FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD
All people, organizations, identifiers, legal conclusions, clinical parameters,
and events are invented for text retrieval practice. Do not use as professional
advice, an authoritative standard, a real filing, or an operational instruction.

RECORD 1: EDGE PERIMETER & EDR COMPROMISE TIMELINE (EXCERPT)
Case ID: IR-2026-0814-BLACKBRIAR
Target Enterprise: Meridian Health Solutions (Synthetic Health System)
Lead Investigator: Sarah Lin, Principal Forensic Analyst (GIAC GREM / GNFA)
Date of Incident Triage: 2026-08-14
Network Status: WAN Severed (Complete Physical & Virtual Air-Gap Containment)

1. INITIAL ACCESS & EXPLOITATION TELEMETRY
Timestamp (UTC): 2026-08-14 02:18:41Z
Device: EDGE-VPN-01 (192.168.10.5 / Public WAN 198.51.100.42)
Source IP: 203.0.113.195 (Tor exit node proxy)
Event: Exploitation of unpatched EXAMPLE-VULN-001 (SSL-VPN Buffer Overflow).
Process Spawned: /bin/sh invoked by process `sslvpnd` (PID 4812).
Dropped Artifact: /tmp/.fips_update (SHA-256: 3c9b8821a7df09c84e2079da152b992160d5c07bfa762b3294ee1280fae41d8e)
Artifact Action: Extracted embedded reverse ELF binary connecting to command-and-control (C2) endpoint at `198.51.100.88:8443`.

2. CREDENTIAL HARVESTING & PRIVILEGE ESCALATION
Timestamp (UTC): 2026-08-14 02:44:12Z
Target Host: CORP-DC-01 (Active Directory Domain Controller, 192.168.20.10)
Event ID: 4624 (Successful Network Logon), Type 3
Account: svc_backup_admin (compromised via memory scrape on VPN gateway)
Action: Execution of modified DCSync attack extracting NTDS.dit password hashes for 42 privileged domain accounts.
