Demo case NW-IR-041
Reusable sales asset. Client: Northwind Holdings. Analyst: M. Ortiz. Timezone: America/New_York. Host: WS-14. User: j.hale. CaseScope 4.26.13. AI off. Evidence types CaseScope handles well today: KAPE package, Huntress export, EVTX/Hayabusa, firewall CSV.
Suspicious remote-access activity
Northwind reports unusual RDP/PowerShell on WS-14 for j.hale.
Initial endpoint alert
Huntress-style export flags encoded PowerShell at 18:14:11.
Evidence collection
kape_ws14.zip, huntress_ws14.csv, northwind_edge.csv. No memory image.
Authentication and process activity
EVTX 18:14:07 on WS-14 / j.hale. Process tree shows powershell.exe under explorer.exe.
Network corroboration
Firewall 18:16:02 egress from WS-14 to 10.8.4.21.
Analyst decisions
Accept 10.8.4.21. Reject 10.0.0.15 as internal. AI off.
Finding and recommendation
Finding: suspicious remote access on WS-14. Remediation: isolate WS-14, reset j.hale, review RDP exposure. Memory still a gap.