FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD All people, organizations, identifiers, legal conclusions, clinical parameters, and events are invented for text retrieval practice. Do not use as professional advice, an authoritative standard, a real filing, or an operational instruction. RECORD 1: EDGE PERIMETER & EDR COMPROMISE TIMELINE (EXCERPT) Case ID: IR-2026-0814-BLACKBRIAR Target Enterprise: Meridian Health Solutions (Synthetic Health System) Lead Investigator: Sarah Lin, Principal Forensic Analyst (GIAC GREM / GNFA) Date of Incident Triage: 2026-08-14 Network Status: WAN Severed (Complete Physical & Virtual Air-Gap Containment) 1. INITIAL ACCESS & EXPLOITATION TELEMETRY Timestamp (UTC): 2026-08-14 02:18:41Z Device: EDGE-VPN-01 (192.168.10.5 / Public WAN 198.51.100.42) Source IP: 203.0.113.195 (Tor exit node proxy) Event: Exploitation of unpatched EXAMPLE-VULN-001 (SSL-VPN Buffer Overflow). Process Spawned: /bin/sh invoked by process `sslvpnd` (PID 4812). Dropped Artifact: /tmp/.fips_update (SHA-256: 3c9b8821a7df09c84e2079da152b992160d5c07bfa762b3294ee1280fae41d8e) Artifact Action: Extracted embedded reverse ELF binary connecting to command-and-control (C2) endpoint at `198.51.100.88:8443`. 2. CREDENTIAL HARVESTING & PRIVILEGE ESCALATION Timestamp (UTC): 2026-08-14 02:44:12Z Target Host: CORP-DC-01 (Active Directory Domain Controller, 192.168.20.10) Event ID: 4624 (Successful Network Logon), Type 3 Account: svc_backup_admin (compromised via memory scrape on VPN gateway) Action: Execution of modified DCSync attack extracting NTDS.dit password hashes for 42 privileged domain accounts.