Audience-scoped reporting
The same underlying evidence, correctly scoped per audience — nothing is added or invented
Technical: ATT&CK, IOCs, evidence, actions taken
INC-2041 — Technical incident record
Identification
- INC-2041 · opened Fri, 21 Aug 2026 15:04:00 UTC · category Targeted intrusion
- First signal Fri, 21 Aug 2026 13:29:00 UTC, detected Fri, 21 Aug 2026 14:56:00 UTC.
Classification
- Severity Critical · risk score 64 · agent confidence 88% · status Investigating.
ATT&CK mapping
- TA0001 → T1566 → T1566.002 (Phishing): A spearphishing link to a credential-harvest page was delivered to the Grid Operations distribution list and clicked by one recipient.
- TA0001 → T1078 → T1078.002 (Valid Accounts): The harvested domain account subsequently authenticated successfully from an ASN never previously seen for this identity.
- TA0002 → T1059 → T1059.001 (Command and Scripting Interpreter): Base64-encoded PowerShell executed on the historian under the same account, spawned from a remote management session.
- TA0006 → T1003 → T1003.001 (OS Credential Dumping): A handle open against LSASS by a non-allowlisted process was blocked by the endpoint agent five minutes later.
Evidence
- [Supporting] Spearphishing link delivered — Message from grid-compliance@northwind-notices.example to 14 Grid Operations recipients; URL detonation returned a credential-harvest verdict after delivery. (source: email, confidence 92%) :: verdict=delivered-then-reclassified url=https://cdn-metrics-sync.example/auth/verify recipients=14 clicked=1
- [Supporting] Unfamiliar-ASN sign-in success — IDN-2003 (L. Marchetti, Elevated) signed in successfully from 203.0.113.77 after MFA push approval; no prior sign-in from this ASN in 180 days. (source: iam, confidence 89%) :: user=l.marchetti result=success mfa=push-approved src=203.0.113.77 asn_first_seen=true
- [Supporting] Encoded PowerShell on historian — powershell.exe -enc <redacted> spawned by wsmprovhost.exe on nwu-scada-hist-01 under the same account. (source: edr, confidence 94%) :: host=nwu-scada-hist-01 parent=wsmprovhost.exe cmd=powershell.exe -nop -w hidden -enc JABzAD0A...
- [Supporting] LSASS access attempt blocked — Non-allowlisted process requested PROCESS_VM_READ on lsass.exe; endpoint agent blocked and quarantined the loader artefact. (source: edr, confidence 96%) :: host=nwu-scada-hist-01 target=lsass.exe access=0x1010 action=blocked artefact=hollowkey-loader
- [Supporting] Indicator match: CINDER VOLE infrastructure — 203.0.113.77 and cdn-metrics-sync.example both match AMBER-marked indicators attributed to CINDER VOLE / campaign QUIET FURNACE. (source: ti, confidence 88%) :: ioc=IOC-5001,IOC-5002 actor=TA-CINDER-VOLE campaign=CMP-QUIET-FURNACE
- [Contextual] Asset criticality: tier 5 — nwu-scada-hist-01 is a tier-5 Grid Operations asset, OT-adjacent, owner L. Marchetti. (source: cmdb, confidence 99%) :: asset=AST-1001 criticality=5 bu=Grid Operations exposure=Internal
- [Contradicting] No outbound C2 confirmed — Egress flow review for the historian shows no sustained beaconing to the indicator infrastructure — this argues against completed C2 establishment. (source: firewall, confidence 71%) :: host=10.42.10.21 dst=203.0.113.77 sessions=2 bytes_out=41KB periodicity=none
- [Contextual] Patch lag on adjacent gateway — nwu-ot-gw-04 carries an open management-interface finding (CVSS 8.2), raising blast-radius exposure if lateral movement continues. (source: vuln, confidence 80%) :: asset=AST-1002 finding=VLN-3002 cvss=8.2 status=open
Threat intelligence
- IOC-5001, IOC-5002, IOC-5007, IOC-5008, TA-CINDER-VOLE, CMP-QUIET-FURNACE, MW-HOLLOWKEY
Correlation logic
- Four signals from four independent sources were grouped into one incident: the email verdict (T1566.002), the unfamiliar-ASN sign-in for the same identity (T1078.002), execution on a host that identity administers (T1059.001), and the credential-dumping attempt on that same host (T1003.001) — all within a 90-minute window and sharing identity IDN-2003 and asset AST-1001.
Response
- Recommended action: ACT-ISOLATE. Decision gate: Authorized Approver approval required — Isolation of a tier-5 Grid Operations asset is destructive to operational visibility. The agent will not execute it automatically; an authorized human approval is required and will be logged.
Source evidence (identical across all four audiences)
INC-2041/EV-1, INC-2041/EV-2, INC-2041/EV-3, INC-2041/EV-4, INC-2041/EV-5, INC-2041/EV-6, INC-2041/EV-7, INC-2041/EV-8
Audit check passed: same source evidence, only the scoping differs.
Deliberately excluded from this view
- Board materiality commentary
- Regulator attestation fields
Compliance flags
Generated views only — no regulatory filing is performed
Grid Operator Security Directive (synthetic) · Determination and internal notification logged 10 minutes after approval. · cases INC-2044
Grid Operator Security Directive (synthetic) · Offline replica restore verified post-incident. · cases INC-2044
Internal Control Standard NW-SEC-14 · Two identities without number matching; remediation scheduled. · cases INC-2043, INC-2046
Internal Control Standard NW-SEC-09 · Backup vault regression identified; enforcement in change window. · cases INC-2044
Customer Data Handling Policy (synthetic) · Assessment completed; no confirmed customer data exfiltration. · cases INC-2042