Two alerts. Fifty-seven hosts.
The reviewer read the back catalog.
Two new “unfamiliar sign-in” alerts came in overnight on March 13. The investigator treated them as a continuation of a known phishing campaign and proposed a Standard-tier disposition. The senior reviewer read two prior investigation reports, and the new victims turned out to be part of a fifty-seven-host C2 compromise the company already had on file. Severity moved up, not down.
The senior reviewer’s first move was to read prior investigation reports. The connection from two new sign-in alerts to a 57-host C2 compromise was one query against the case archive.
YTTRIUM moved severity down. This case moved severity up. The review process is not a confidence layer that confirms the agent’s first answer. It’s a stress test that can correct in either direction.
The reviewer searched prior investigations by artifact name and found the connection in one query. The case archive isn’t a filing cabinet. It’s a data source.
Two more victims. Same campaign, apparently.
At 01:45 UTC on 2026-03-13, Azure AD Identity Protection raised “Unfamiliar sign-in
properties” on carolyn.c***@ from host NY-1678. Ninety minutes later,
the same alert fired on gregory.h***@ from DC-2823. Two new users.
Two new hosts. Same internal /24 subnet as the ten victims surfaced on March 12.
Both users had received O365 ATP Phishing alerts in the days prior, three alerts total, with attachment hashes matching the same automated repackaging pattern as the March 12 campaign (one hash, 100+ filenames seen across O365). Both hosts showed NEW persistence alerts. Carolyn C*** had a prior unfamiliar sign-in event on March 7 that had never been remediated.
The shape of the case was unmistakable: a phishing campaign growing while remediation lags behind.
Campaign continuation. Same severity as yesterday.
The investigator built the obvious narrative. Phishing delivery confirmed via O365 ATP alerts.
Credential compromise inferred via the unfamiliar sign-ins. Two new hosts with NEW persistence
mechanisms: WMI subscriptions, AppCertDlls, IFEO debugger, masqueraded tasks, file association
changes, system discovery commands. Same internal scanning IP (10.100.21.239)
hitting both hosts that had hit three others in the March 12 investigation.
Composite severity score: 3.6, MEDIUM. Disposition: Recommend Escalation. Confidence: MEDIUM, phishing-to-sign-in correlation strong, but causal confirmation blocked by missing Azure AD authentication logs and missing endpoint execution telemetry.
The report was thorough. The narrative was correct as far as it went. The escalation was appropriate for what the agent had assembled. It missed the bigger story.
Before signing off, the reviewer opened a prior case.
The senior reviewer’s first check is not the conclusion. It’s the missed-indicator surface.
Today’s hosts have CRITICAL endpoint alerts: SystemService.exe
acting as a network server. Fileless PowerShell. ContentServer.exe acting as a
network server on NY-1678.
That name was familiar. The reviewer ran a cross-investigation memory check:
The March 11 investigation had confirmed ContentServer.exe as a command-and-control
backdoor operating across 57 hosts with three external C2 IPs
(8.39.141.5, 123.201.124.227, 208.184.220.60),
active since March 4. The reviewer pulled the affected-host list and the affected-user list,
and cross-referenced the current investigation’s two new victims against both.
Both hosts. Both users. One hash, already Known Malicious.
- carolyn.c***@ · NY-1678 · 172.16.16.107
- gregory.h***@ · DC-2823 · 172.16.16.94
- 3 O365 ATP Phishing alerts
- Hash
e7fc03267e...sent to carolyn.c*** Mar 12 - ContentServer.exe alert on NY-1678 (Mar 9, null status)
- NY-1678 in affected-host list ✓
- DC-2823 in affected-host list ✓
- carolyn.c***@ in affected-user list ✓
- gregory.h***@ in affected-user list ✓
- Hash
e7fc03267e...classified Known Malicious ✓
ContentServer.exe alert on NY-1678
was the same C2 backdoor the March 11 report had named.
The current investigation wasn’t a campaign continuation. It was day three of an ongoing organization-wide compromise where every prior day’s escalation recommendations remained unactioned.
Severity moved up. The reframe moved with it.
The senior reviewer materially changed four things about the investigation’s conclusions:
- Severity: 3.6 → 4.0 (Standard → Deep). The numeric movement is small; the framing movement is the point.
- Confidence: MEDIUM → HIGH. The C2 cross-reference closes the causal gap that the first-pass agent had explicitly flagged.
- Frame: from “phishing campaign continuation” to “part of confirmed org-wide ContentServer.exe C2 intrusion.”
- Urgency: the business summary now opens by noting that three consecutive days of escalation recommendations appear unactioned. This is the third investigation in a series, and the campaign is growing while remediation lags.
The disposition stayed the same: RECOMMEND ESCALATION. But the meaning changed. The original report would have landed in the SOC as one more case in a busy week. The corrected report landed as the third day of an active org-wide compromise that someone needed to actually own.
Read the back catalog before signing off.
The reviewer searched prior investigation reports for ContentServer.exe. One query found the report. The connection between today’s two alerts and the 57-host compromise was a thirty-second pivot, not a feat of analyst intuition.
Severity moves both ways.
The first-pass agent here underestimated severity. The first-pass agent on YTTRIUM overestimated it. The senior reviewer pattern is the same: re-test the load-bearing claims against the evidence, including evidence in other case files. Direction of movement is not the point. Accuracy is.
Cross-investigation memory beats institutional memory.
“Someone on the team should have remembered the ContentServer.exe case” is not a workable assumption in a SOC where the team rotates and case volume is high. Cross-investigation memory belongs in the agent, not in the analyst’s head. It has to be searchable on artifact name, IOC hash, affected entity, and disposition.
Unactioned recommendations compound.
This is day three of a campaign growing while remediation lags. The reviewer’s reframe doesn’t just upgrade severity. It notes that three days of escalation recommendations appear unactioned. The agent surfaces the lag as evidence, not subtext.
Key queries: investigator + reviewer
Q1 Pull new unfamiliar sign-in alerts (4h) INTAKE
Q2 Pull O365 phishing alerts for the 2 affected hosts (7d) ENRICH
Q14–Q22 Per-host 7-day persistence + behavior sweep (NY-1678, DC-2823) 19 NEW
R·Q1 REVIEWER · search prior investigations for “ContentServer.exe” CROSS-INVESTIGATION
2026-03-11-contentserver-c2-org-wide-compromise.md — 57 hosts, 3 external C2 IPs, active since Mar 4. Both NY-1678 and DC-2823 in affected-host list. Both carolyn.c*** and gregory.h*** in affected-user list.R·Q2 REVIEWER · check phishing attachment hash against prior IOC database KNOWN MALICIOUS
Known Malicious in the 2026-03-11 ContentServer.exe investigation. Sent to carolyn.c***@ as an O365 phishing attachment on Mar 12.R·Q3 REVIEWER · broader search on scanning IP 10.100.21.239 (7d) INSUFFICIENT DATA
osint_inventory_info (“last seen Mar 13 03:37 UTC, active”). No detection findings. No process activity. Identity remains unknown. Now scanning 5 hosts across 2 investigations.
Showing 6 of 38 queries. Full investigator + reviewer trails in queries.md and review.md.
Sources queried · with status
| Source | Status | Notes |
|---|---|---|
| detection.alerts (SecLake) | HIT | Primary intake; identity + persistence + endpoint alerts across 2 hosts |
| email.o365 (ATP) | PARTIAL | 3 phishing alerts captured; status_id = UNKNOWN; cannot confirm investigation lifecycle |
| edr.crowdstrike (endpoint) | PARTIAL | CRITICAL null-status records; no execution telemetry to confirm attachment opening |
| docs/investigations/ (case archive) | HIT | Reviewer cross-referenced prior cases. Loaded contentserver-c2 report + IOC database. |
| identity.azuread (sign-in logs) | GAP | Not ingested; cannot verify sign-in source IP, geo, MFA |
| identity.azuread (audit logs) | GAP | No account_change events; cannot detect post-compromise privilege changes |
| network.flow (on-prem) | GAP | No flow data for 172.16.16.x; cannot trace lateral movement from 10.100.21.239 |
Gaps explicitly catalogued
- No Azure AD sign-in logs in mesh; cannot verify sign-in source IP, geo, MFA, session detail.
- AAD connector “UnsupportedAlertType”; cannot determine what made sign-ins “unfamiliar” (geo, device, browser).
- No account_change events; cannot detect password resets, MFA changes, role modifications post-compromise.
- Phishing alerts status_id: UNKNOWN; cannot confirm O365 investigation/resolution lifecycle.
- No click / execution telemetry; cannot confirm users opened malicious attachments.
- Mar 12 escalation status uncertain; 10 prior accounts still appear compromised; verify with SOC whether prior recommendation was received.
MITRE ATT&CK · current case + prior compromise
| Technique | Tactic | Evidence |
|---|---|---|
| T1566.001 | Initial Access · Spearphishing Attachment | 3 O365 ATP phishing alerts; hash e7fc03267e… classified Known Malicious in prior case |
| T1078 | Initial Access · Valid Accounts | 2 new “Unfamiliar sign-in” alerts on NY-1678 and DC-2823 |
| T1546 / T1543 / T1053 | Persistence · multiple | WMI, AppCertDlls, IFEO, masqueraded tasks on both hosts (NEW) |
| T1059 | Execution · Command and Scripting | Suspicious cmd.exe (5 NEW), fileless PowerShell CRITICAL on NY-1678 |
| T1071 | C2 · Application Layer Protocol | ContentServer.exe + SystemService.exe + flexnetls.jar acting as network servers, cross-confirmed against 57-host prior compromise |
See Workers read your back catalog.
Bring an alert and the last quarter of investigation reports.
