10.10.22.22","event_count":102,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"10.10.22.156"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 4249 / TCP stream 187, frame 4251 / TCP stream 187, frame 4253 / TCP stream 187, frame 4255 / TCP stream 187, frame 4257 / TCP stream 187.

Metrics: {"destination":"10.10.22.22","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.156"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 127 / TCP stream 3, frame 131 / TCP stream 3, frame 134 / TCP stream 3, frame 145 / TCP stream 3, frame 147 / TCP stream 3.

Metrics: {"destination":"10.10.22.22","event_count":49,"operation_numbers":["0","1","12","30"],"protocol":"drsuapi","source":"10.10.22.157"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 27 / TCP stream 0, frame 91 / TCP stream 5, frame 120 / TCP stream 5, frame 129 / TCP stream 5, frame 133 / TCP stream 5.

Metrics: {"destination":"10.10.22.22","event_count":92,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"10.10.22.157"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 3468 / TCP stream 157, frame 3470 / TCP stream 157, frame 3472 / TCP stream 157, frame 3474 / TCP stream 157, frame 3476 / TCP stream 157.

Metrics: {"destination":"10.10.22.22","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.157"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1951 / TCP stream 93, frame 1959 / TCP stream 93, frame 1963 / TCP stream 93, frame 1964 / TCP stream 86, frame 1968 / TCP stream 86.

Metrics: {"destination":"10.10.22.22","event_count":53,"operation_numbers":["0","1","12","13","30"],"protocol":"drsuapi","source":"10.10.22.158"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1696 / TCP stream 79, frame 1776 / TCP stream 84, frame 1907 / TCP stream 79, frame 1938 / TCP stream 84, frame 1960 / TCP stream 84.

Metrics: {"destination":"10.10.22.22","event_count":88,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"10.10.22.158"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2699 / TCP stream 126, frame 2701 / TCP stream 126, frame 2703 / TCP stream 126, frame 2705 / TCP stream 126, frame 2708 / TCP stream 126.

Metrics: {"destination":"10.10.22.22","event_count":43,"operation_numbers":["1","16","17","18","19","20","25","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.158"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1000 / TCP stream 46, frame 1002 / TCP stream 46, frame 1004 / TCP stream 46, frame 1014 / TCP stream 46, frame 1016 / TCP stream 46.

Metrics: {"destination":"10.10.22.156","event_count":59,"operation_numbers":["0","1","12","13","30"],"protocol":"drsuapi","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 806 / TCP stream 37, frame 968 / TCP stream 37, frame 1064 / TCP stream 55, frame 1071 / TCP stream 55, frame 1073 / TCP stream 55.

Metrics: {"destination":"10.10.22.156","event_count":82,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 4250 / TCP stream 187, frame 4252 / TCP stream 187, frame 4254 / TCP stream 187, frame 4256 / TCP stream 187, frame 4258 / TCP stream 187.

Metrics: {"destination":"10.10.22.156","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 128 / TCP stream 3, frame 132 / TCP stream 3, frame 135 / TCP stream 3, frame 146 / TCP stream 3, frame 150 / TCP stream 3.

Metrics: {"destination":"10.10.22.157","event_count":49,"operation_numbers":["0","1","12","30"],"protocol":"drsuapi","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 29 / TCP stream 0, frame 93 / TCP stream 5, frame 124 / TCP stream 5, frame 130 / TCP stream 5, frame 136 / TCP stream 5.

Metrics: {"destination":"10.10.22.157","event_count":74,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 3469 / TCP stream 157, frame 3471 / TCP stream 157, frame 3473 / TCP stream 157, frame 3475 / TCP stream 157, frame 3477 / TCP stream 157.

Metrics: {"destination":"10.10.22.157","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1954 / TCP stream 93, frame 1961 / TCP stream 93, frame 1965 / TCP stream 93, frame 1966 / TCP stream 86, frame 1972 / TCP stream 86.

Metrics: {"destination":"10.10.22.158","event_count":53,"operation_numbers":["0","1","12","13","30"],"protocol":"drsuapi","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1698 / TCP stream 79, frame 1779 / TCP stream 84, frame 1925 / TCP stream 79, frame 1947 / TCP stream 84, frame 1962 / TCP stream 84.

Metrics: {"destination":"10.10.22.158","event_count":71,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.10.22.22"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2700 / TCP stream 126, frame 2702 / TCP stream 126, frame 2704 / TCP stream 126, frame 2706 / TCP stream 126, frame 2709 / TCP stream 126.

Metrics: {"destination":"10.10.22.158","event_count":43,"operation_numbers":["1","16","17","18","19","20","25","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.10.22.22"}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 5644 / TCP stream 232.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":336.595,"packets":514,"source":"10.10.22.157","wire_bytes":376928}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 17795 / TCP stream 391.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":171.549,"packets":72,"source":"10.10.22.157","wire_bytes":4376}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 24560 / TCP stream 691.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":330.753,"packets":134,"source":"10.10.22.157","wire_bytes":8096}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 42858 / TCP stream 810.

Metrics: {"destination":"23.111.114.52","destination_port":65400,"duration_seconds":3322.704,"packets":9622,"source":"10.10.22.156","wire_bytes":1586196}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 51877 / TCP stream 968.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":334.618,"packets":136,"source":"10.10.22.157","wire_bytes":8216}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 61387 / TCP stream 1254.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":330.634,"packets":134,"source":"10.10.22.157","wire_bytes":8096}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 67512 / TCP stream 1346.

Metrics: {"destination":"45.153.241.142","destination_port":443,"duration_seconds":699.347,"packets":52,"source":"10.10.22.156","wire_bytes":3186}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 67513 / TCP stream 1347.

Metrics: {"destination":"45.153.241.142","destination_port":443,"duration_seconds":699.318,"packets":54,"source":"10.10.22.156","wire_bytes":3306}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 69549 / TCP stream 1450.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":331.166,"packets":132,"source":"10.10.22.157","wire_bytes":7976}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 74529 / TCP stream 1485.

Metrics: {"destination":"45.153.241.142","destination_port":443,"duration_seconds":30.11,"packets":19,"source":"10.10.22.156","wire_bytes":1120}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 76852 / TCP stream 1559.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":333.255,"packets":132,"source":"10.10.22.157","wire_bytes":7976}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 81050 / TCP stream 1607.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":331.75,"packets":134,"source":"10.10.22.157","wire_bytes":8096}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 83774 / TCP stream 1645.

Metrics: {"destination":"37.0.10.22","destination_port":1187,"duration_seconds":91.986,"packets":41,"source":"10.10.22.157","wire_bytes":2522}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 5222f776b8c48e86a0c8622f8a6c5757c219009df704244b52c91467fdafc237; recorded 2026-09-19T12:10:24.874416+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":512,"observable_limit":5000,"observables_checked":512,"observables_total":512,"prior_case_limit_reached":false,"prior_cases_checked":14,"truncated":false}

Coverage and limitations