ATT&CK — Malware
CASE-20260823-CDEB
MEDIUM
OPEN
Assignee: unassigned · Opened 5h ago
Opened from malware ATT&CK
Entities
4
linked to case
IoCs
3
indicators
Entity types
2
dimensions
Evidence events
3
chain of custody
➕ Add anything to this case
Attach any entity — region, country, APT, source, MITRE technique, IoC, nation-state, campaign, data point, mission domain, CVE, malware, ransomware — and all linked entities are pulled in automatically.
🔎 IoC (3)
| Indicator | Role | Source | |
|---|---|---|---|
28553b3a9d2ad4361d33d29ac4bf771d008e0073cec01b5561c6348a608f | indicator | pivot | search · workbench |
2a8efbfadd798f6111340f7c1c956bee | indicator | pivot | search · workbench |
c9b65b764985dfd7a11d3faf599c56b8 | indicator | pivot | search · workbench |
🦠 Malware (1)
🤖 Case Operations
📜 Chain of Evidence (tamper-evident, hash-chained)
| When | Actor | Action | Entity | Source | Hash |
|---|---|---|---|---|---|
| 2026-08-23 06:48:27 | analyst | expand | malware: ATT&CK | graph+live · 3 linked entities pulled | 2051f14299 |
| 2026-08-23 06:48:25 | analyst | add | malware: ATT&CK | manual · primary | 87daf1761e |
| 2026-08-23 06:48:25 | analyst | open | malware: ATT&CK | analyst · case created | 823c9bcf4d |
Each record's hash chains to the previous, so any tampering is detectable. Export the full trail via the Evidence report.
📝 Case Notes (0)
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Attach all related IoCs as artifacts
- Run a response playbook per case type
- Escalate to legal when needed