CASE-2026-0313-D · 2026-03-13 Initial: Medium · 3.6 Corrected: Critical · 4.0 DEEP CROSS-INVESTIGATION MEMORY

Two alerts. Fifty-seven hosts.
The reviewer read the back catalog.

Two new “unfamiliar sign-in” alerts came in overnight on March 13. The investigator treated them as a continuation of a known phishing campaign and proposed a Standard-tier disposition. The senior reviewer read two prior investigation reports, and the new victims turned out to be part of a fifty-seven-host C2 compromise the company already had on file. Severity moved up, not down.

What fired
2 new “Unfamiliar sign-in properties” alerts overnight (carolyn.c***@, gregory.h***@), bringing the campaign total to 12 known victims across 3 days.
First-pass verdict
MEDIUM · 3.6, phishing campaign continuation. Confidence: MEDIUM. Recommend escalation, but at the same tier as the Mar 12 investigation.
After reviewer’s read
CRITICAL · 4.0, part of confirmed org-wide ContentServer.exe C2 intrusion. Both new hosts in the 57-host list. Both users in the affected user list. One phishing hash classified Known Malicious in the Mar 11 report.
38
FSQL queries
27m
Workers + review
$15K+
Incident cost avoided
2 → 57
Scope expansion
2
Prior cases read
3.6→4.0
Severity moved UP
→ Cross-investigation memory.

The senior reviewer’s first move was to read prior investigation reports. The connection from two new sign-in alerts to a 57-host C2 compromise was one query against the case archive.

→ Severity moves both ways.

YTTRIUM moved severity down. This case moved severity up. The review process is not a confidence layer that confirms the agent’s first answer. It’s a stress test that can correct in either direction.

→ Case archive as queryable data source.

The reviewer searched prior investigations by artifact name and found the connection in one query. The case archive isn’t a filing cabinet. It’s a data source.

Initial Signal

Two more victims. Same campaign, apparently.

At 01:45 UTC on 2026-03-13, Azure AD Identity Protection raised “Unfamiliar sign-in properties” on carolyn.c***@ from host NY-1678. Ninety minutes later, the same alert fired on gregory.h***@ from DC-2823. Two new users. Two new hosts. Same internal /24 subnet as the ten victims surfaced on March 12.

Both users had received O365 ATP Phishing alerts in the days prior, three alerts total, with attachment hashes matching the same automated repackaging pattern as the March 12 campaign (one hash, 100+ filenames seen across O365). Both hosts showed NEW persistence alerts. Carolyn C*** had a prior unfamiliar sign-in event on March 7 that had never been remediated.

The shape of the case was unmistakable: a phishing campaign growing while remediation lags behind.

First Read

Campaign continuation. Same severity as yesterday.

The investigator built the obvious narrative. Phishing delivery confirmed via O365 ATP alerts. Credential compromise inferred via the unfamiliar sign-ins. Two new hosts with NEW persistence mechanisms: WMI subscriptions, AppCertDlls, IFEO debugger, masqueraded tasks, file association changes, system discovery commands. Same internal scanning IP (10.100.21.239) hitting both hosts that had hit three others in the March 12 investigation.

Composite severity score: 3.6, MEDIUM. Disposition: Recommend Escalation. Confidence: MEDIUM, phishing-to-sign-in correlation strong, but causal confirmation blocked by missing Azure AD authentication logs and missing endpoint execution telemetry.

First-pass disposition Critical Threat · Medium-Confidence
RECOMMEND ESCALATION · Phishing Campaign Continuation
Severity: 3.6 / 10 Confidence: MEDIUM Tier: STANDARD Scope: 12 victims / 2 new hosts

The report was thorough. The narrative was correct as far as it went. The escalation was appropriate for what the agent had assembled. It missed the bigger story.

Reviewer’s Move

Before signing off, the reviewer opened a prior case.

The senior reviewer’s first check is not the conclusion. It’s the missed-indicator surface. Today’s hosts have CRITICAL endpoint alerts: SystemService.exe acting as a network server. Fileless PowerShell. ContentServer.exe acting as a network server on NY-1678.

That name was familiar. The reviewer ran a cross-investigation memory check:

# Reviewer’s first move — search prior investigations for the artifact QUERY investigation.title, investigation.date, investigation.disposition FROM ‘docs/investigations/’ WITH investigation.body MATCHES ‘ContentServer.exe’ AFTER 30d → 1 hit: 2026-03-11-contentserver-c2-org-wide-compromise.md

The March 11 investigation had confirmed ContentServer.exe as a command-and-control backdoor operating across 57 hosts with three external C2 IPs (8.39.141.5, 123.201.124.227, 208.184.220.60), active since March 4. The reviewer pulled the affected-host list and the affected-user list, and cross-referenced the current investigation’s two new victims against both.

Connection

Both hosts. Both users. One hash, already Known Malicious.

Cross-investigation memory
CURRENT · 2026-03-13
Unfamiliar Sign-In Continuation
  • carolyn.c***@ · NY-1678 · 172.16.16.107
  • gregory.h***@ · DC-2823 · 172.16.16.94
  • 3 O365 ATP Phishing alerts
  • Hash e7fc03267e... sent to carolyn.c*** Mar 12
  • ContentServer.exe alert on NY-1678 (Mar 9, null status)
PRIOR · 2026-03-11
ContentServer.exe C2: 57-Host Compromise
  • NY-1678 in affected-host list ✓
  • DC-2823 in affected-host list ✓
  • carolyn.c***@ in affected-user list ✓
  • gregory.h***@ in affected-user list ✓
  • Hash e7fc03267e... classified Known Malicious
Every entity in the current investigation maps to the prior compromise. The two “new” victims weren’t new. They were among the 57 already-compromised users that the org-wide intrusion investigation had identified two days earlier. The phishing attachment hash had already been classified as Known Malicious. The CRITICAL ContentServer.exe alert on NY-1678 was the same C2 backdoor the March 11 report had named.

The current investigation wasn’t a campaign continuation. It was day three of an ongoing organization-wide compromise where every prior day’s escalation recommendations remained unactioned.
What Changed

Severity moved up. The reframe moved with it.

First-pass
Medium · 3.6
Phishing campaign continuation. 2 new victims overnight, same infrastructure. Recommend escalation, standard tier. Confidence MEDIUM.
After review
Critical · 4.0
Part of confirmed org-wide ContentServer.exe C2 intrusion. 57-host scope already on file. 3 days of unactioned escalation recommendations. Confidence HIGH.

The senior reviewer materially changed four things about the investigation’s conclusions:

  • Severity: 3.6 → 4.0 (Standard → Deep). The numeric movement is small; the framing movement is the point.
  • Confidence: MEDIUM → HIGH. The C2 cross-reference closes the causal gap that the first-pass agent had explicitly flagged.
  • Frame: from “phishing campaign continuation” to “part of confirmed org-wide ContentServer.exe C2 intrusion.”
  • Urgency: the business summary now opens by noting that three consecutive days of escalation recommendations appear unactioned. This is the third investigation in a series, and the campaign is growing while remediation lags.

The disposition stayed the same: RECOMMEND ESCALATION. But the meaning changed. The original report would have landed in the SOC as one more case in a busy week. The corrected report landed as the third day of an active org-wide compromise that someone needed to actually own.

01

Read the back catalog before signing off.

The reviewer searched prior investigation reports for ContentServer.exe. One query found the report. The connection between today’s two alerts and the 57-host compromise was a thirty-second pivot, not a feat of analyst intuition.

02

Severity moves both ways.

The first-pass agent here underestimated severity. The first-pass agent on YTTRIUM overestimated it. The senior reviewer pattern is the same: re-test the load-bearing claims against the evidence, including evidence in other case files. Direction of movement is not the point. Accuracy is.

03

Cross-investigation memory beats institutional memory.

“Someone on the team should have remembered the ContentServer.exe case” is not a workable assumption in a SOC where the team rotates and case volume is high. Cross-investigation memory belongs in the agent, not in the analyst’s head. It has to be searchable on artifact name, IOC hash, affected entity, and disposition.

04

Unactioned recommendations compound.

This is day three of a campaign growing while remediation lags. The reviewer’s reframe doesn’t just upgrade severity. It notes that three days of escalation recommendations appear unactioned. The agent surfaces the lag as evidence, not subtext.

Queries, sources & gaps

Key queries: investigator + reviewer

Q1 Pull new unfamiliar sign-in alerts (4h) INTAKE
QUERY detection_finding.** WITH detection_finding.message = ‘Unfamiliar sign-in properties’ AND detection_finding.status_id = NEW AFTER 4h
2 NEW alerts — carolyn.c***@ (01:45 UTC, NY-1678) and gregory.h***@ (03:26 UTC, DC-2823)
Q2 Pull O365 phishing alerts for the 2 affected hosts (7d) ENRICH
QUERY detection_finding.message, detection_finding.time, detection_finding.evidences.file.hash WITH detection_finding.message = ‘Office 365 Advanced Threat Protection Phishing Alert’ AND detection_finding.device.hostname IN (‘NY-1678’, ‘DC-2823’) AFTER 7d
3 phishing alerts — 2 to carolyn.c*** (Mar 9, Mar 12), 1 to gregory.h*** (Mar 11). All hashes show the same automated 100+-filename repackaging pattern.
Q14–Q22 Per-host 7-day persistence + behavior sweep (NY-1678, DC-2823) 19 NEW
QUERY detection_finding.message, detection_finding.severity_id, detection_finding.status_id, detection_finding.status_detail, detection_finding.time WITH detection_finding.evidences.dst_endpoint.ip = ‘172.16.16.107’ AFTER 7d
19 NEW alerts combined across both hosts — file association changes, exploration, cmd.exe, WMI subscriptions, AppCertDlls, IFEO debugger, masqueraded tasks, hardware discovery. CRITICAL null-status: ContentServer.exe, SystemService.exe, fileless PowerShell.
R·Q1 REVIEWER · search prior investigations for “ContentServer.exe” CROSS-INVESTIGATION
# Senior reviewer’s first move — read the back catalog before signing off QUERY investigation.title, investigation.date, investigation.disposition, investigation.affected_hosts, investigation.affected_users FROM ‘docs/investigations/’ WITH investigation.body MATCHES ‘ContentServer.exe’ AFTER 30d
1 hit: 2026-03-11-contentserver-c2-org-wide-compromise.md — 57 hosts, 3 external C2 IPs, active since Mar 4. Both NY-1678 and DC-2823 in affected-host list. Both carolyn.c*** and gregory.h*** in affected-user list.
R·Q2 REVIEWER · check phishing attachment hash against prior IOC database KNOWN MALICIOUS
QUERY ioc.hash, ioc.classification, ioc.source_investigation, ioc.first_seen FROM ‘docs/investigations/’ WITH ioc.hash = ‘e7fc03267e47814e23e004e5f3a1205b’
1 hit — classified Known Malicious in the 2026-03-11 ContentServer.exe investigation. Sent to carolyn.c***@ as an O365 phishing attachment on Mar 12.
R·Q3 REVIEWER · broader search on scanning IP 10.100.21.239 (7d) INSUFFICIENT DATA
QUERY *.message, *.time WITH %ip = ‘10.100.21.239’ AFTER 7d
1 record — only osint_inventory_info (“last seen Mar 13 03:37 UTC, active”). No detection findings. No process activity. Identity remains unknown. Now scanning 5 hosts across 2 investigations.

Showing 6 of 38 queries. Full investigator + reviewer trails in queries.md and review.md.

Sources queried · with status

SourceStatusNotes
detection.alerts (SecLake)HITPrimary intake; identity + persistence + endpoint alerts across 2 hosts
email.o365 (ATP)PARTIAL3 phishing alerts captured; status_id = UNKNOWN; cannot confirm investigation lifecycle
edr.crowdstrike (endpoint)PARTIALCRITICAL null-status records; no execution telemetry to confirm attachment opening
docs/investigations/ (case archive)HITReviewer cross-referenced prior cases. Loaded contentserver-c2 report + IOC database.
identity.azuread (sign-in logs)GAPNot ingested; cannot verify sign-in source IP, geo, MFA
identity.azuread (audit logs)GAPNo account_change events; cannot detect post-compromise privilege changes
network.flow (on-prem)GAPNo flow data for 172.16.16.x; cannot trace lateral movement from 10.100.21.239

Gaps explicitly catalogued

  • No Azure AD sign-in logs in mesh; cannot verify sign-in source IP, geo, MFA, session detail.
  • AAD connector “UnsupportedAlertType”; cannot determine what made sign-ins “unfamiliar” (geo, device, browser).
  • No account_change events; cannot detect password resets, MFA changes, role modifications post-compromise.
  • Phishing alerts status_id: UNKNOWN; cannot confirm O365 investigation/resolution lifecycle.
  • No click / execution telemetry; cannot confirm users opened malicious attachments.
  • Mar 12 escalation status uncertain; 10 prior accounts still appear compromised; verify with SOC whether prior recommendation was received.

MITRE ATT&CK · current case + prior compromise

TechniqueTacticEvidence
T1566.001Initial Access · Spearphishing Attachment3 O365 ATP phishing alerts; hash e7fc03267e… classified Known Malicious in prior case
T1078Initial Access · Valid Accounts2 new “Unfamiliar sign-in” alerts on NY-1678 and DC-2823
T1546 / T1543 / T1053Persistence · multipleWMI, AppCertDlls, IFEO, masqueraded tasks on both hosts (NEW)
T1059Execution · Command and ScriptingSuspicious cmd.exe (5 NEW), fileless PowerShell CRITICAL on NY-1678
T1071C2 · Application Layer ProtocolContentServer.exe + SystemService.exe + flexnetls.jar acting as network servers, cross-confirmed against 57-host prior compromise