Two worked examples

01 · WORKED EXAMPLE A — EARLY SIGNAL & ACCESS VALIDATION

Low-depth interaction can still produce useful intelligence.

Mission context — Observe authentication and validation pressure against a selected edge-technology profile relevant to the organization or sector.
Observed
  • a fixed set of credentials was attempted repeatedly;
  • source addresses changed, but selected client characteristics and cadence recurred;
  • interaction with the controlled profile was followed by session termination;
  • no deeper post-access behavior occurred.
Assessed
  • behavior is consistent with access validation or automated credential testing;
  • repeated characteristics may indicate one shared toolchain or operating workflow.
Not established
  • named actor identity or customer-directed targeting.

Confidence Medium · Relevance Sector-relevant / profile-specific, depending on the evidence.

Operational action — check whether the same credentials or usernames appear in real exposure telemetry, tune edge and identity monitoring, correlate with external CTI and customer logs, and watch for recurrence across the Surface.

Related Research: credential validation across four regions. The page does not imply every deployment produces the same pattern.

02 · WORKED EXAMPLE B — DEEPER ENGAGEMENT

A Live Host produces knowledge beyond a touch or authentication event.

Mission context — Observe post-access workflows against a controlled target without using production as the observation environment.
Observed
  • interactive or non-interactive commands were executed;
  • one or more files were transferred and hashed;
  • the operator enumerated the host or environment;
  • persistence, pivot or outbound activity was attempted;
  • command timing and sequencing were recorded.
Assessed
  • the sequence is consistent with a particular objective, such as persistence preparation, propagation or access resale;
  • tool choice and workflow may relate to other observed sessions.
Not established
  • the actor’s complete campaign or named identity, unless separately evidenced.

Supporting material — session record or replay, command chronology, transferred artifact and analytical hash, network context, related observations, derived detection material.

Operational action — hunt for the artifact or behavior in production telemetry, create or tune detection logic, brief incident response and identity teams, and watch for recurrence.

Related Research: anatomy of a ransomware-worm.

Audience workflows
How each team turns the same Finding into a decision is covered on the Solutions pages
One Finding supports different uses — SOC triage, CTI provenance, detection engineering, incident response, MSSP briefing and executive decision. How each team consumes it is set out on the Solutions and Partners pages.