Synthetic demonstration. Not captured from a running CaseScope host. The same IDs, timestamps, files, and findings appear on the homepage, tour, features, and sample report.

1

Suspicious remote-access activity

Northwind reports unusual RDP/PowerShell on WS-14 for j.hale.

2

Initial endpoint alert

Huntress-style export flags encoded PowerShell at 18:14:11.

3

Evidence collection

kape_ws14.zip, huntress_ws14.csv, northwind_edge.csv. No memory image.

4

Authentication and process activity

EVTX 18:14:07 on WS-14 / j.hale. Process tree shows powershell.exe under explorer.exe.

5

Network corroboration

Firewall 18:16:02 egress from WS-14 to 10.8.4.21.

6

Analyst decisions

Accept 10.8.4.21. Reject 10.0.0.15 as internal. AI off.

7

Finding and recommendation

Finding: suspicious remote access on WS-14. Remediation: isolate WS-14, reset j.hale, review RDP exposure. Memory still a gap.

8

Report

CaseScope assembled the record. The analyst authored the conclusion. Sample report ยท Tour