Endpoint malware followed by credential dumping
Public-safe case study Customer names, domains, employee identifiers, exact user addresses, internal evidence locations, and case-specific identifiers have been removed or replaced. Quantitative findings and defensive lessons are retained for educational use.
Executive assessment
At 09:14 UTC, an unsigned process launched from a user-writable directory on WKSTN-FIN-042, established Run-key persistence, and accessed LSASS through a renamed credential-dumping utility. Seven correlated endpoint, identity, and network observations establish a true positive. The workstation was isolated 4 minutes 13 seconds after the first high-confidence credential-access event and before confirmed lateral movement.
95% autonomous investigation. 100% human authority.
TandemTrace AI agents completed 38 of 40 recorded investigation actions autonomously. The human analyst retained final verdict approval and containment authorization.
Agents built the case. The analyst controlled the consequential decisions.
Agent-to-human handoff
Orange = AI · black diamond = human · green = responseInvestigation dataset
- Alert source
- EDR · Credential access behavior
- First observed
- 2026-07-17 09:14:07 UTC
- Host
- WKSTN-FIN-042 · Windows 11 23H2
- Identity
- a.mercer · Finance Operations
- Asset context
- Standard endpoint · high data sensitivity
- Endpoint
- 2,416 events · ±30 minutes
- Identity
- 138 sign-ins · 24 hours
- Network
- 31 DNS lookups · 12 proxy sessions
- Prevalence
- 18,642 endpoints · 30 days
- Sources
- EDR, SIEM, Entra ID, DNS, web gateway
| Artifact | Sanitized value | Prevalence | Assessment |
|---|---|---|---|
| Initial SHA-256 | 8d31…b7a2 | 1 host / 30 days | Unique and unsigned |
| Dump tool SHA-256 | 41ac…09de | 1 host / 30 days | Renamed utility |
| Run-key value | CollabUpdate | 1 host | Masquerading persistence |
| Destination | 198.51.100[.]27:443 | 0 prior connections | Sanitized TEST-NET value |
Visual investigation brief
Original detection
EDR alert · rule v4.18Investigation funnel
2,416 → 1Evidence confidence matrix
Cross-source support| Finding | Endpoint | Identity | Network | Confidence |
|---|---|---|---|---|
| Malware execution | ✓ | — | — | Confirmed |
| Credential access | ✓ | Context | — | Confirmed |
| Command and control | ✓ | — | ✓ | High |
| Archive exfiltration | Partial | — | Partial | Unconfirmed |
| Lateral movement | None | None | None | Not observed |
One suspicious process
- LSASS access alert
- One host identified
- Unknown scope and intent
- No response recommendation
Five-stage malicious chain
- Execution and persistence confirmed
- Two credentials at risk
- 18,642 endpoints searched
- C2 probable; exfiltration bounded
Multi-source timeline
09:14–09:21 UTCEvidence that changed the verdict
Execution chain
invoice_viewer.exe spawned an unsigned binary from AppData\Local\Temp, inconsistent with the signed finance application baseline.
Credential access
The child process requested a handle to LSASS with memory-read rights and produced a compressed output file moments later.
Persistence
A new per-user Run key referenced the staged binary. The value name imitated a legitimate collaboration updater.
Network correlation
The process contacted a newly observed TLS endpoint using a rare certificate and a fixed 30-second beacon interval.
Correlated timeline
User launches the weaponized attachment from the downloads directory.
Unsigned executable written to a user-writable temporary path.
Run-key value created for execution at next sign-in.
LSASS access followed by creation of an encrypted archive.
Endpoint isolated; identity-session revocation initiated.
Competing hypotheses tested
| Hypothesis | Test | Disposition |
|---|---|---|
| Authorized administrative tool | Compared signer, path, parent process, software inventory, and change records. | Rejected: no approved tool or maintenance window matched. |
| Security product LSASS access | Compared process identity and access pattern with known EDR modules. | Rejected: binary was unsigned and outside protected directories. |
| Credential theft malware | Correlated LSASS access, archive creation, persistence, and beaconing. | Confirmed. |
Confirmed scope and uncertainty
- Execution, persistence, LSASS access, and archive creation occurred on one workstation.
- The interactive token and one cached service credential were present during LSASS access.
- Seven TLS connections totaling 1.84 MB occurred at roughly 30-second intervals.
- No matching chain appeared across 18,642 peer endpoints.
- Proxy evidence cannot prove the archive was uploaded.
- No evidence proves either exposed credential was used.
- The operator and malware family remain unattributed.
- Memory collection may not contain the complete module.
Containment and follow-up
Keep the endpoint isolated and acquire volatile memory plus the staged binaries.
Rotate the user password and any credentials present in the interactive session.
Search for the file lineage, Run-key value, certificate fingerprint, and beacon cadence.
Retain upload byte counts so future exfiltration assessments are conclusive.
Technical evidence and response
LSASS access evidence
Credential access · T1003.001| Time | Source | Target | Requested rights | Signer / prevalence |
|---|---|---|---|---|
| 09:16:41.228 | svchelper.exe · PID 10308 | lsass.exe · PID 756 | VM_READ · QUERY_INFORMATION | Unsigned · 1/18,642 |
| 09:16:42.019 | svchelper.exe | LSASS memory | 17.6 MB read | Not approved software |
| 09:16:48.602 | 7z.exe · PID 10444 | cache_17.dat | Encrypted archive created | Child of malicious lineage |
Beacon regularity
7 TLS sessions · 1.84 MB totalMedian interval: 30.4 seconds · interval deviation: 2.1 seconds · destination first observed 09:16:58 UTC.
a.mercer
- Exposure
- High confidence
- Action
- Password reset; tokens revoked
- Post-event use
- No anomalous sign-in
svc_fin_export
- Exposure
- Possible secret material
- Action
- Secret rotated
- Post-event use
- No authentication observed
Enterprise prevalence
18,642 endpoints · 30 daysSHA256 = 41ac…09de · lookback 30dRunValue = CollabUpdateUsers in LSASS window · post-event sign-insRemote services · SMB · RDP · WinRMNegative evidence reviewed
Absence tested—not assumed| Question | Sources / window | Result | Meaning |
|---|---|---|---|
| Did the chain execute elsewhere? | EDR · 18,642 hosts · 30d | 0 additional | Scope remains one host |
| Were exposed credentials used? | Entra + service auth · 24h | 0 anomalous | Misuse not observed |
| Was lateral movement attempted? | SMB, RDP, WinRM, service creation · 24h | 0 matches | No confirmed lateral movement |
| Was archive upload proven? | Proxy sessions · event window | Inconclusive | Cannot claim no exfiltration |
Response status
Closing reviewEvidence ledger
Sanitized chain of evidence| ID | Source | Event UTC | Collected | Entity | Verdict contribution |
|---|---|---|---|---|---|
| E-01 | EDR process | 09:14:07 | 09:16:43 | invoice_viewer.exe | Initial execution |
| E-02 | Registry | 09:15:02 | 09:16:45 | CollabUpdate | Persistence confirmed |
| E-03 | EDR memory | 09:16:41 | 09:16:42 | LSASS | Credential access confirmed |
| E-04 | Proxy | 09:16:58 | 09:17:20 | 198.51.100[.]27 | C2 corroboration |
| E-05 | Entra ID | 24h review | 10:18:00 | 2 identities | No misuse observed |
MITRE ATT&CK mapping
| Technique | Observed behavior |
|---|---|
| T1204.002 · Malicious File | User execution of weaponized attachment. |
| T1547.001 · Registry Run Keys | Per-user persistence value. |
| T1003.001 · LSASS Memory | Process memory access consistent with credential dumping. |
| T1071.001 · Web Protocols | Periodic TLS command-and-control traffic. |