← Evidenx Demonstrations
REAL DETERMINISTIC PIPELINE OUTPUT · HYPOTHETICAL PROOF-OF-CONCEPT CASE · NOT GENERATED
Evidenx
Data → Information → Understanding · the analyst concludes
case  cases/case_001
location  c:\windows\addins
predicate  attacker_toolkit v0.2.0 [in_review]
reference  attacker_toolkit v0.2.0
observations  70,212
generated  2026-07-08 18:24 UTC

Hypothesis Card

Evidenx does not score. This card presents bounded facts; significance is for the analyst to assign.
Step 1 of 8

Scope & signal reduction

What we looked through
Evidenx examined six artifact types for this host and reduced them deterministically to one explainable Fact Pack. Nothing was discarded silently. Every raw signal remains an observation; this layer selects and correlates, it does not delete.
70,597
signals across 6 artifacts
5
reference-tool matches
1
staging directory
9
co-located context files
Prefetch
9,585
historical · prefetch
Shimcache
306
historical · shimcache
MFT
60,206
historical · mft
Netstat
73
live snapshot · netstat
Running Processes
42
live snapshot · running_processes
Event Logs
385
historical · eventlog
Step 2 of 8

Reference matches

The anchor: presence / execution evidence only
Netcat
files nc.exe
Swiss-army networking tool abused for reverse shells, tunnelling, and transfer. Context-dependent but rarely benign in staging directories.
evidence in mft prefetch shimcache
Wget
files wget.exe
Command-line downloader used for ingress tool transfer / payload staging. Legitimate utility; context-dependent.
evidence in mft prefetch shimcache
WinRAR (rar CLI)
files rar.exe
Command-line archiver used to stage/compress data for exfiltration (e.g. out.rar). Legitimate software; anomalous in system directories.
evidence in mft prefetch shimcache
MITRE ATT&CK T1560.001
Windows Credential Editor (WCE)
files wce.exe
Classic credential dumper; extracts logon credentials/hashes from memory. wce.txt is its typical output file. High-signal.
evidence in mft prefetch shimcache
MITRE ATT&CK T1003.001LSASS Memory
SetMACE
files setmace.exe
Timestomping tool that manipulates MFT/$STANDARD_INFORMATION and $FILE_NAME timestamps. Strong anti-forensic indicator.
evidence in prefetch shimcache
MITRE ATT&CK T1070.006Timestomp
Step 3 of 8

Co-located non-tool files

The outputs & staging around the tools
These files sit in the same directory as the matched tools. They are not reference tools and no predicate matches them, only the cluster surfaces them. Stated as neutral facts; the analyst decides what they mean.
c.txt
temporal
MFT SI-created 2012-05-22T04:43:39Z, within the execution-evidence window (2012-05-22T04:41:52Z..2012-05-22T04:44:27Z); co-located in c:\windows\addins.
created 2012-05-22T04:43:39Z · md5 bd9935d92be0a077572bba3e3d473760
fxsext.ecf
spatial temporal
Co-located in c:\windows\addins with the matched toolkit files.
MFT SI-created (2009-06-10T21:20:04Z) precedes FN-created (2012-05-16T01:53:21Z): timestamp divergence.
created 2009-06-10T21:20:04Z · md5 18515f8ddaee2750c81d768f2c0e7117
install_win.bat
spatial
Co-located in c:\windows\addins with the matched toolkit files.
out.rar
spatial
Co-located in c:\windows\addins with the matched toolkit files.
tools.rar
spatial
Co-located in c:\windows\addins with the matched toolkit files.
wce.txt
temporal
MFT SI-created 2012-05-22T04:43:23Z, within the execution-evidence window (2012-05-22T04:41:52Z..2012-05-22T04:44:27Z); co-located in c:\windows\addins.
created 2012-05-22T04:43:23Z · md5 64078086f2e532fbaf95386ee33d7757
Step 4 of 8

Timeline

Execution evidence, process creation & file activity
Window 2012-05-22T04:41:52Z .. 2012-05-22T04:44:27Z · derived from prefetch_last_run + mft_si_created + eventlog_4688
2009-06-10T21:20:04Z   fxsext.ecffile created
2010-11-20T21:29:12Z   nc.exefile created
2010-11-20T21:29:12Z   wce.exefile created
2010-11-20T21:29:12Z   wget.exefile created
2012-05-22T04:41:50Z   rar.exefile created
2012-05-22T04:41:50Z   wget.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:52Z   wget.exeexecution evidence
2012-05-22T04:41:52Z   wget.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:53Z   rar.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:54Z   setmace.exeexecution evidence
2012-05-22T04:41:54Z   setmace.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:54Z   setmace.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:54Z   setmace.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:41:55Z   nc.exeexecution evidence
2012-05-22T04:41:55Z   nc.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xCCC; command line not audited.
2012-05-22T04:43:22Z   wce.exeexecution evidence
2012-05-22T04:43:22Z   wce.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xDD0; command line not audited.
2012-05-22T04:43:23Z   wce.txtfile created
MFT SI-created 1s after the execution-evidence timestamp of wce.exe [temporal proximity; presentation TBD].
2012-05-22T04:43:39Z   c.txtfile created
MFT SI-created 17s after the execution-evidence timestamp of wce.exe [temporal proximity; presentation TBD].
2012-05-22T04:44:27Z   rar.exeexecution evidence
2012-05-22T04:44:27Z   rar.exeprocess created
Security 4688 process-creation record; account WIN-JACR88JTQV5\Joffrey Baratheon, parent PID 0xDD0; command line not audited.
Step 5 of 8

Actor & process lineage

From Security 4688 (event logs)
identity
Security 4688 process-creation records for the matched tools are attributed to account WIN-JACR88JTQV5\Joffrey Baratheon.
lineage
Matched-tool process-creation records share parent process id(s): 0xCCC (from 2012-05-22T04:41:55Z), 0xDD0 (from 2012-05-22T04:44:27Z).
Step 6 of 8

Timestamp-collision findings

Neutral structural facts
nc.exe
MFT SI-created 2010-11-20T21:29:12Z is identical to a cohort of 268 file(s) in this image (97 of them in system32, including cmd.exe), while its FN-created is 2012-05-22T04:41:53Z. SI/FN divergence with a system-cohort SI value. Neutral structural observation; significance is for the analyst.
wce.exe
MFT SI-created 2010-11-20T21:29:12Z is identical to a cohort of 268 file(s) in this image (97 of them in system32, including cmd.exe), while its FN-created is 2012-05-22T04:41:53Z. SI/FN divergence with a system-cohort SI value. Neutral structural observation; significance is for the analyst.
wget.exe
MFT SI-created 2010-11-20T21:29:12Z is identical to a cohort of 268 file(s) in this image (97 of them in system32, including cmd.exe), while its FN-created is 2012-05-22T04:41:29Z. SI/FN divergence with a system-cohort SI value. Neutral structural observation; significance is for the analyst.
Step 7 of 8

Understanding

Bounded & factual, no score
5 file(s) matching the attacker_toolkit reference were observed (Netcat, SetMACE, Wget, WinRAR (rar CLI), Windows Credential Editor (WCE)). Corroboration spans 4 artifact type(s): mft, prefetch, shimcache, eventlog. Tool categories present in the reference: command_and_control, credential_access, defense_evasion, exfiltration. Security 4688 process-creation records are present for 5 of the matched tools, providing independent corroboration of execution alongside the prefetch/shimcache execution evidence; command-line auditing was not enabled, so no command lines are available. Maliciousness, attribution, and intent are not established.
5 reference matchesartifact: mftartifact: prefetchartifact: shimcacheartifact: eventlogcategory: command_and_controlcategory: credential_accesscategory: defense_evasioncategory: exfiltration
Step 8 of 8

Conclusion

The analyst's call: Evidenx stops at understanding
Evidenx has taken the raw artifacts to data, to information, to understanding, the structured, corroborated, bounded picture on the preceding pages. It stops here. The conclusion is the analyst's to make.
data → information → understanding → your conclusion
Evidenx has not decided, and does not decide: maliciousness, intent, attribution, or sequence-as-proof. Presence and execution evidence are not proof of execution. There is no score, rank, or confidence value in this card.
For the analyst to determine:
  • Whether the corroborated pattern is significant in this case's context.
  • Which alternative explanations survive scrutiny.
  • Whether collection gaps must be closed before a call is made.
  • The finding, and any action or disposition it warrants.
Analyst determination
Left intentionally blank. This is the analyst's conclusion to record. Evidenx provides the evidence, not the verdict.