1. Create the case

Action: create Northwind Holdings / NW-IR-041 with timezone America/New_York and analyst M. Ortiz. Result: a case record before files arrive.

2. Add collected evidence

Action: attach kape_ws14.zip, huntress_ws14.csv, and northwind_edge.csv. Result: evidence listed on the case with lanes assigned.

3. Process supported artifacts

Action: run ingest to published generation. Result: counts and status, not a half-built hunt surface.

4. Review and search

Action: hunt WS-14 / j.hale around 18:14. Result: EVTX and Huntress rows in one grid.

5. Record an analyst decision

Action: accept IOC 10.8.4.21; reject 10.0.0.15 as internal. Result: dispositions by the analyst. AI off.

6. Promote evidence into a finding

Action: name “Suspicious remote access on WS-14” and attach supporting events. Result: a finding with sources and an explicit gap (no memory image).

7. Assemble the report

Action: generate the case report package. Result: cover, scope, findings, and limitations. CaseScope assembled the record; the analyst authored the conclusion.