Deep Lateral Movement & Account Compromise Forensic Report

Comprehensive Security Event Correlation on Mounted Windows 11 Image E:\

Analysis Date: 2026-05-31
Incident Timeframe: January 2023
Investigation Standard: MITRE ATT&CK Mapping
Active Subnet Scope: 172.16.0.0/16
Primary Compromised Account
wacsvc / rsydow-a
Threat Actor Pivot IP
172.16.6.18
Lateral Movement Vector
Network Type 3 / RDP Type 10
Forensic Ingress Station
172.16.5.25
DEEP CORRELATION ANALYSIS & PATH DETERMINATION
Through advanced Event Log correlation, we successfully mapped the threat actor's lateral movement path. The attacker originally compromised the user account `rsydow-a` on a pivot host **`172.16.6.18`**. Between January 16 and 17, they used these credentials to establish 85 Network Logons (Logon Type 3) to this machine. On January 17 at 14:43:03 UTC, the attacker escalated their access by launching a remote RDP Session (Logon Type 10) as the service account `wacsvc`, originating from the same pivot host `172.16.6.18`. In this session, they executed their browser history harvesting actions. Additionally, RDP logs show a subsequent ingress on January 23 as `wacsvc`, originating from **`172.16.4.9`**, during which the remote execution toolkit was staged. Finally, the logs capture the DFIR response team's ingress on January 24 at 18:04:57 UTC from `172.16.5.25` under the analyst account `cbarton-a`, which installed the triage utility `F-Response Subject Service` and acquired kernel memory.

Visual Lateral Movement Mapping

Pivot Host
172.16.6.18
Compromised Account: rsydow-a
Jan 16-17 Network Type 3 Pivot
Target Host (Current System)
E:\ Windows 11
Privilege Escalation to: wacsvc
Jan 24 Forensic Response
Forensic Workstation
172.16.5.25
Analyst Account: cbarton-a

Chronological Lateral Movement & Response Timeline

Correlated across Security, System, LocalSessionManager, and WMI-Activity event logs.

Initial Remote Reconnaissance & Network Pivot

2023-01-16 17:01:03 to 2023-01-17 19:01:34 | User: rsydow-a | Vector: Network (Type 3)

The attacker established 85 Network Logons (Type 3) using the compromised credentials of account rsydow-a, originating from pivot host 172.16.6.18.

Privilege Escalation & Interactive RDP Session

2023-01-17 14:43:03 | User: wacsvc | Vector: RDP (Type 10)

The attacker logged in remotely as service account wacsvc via RDP (Type 10) from the pivot host 172.16.6.18.

Action on Objectives: History Harvesting Tool Executed

2023-01-17 18:00:27 | User: wacsvc | Vector: System

Under the wacsvc session, the attacker executed the browser history gathering tool bhv.exe exactly once, creating bhv.cfg, dumping the logs, and subsequently deleting the executable.

Second Wave Staging Session

2023-01-23 20:53:05 | User: wacsvc | Vector: RDP (Type 10)

A new RDP session was established for the service account wacsvc originating from 172.16.4.9, staging `ph.exe` and `px.exe` in the Downloads directory.

Incident Detection & DFIR Ingress

2023-01-24 18:04:57 | User: cbarton-a | Vector: Network (Type 3)

Forensic analyst `cbarton-a` logged in remotely from the incident response server `172.16.5.25` using Kerberos to triage the compromised system.

Incident Response: Memory Acquisition Loaded

2023-01-24 18:04:59 | User: System | Vector: System

The DFIR team installed the **`F-Response Subject Service`** and loaded the **`mnemosyne`** (Mnemosyne.sys) kernel memory acquisition driver to capture physical memory and preserve volatile evidence.

January 2023 Unique Logon Sessions
User Account Logon Mechanism Source IP Address Session Count First Logon Time Last Logon Time
tdungan 3 - Network (SMB/WinRM) 172.16.30.20 4 2023-01-05 20:49:46 2023-01-09 16:57:23
UMFD-5 2 - Interactive (Local) - 2 2023-01-05 20:49:47 2023-01-24 14:17:12
DWM-5 2 - Interactive (Local) - 4 2023-01-05 20:49:47 2023-01-24 14:17:12
tdungan 10 - RDP (Remote) 172.16.30.20 2 2023-01-05 20:49:49 2023-01-09 16:57:25
tdungan 11 - Unknown ::1 1 2023-01-05 21:41:01 2023-01-05 21:41:01
UMFD-6 2 - Interactive (Local) - 1 2023-01-09 16:57:23 2023-01-09 16:57:23
DWM-6 2 - Interactive (Local) - 2 2023-01-09 16:57:24 2023-01-09 16:57:24
rsydow-a 3 - Network (SMB/WinRM) 172.16.4.4 25 2023-01-12 05:02:19 2023-01-13 22:07:03
tdungan 3 - Network (SMB/WinRM) 172.16.30.8 14 2023-01-12 06:19:41 2023-01-24 14:17:11
UMFD-7 2 - Interactive (Local) - 1 2023-01-12 06:19:41 2023-01-12 06:19:41
DWM-7 2 - Interactive (Local) - 2 2023-01-12 06:19:41 2023-01-12 06:19:41
tdungan 10 - RDP (Remote) 172.16.30.8 7 2023-01-12 06:19:43 2023-01-24 14:17:13
UMFD-8 2 - Interactive (Local) - 1 2023-01-12 20:40:53 2023-01-12 20:40:53
DWM-8 2 - Interactive (Local) - 2 2023-01-12 20:40:53 2023-01-12 20:40:53
UMFD-9 2 - Interactive (Local) - 1 2023-01-13 18:32:14 2023-01-13 18:32:14
DWM-9 2 - Interactive (Local) - 2 2023-01-13 18:32:14 2023-01-13 18:32:14
rsydow-a 3 - Network (SMB/WinRM) 172.16.4.7 42 2023-01-14 17:29:53 2023-01-23 02:09:11
rsydow-a 3 - Network (SMB/WinRM) 172.16.6.18 85 2023-01-16 17:01:03 2023-01-17 19:01:34
UMFD-10 2 - Interactive (Local) - 1 2023-01-17 00:12:36 2023-01-17 00:12:36
DWM-10 2 - Interactive (Local) - 2 2023-01-17 00:12:36 2023-01-17 00:12:36
UMFD-11 2 - Interactive (Local) - 1 2023-01-17 04:21:54 2023-01-17 04:21:54
DWM-11 2 - Interactive (Local) - 2 2023-01-17 04:21:54 2023-01-17 04:21:54
UMFD-12 2 - Interactive (Local) - 1 2023-01-17 14:42:00 2023-01-17 14:42:00
DWM-12 2 - Interactive (Local) - 2 2023-01-17 14:42:00 2023-01-17 14:42:00
wacsvc 10 - RDP (Remote) 172.16.6.18 12 2023-01-17 14:43:03 2023-01-19 14:28:14
tdungan 3 - Network (SMB/WinRM) 172.16.30.3 8 2023-01-17 23:30:53 2023-01-19 18:01:58
UMFD-13 2 - Interactive (Local) - 1 2023-01-17 23:30:54 2023-01-17 23:30:54
DWM-13 2 - Interactive (Local) - 2 2023-01-17 23:30:54 2023-01-17 23:30:54
tdungan 10 - RDP (Remote) 172.16.30.3 4 2023-01-17 23:30:56 2023-01-19 18:02:01
UMFD-14 2 - Interactive (Local) - 10 2023-01-18 14:49:52 2023-01-19 18:01:59
DWM-14 2 - Interactive (Local) - 20 2023-01-18 14:49:52 2023-01-19 18:01:59
UMFD-15 2 - Interactive (Local) - 5 2023-01-19 18:45:35 2023-01-23 14:37:27
DWM-15 2 - Interactive (Local) - 10 2023-01-19 18:45:36 2023-01-23 14:37:27
tdungan 3 - Network (SMB/WinRM) 172.16.30.14 6 2023-01-22 23:30:58 2023-01-23 14:52:54
tdungan 10 - RDP (Remote) 172.16.30.14 3 2023-01-22 23:31:01 2023-01-23 14:52:56
UMFD-0 2 - Interactive (Local) - 3 2023-01-23 14:51:17 2023-01-25 14:38:28
UMFD-1 2 - Interactive (Local) - 3 2023-01-23 14:51:17 2023-01-25 14:38:28
DWM-1 2 - Interactive (Local) - 6 2023-01-23 14:51:17 2023-01-25 14:38:29
UMFD-2 2 - Interactive (Local) - 3 2023-01-23 14:52:55 2023-01-25 14:38:49
DWM-2 2 - Interactive (Local) - 6 2023-01-23 14:52:55 2023-01-25 14:38:49
tdungan 9 - NewCredentials (RunAs /b) - 2 2023-01-23 15:00:42 2023-01-25 14:50:15
tdungan 9 - NewCredentials (RunAs /b) ::1 17 2023-01-23 15:14:05 2023-01-25 15:07:55
wacsvc 3 - Network (SMB/WinRM) fe80::7e6b:763c:b405:22b4 1 2023-01-23 16:08:23 2023-01-23 16:08:23
UMFD-3 2 - Interactive (Local) - 1 2023-01-23 20:52:48 2023-01-23 20:52:48
DWM-3 2 - Interactive (Local) - 2 2023-01-23 20:52:48 2023-01-23 20:52:48
wacsvc 10 - RDP (Remote) 172.16.4.9 2 2023-01-23 20:53:05 2023-01-23 20:53:05
UMFD-4 2 - Interactive (Local) - 1 2023-01-24 03:21:29 2023-01-24 03:21:29
DWM-4 2 - Interactive (Local) - 2 2023-01-24 03:21:29 2023-01-24 03:21:29
cbarton-a 3 - Network (SMB/WinRM) 172.16.5.25 26 2023-01-24 18:04:57 2023-01-24 18:04:59
tdungan 3 - Network (SMB/WinRM) 172.16.30.23 5 2023-01-25 07:11:09 2023-01-25 14:38:48
tdungan 10 - RDP (Remote) 172.16.30.23 2 2023-01-25 14:19:26 2023-01-25 14:38:50
slevine 3 - Network (SMB/WinRM) 172.16.6.18 1 2023-01-25 14:26:57 2023-01-25 14:26:57
wacsvc 3 - Network (SMB/WinRM) 172.16.6.18 1 2023-01-25 14:43:02 2023-01-25 14:43:02

Prefetch Execution Evidence

Service Installations (January 2023)

Service Name Image Path Installation Time Account Context Status
MpKsl80b1fd2a C:/Windows/system32/MpEngineStore/MpKslDrv.sys 2023-01-05 02:24:41 System Service
Ec2Config "C:/Program Files/Amazon/Ec2ConfigService/Ec2Config.exe" 2023-01-17 14:43:59 LocalSystem System Service
MpKsle2439143 C:/ProgramData/Microsoft/Windows Defender/Definition Updates/{1FEC7FC9-D47D-4480-85E5-AE4DD6CCA988}/MpKslDrv.sys 2023-01-24 00:51:58 System Service
F-Response Subject Service "C:/windows/subject_srv.exe" -s "172.16.5.25:5682" -l 3262 -v "F-Response Subject Service" -k "155522845" 2023-01-24 18:04:59 LocalSystem Forensic Tool
mnemosyne C:/windows/Mnemosyne.sys 2023-01-24 18:04:59 Forensic Tool
mnemosyne C:/windows/Mnemosyne.sys 2023-01-25 14:38:37 Forensic Tool
DISCOVERED ATTACK PATTERNS & INCIDENT PLAYBOOK
  • Attacker Subnet Scope Identified: Connections originated from 172.16.6.18 and 172.16.4.9. Security teams must perform a sweep of these two hosts immediately, as they serve as the threat actor's active pivot points.
  • No Execution of Lateral Movement Tools locally: Although the attacker staged ph.exe (Process Hacker) and px.exe (PsExec) on January 23, the Prefetch logs confirm they were never executed on this system. The attacker likely planned lateral movement *outbound* but was disrupted by the DFIR team's rapid response on January 24.
  • Security Audit Logs Integrity: While the Security event log contains oldest events starting from August 2022, it is fully populated up to January 25, 2023. The apparent "missing" events in previous runs were due to standard API search limits, not log manipulation. The audit log integrity remains intact.