TandemTrace
Signal file // INC-002Severity // HighConfidence // Confirmed
Public-safe true-positive investigation · Endpoint

Endpoint malware followed by credential dumping

Confirmed malicious activity

Public-safe case study Customer names, domains, employee identifiers, exact user addresses, internal evidence locations, and case-specific identifiers have been removed or replaced. Quantitative findings and defensive lessons are retained for educational use.

Executive assessment

At 09:14 UTC, an unsigned process launched from a user-writable directory on WKSTN-FIN-042, established Run-key persistence, and accessed LSASS through a renamed credential-dumping utility. Seven correlated endpoint, identity, and network observations establish a true positive. The workstation was isolated 4 minutes 13 seconds after the first high-confidence credential-access event and before confirmed lateral movement.

1Compromised endpoint
5Process stages
2Credentials at risk
18,642Peer endpoints searched

95% autonomous investigation. 100% human authority.

TandemTrace AI agents completed 38 of 40 recorded investigation actions autonomously. The human analyst retained final verdict approval and containment authorization.

Investigation ownership

Agents built the case. The analyst controlled the consequential decisions.

95% AI agents
38Autonomous actions2Human decisions
Investigation stageAIHuman
Evidence collection110
Artifact enrichment80
Process and identity correlation70
Hypothesis testing70
Scope and prevalence50
Verdict approval01
Containment authorization01

Agent-to-human handoff

Orange = AI · black diamond = human · green = response
Agent collected the process lineage and LSASS-access telemetry.
Agent joined persistence, archive creation, and first-seen network evidence.
Agent enriched both payloads and confirmed enterprise-wide uniqueness.
Agent tested administrative-tooling and software-deployment explanations.
Agent searched 18,642 peers and assembled the true-positive recommendation.
Human analyst approved the true-positive verdict.
Human analyst authorized endpoint containment.
Endpoint isolation completed.

Investigation dataset

Case context
Alert source
EDR · Credential access behavior
First observed
2026-07-17 09:14:07 UTC
Host
WKSTN-FIN-042 · Windows 11 23H2
Identity
a.mercer · Finance Operations
Asset context
Standard endpoint · high data sensitivity
Telemetry reviewed
Endpoint
2,416 events · ±30 minutes
Identity
138 sign-ins · 24 hours
Network
31 DNS lookups · 12 proxy sessions
Prevalence
18,642 endpoints · 30 days
Sources
EDR, SIEM, Entra ID, DNS, web gateway
explorer.exePID 4128 · signed
invoice_viewer.exePID 9364 · unsigned
rundll32.exePID 10120 · abnormal DLL
svchelper.exePID 10308 · LSASS access
7z.exePID 10444 · archive
ArtifactSanitized valuePrevalenceAssessment
Initial SHA-2568d31…b7a21 host / 30 daysUnique and unsigned
Dump tool SHA-25641ac…09de1 host / 30 daysRenamed utility
Run-key valueCollabUpdate1 hostMasquerading persistence
Destination198.51.100[.]27:4430 prior connectionsSanitized TEST-NET value

Visual investigation brief

Original detection

EDR alert · rule v4.18
Alert IDEDR-7F2A-1048
Detected09:16:41 UTC
RuleSuspicious LSASS access
HostWKSTN-FIN-042
Processsvchelper.exe · PID 10308
Initial severityHigh · 82/100

Investigation funnel

2,416 → 1
2,416Endpoint events reviewed
47Events in process lineage
12Suspicious behaviors
7Corroborating signals
1Confirmed incident

Evidence confidence matrix

Cross-source support
FindingEndpointIdentityNetworkConfidence
Malware executionConfirmed
Credential accessContextConfirmed
Command and controlHigh
Archive exfiltrationPartialPartialUnconfirmed
Lateral movementNoneNoneNoneNot observed
Initial alert

One suspicious process

  • LSASS access alert
  • One host identified
  • Unknown scope and intent
  • No response recommendation
Completed investigation

Five-stage malicious chain

  • Execution and persistence confirmed
  • Two credentials at risk
  • 18,642 endpoints searched
  • C2 probable; exfiltration bounded

Multi-source timeline

09:14–09:21 UTC
Endpoint
Registry
Network
Identity
Response
09:1409:1609:1809:2009:21

Evidence that changed the verdict

Execution chain

invoice_viewer.exe spawned an unsigned binary from AppData\Local\Temp, inconsistent with the signed finance application baseline.

Credential access

The child process requested a handle to LSASS with memory-read rights and produced a compressed output file moments later.

Persistence

A new per-user Run key referenced the staged binary. The value name imitated a legitimate collaboration updater.

Network correlation

The process contacted a newly observed TLS endpoint using a rare certificate and a fixed 30-second beacon interval.

Correlated timeline

09:14:07 · Initial execution

User launches the weaponized attachment from the downloads directory.

09:14:19 · Payload staged

Unsigned executable written to a user-writable temporary path.

09:15:02 · Persistence

Run-key value created for execution at next sign-in.

09:16:41 · Credential dumping

LSASS access followed by creation of an encrypted archive.

09:20:54 · Containment

Endpoint isolated; identity-session revocation initiated.

Competing hypotheses tested

HypothesisTestDisposition
Authorized administrative toolCompared signer, path, parent process, software inventory, and change records.Rejected: no approved tool or maintenance window matched.
Security product LSASS accessCompared process identity and access pattern with known EDR modules.Rejected: binary was unsigned and outside protected directories.
Credential theft malwareCorrelated LSASS access, archive creation, persistence, and beaconing.Confirmed.

Confirmed scope and uncertainty

Confirmed by evidence
  • Execution, persistence, LSASS access, and archive creation occurred on one workstation.
  • The interactive token and one cached service credential were present during LSASS access.
  • Seven TLS connections totaling 1.84 MB occurred at roughly 30-second intervals.
  • No matching chain appeared across 18,642 peer endpoints.
Not yet confirmed
  • Proxy evidence cannot prove the archive was uploaded.
  • No evidence proves either exposed credential was used.
  • The operator and malware family remain unattributed.
  • Memory collection may not contain the complete module.

Containment and follow-up

Isolate and preserve

Keep the endpoint isolated and acquire volatile memory plus the staged binaries.

Reset exposed credentials

Rotate the user password and any credentials present in the interactive session.

Hunt enterprise-wide

Search for the file lineage, Run-key value, certificate fingerprint, and beacon cadence.

Close the proxy gap

Retain upload byte counts so future exfiltration assessments are conclusive.

Technical evidence and response

LSASS access evidence

Credential access · T1003.001
TimeSourceTargetRequested rightsSigner / prevalence
09:16:41.228svchelper.exe · PID 10308lsass.exe · PID 756VM_READ · QUERY_INFORMATIONUnsigned · 1/18,642
09:16:42.019svchelper.exeLSASS memory17.6 MB readNot approved software
09:16:48.6027z.exe · PID 10444cache_17.datEncrypted archive createdChild of malicious lineage

Beacon regularity

7 TLS sessions · 1.84 MB total

Median interval: 30.4 seconds · interval deviation: 2.1 seconds · destination first observed 09:16:58 UTC.

Interactive identity

a.mercer

Exposure
High confidence
Action
Password reset; tokens revoked
Post-event use
No anomalous sign-in
Cached credential

svc_fin_export

Exposure
Possible secret material
Action
Secret rotated
Post-event use
No authentication observed

Enterprise prevalence

18,642 endpoints · 30 days
Exact initial hash
1 host
Run-key value
1 host
Full process ancestry
1 host
Destination certificate
1 host
Ordinary rundll32 use
914 hosts
Prevalence querySHA256 = 41ac…09de · lookback 30d
EDR1 host
Persistence queryRunValue = CollabUpdate
Registry telemetry1 host
Identity queryUsers in LSASS window · post-event sign-ins
Entra ID0 anomalous
Lateral movement queryRemote services · SMB · RDP · WinRM
SIEM · 24h0 matches

Negative evidence reviewed

Absence tested—not assumed
QuestionSources / windowResultMeaning
Did the chain execute elsewhere?EDR · 18,642 hosts · 30d0 additionalScope remains one host
Were exposed credentials used?Entra + service auth · 24h0 anomalousMisuse not observed
Was lateral movement attempted?SMB, RDP, WinRM, service creation · 24h0 matchesNo confirmed lateral movement
Was archive upload proven?Proxy sessions · event windowInconclusiveCannot claim no exfiltration

Response status

Closing review
Endpoint isolatedComplete · 09:20
User sessions revokedComplete · 09:22
Credentials rotatedComplete · 10:05
Enterprise huntComplete · 18,642
Memory analysisPartial
Upload verificationTelemetry gap

Evidence ledger

Sanitized chain of evidence
IDSourceEvent UTCCollectedEntityVerdict contribution
E-01EDR process09:14:0709:16:43invoice_viewer.exeInitial execution
E-02Registry09:15:0209:16:45CollabUpdatePersistence confirmed
E-03EDR memory09:16:4109:16:42LSASSCredential access confirmed
E-04Proxy09:16:5809:17:20198.51.100[.]27C2 corroboration
E-05Entra ID24h review10:18:002 identitiesNo misuse observed

MITRE ATT&CK mapping

TechniqueObserved behavior
T1204.002 · Malicious FileUser execution of weaponized attachment.
T1547.001 · Registry Run KeysPer-user persistence value.
T1003.001 · LSASS MemoryProcess memory access consistent with credential dumping.
T1071.001 · Web ProtocolsPeriodic TLS command-and-control traffic.