Protocol SIFT · Evidence Inventory
Find Evil! · 2026

Four cases.

Two enterprises, two hosts.

A working inventory of the forensic datasets shared with the team. Each case contains one or more disk images, sometimes a memory capture, and a scenario briefing where available. Network architecture verified against SANS Lab documentation where applicable.

Cases
04
Disk Images
13
Memory Captures
01
Total Volume
224.6 GB
01SRL-2015
Enterprise Compromise

Compromised Enterprise Network · 2015

A multi-host breach simulation across a Windows Server 2008 R2 domain controller and three user workstations on a flat /24 subnet. Scenario predates the documented SANS lab series; topology inferred from filename conventions.

Network Architecture
Inferred
DCWS-1WS-2WS-310.3.58.0/24
At a Glance
Disk Images
4
Memory Dumps
0
Documents
0
Total
55.6 GB
Evidence Inventory
HostRoleNetworkSize
win2008R2-controllerDomain Controller10.3.58.416.3 GB
win7-32-nromanoffWorkstation · Win7 x8610.3.58.514.8 GB
win7-64-nfuryWorkstation · Win7 x6410.3.58.613.3 GB
xp-tdunganWorkstation · Windows XP10.3.58.711.2 GB
02SRL-2018
Enterprise Compromise

Stark Research Labs · APT Investigation · 2023

Incident date 2023-01-24

A six-subnet enterprise compromise with a Windows domain core, public-facing DMZ, and isolated R&D and business networks. Primary compromise host is rd01 in the R&D subnet; attacker lateral movement targets 172.16.6.12. Folder labeling 'SRL-2018' maps to Lab 1.1 in SANS documentation.

Network Architecture
Verified
Management
172.16.8.0/24
log01assess01assess02sft01trust01adusa01
Services
172.16.4.0/24
dc01file01exchange01proxy01dev01sql01
R&D
172.16.6.0/24
● rd01rd02rd03–10
Business Line
172.16.7.0/24
wksta01wksta05wksta02–04wksta06–10
DMZ
172.16.19.0/24
ftp01dns01smtp01
VPN Client
172.16.30.0/24
No hosts in this subnet documented.
hostIn evidence inventory
● hostPrimary compromise
hostNot collected
At a Glance
Disk Images
7
Memory Dumps
0
Documents
0
Total
100.9 GB
Evidence Inventory
HostRoleNetworkSize
base-dc-cdriveDomain Controller · dc01Services · 172.16.4.0/2411.5 GB
base-file-cdriveFile Server · file01Services · 172.16.4.0/2415.3 GB
base-rd-01-cdriveR&D Host · rd01 · COMPROMISER&D · 172.16.6.0/2416.6 GB
base-rd-02-cdriveR&D Host · rd02R&D · 172.16.6.0/2416.0 GB
base-wkstn-01-c-driveWorkstation · wksta01Business · 172.16.7.0/2415.8 GB
base-wkstn-05-cdriveWorkstation · wksta05Business · 172.16.7.0/2413.8 GB
dmz-ftp-cdriveFTP Server · ftp01DMZ · 172.16.19.0/2411.9 GB
SRL-2018/Supporting materials
03ROCBA
Single-Host Investigation

Standard Forensic Case

A single-machine investigation supported by a full memory capture and scenario briefing. Smaller in scope, well-suited for end-to-end agent validation.

Network Architecture
HOSTISOLATED IMAGE
At a Glance
Disk Images
1
Memory Dumps
1
Documents
1
Total
27.4 GB
Evidence Inventory
HostRoleNetworkSize
rocba-cdrive.e01Disk Image22.1 GB
Rocba-Memory.zipMemory Capture5.3 GB
ROCBA-BACKGROUND.pptxScenario Briefing38.3 MB
04VANKO
Single-Host Investigation

Standard Forensics Case 2

A single-host investigation accompanied by a scenario document. Contains the largest individual disk image in the inventory.

Network Architecture
HOSTISOLATED IMAGE
At a Glance
Disk Images
1
Memory Dumps
0
Documents
1
Total
40.7 GB
Evidence Inventory
HostRoleNetworkSize
VANKO.zipDisk Image40.7 GB
Vanko Student Scenario_D01_01.docxScenario Briefing23 KB