Case CC-2026-031 - log exports
==============================

Collected by the managed SOC (NordWacht Security GmbH) from the Crumble & Co.
SOC jump host for the window 2026-11-09 00:00 to 2026-11-22 23:59
(Europe/Berlin) and handed over to Corporate Security. Every export is the
unmodified output of the source system. How and when each file was collected,
the clock check of every source and the hashes taken at collection are in
collection_record.txt. Hashes of all files: SHA256SUMS.

file                     source system                         time stamps
-----------------------  ------------------------------------  ---------------------------------------------
badge_access.csv         Access control (PACS) central export  local wall-clock time of the door controller
dhcp_HAM.log             DHCP server Hamburg (Windows)         local time, MM/DD/YY
dhcp_LUE.log             DHCP server Lüneburg (Windows)        local time, MM/DD/YY
dhcp_BRE.log             DHCP server Bremen (Windows)          local time, MM/DD/YY
wlc.log                  WLAN controller wlc01 (all sites)     syslog, local time
windows_security.jsonl   Windows Event Forwarding collector    UTC
                         (Security log of DCs, servers, clients)
vpn.log                  VPN gateway vpn-gw01                  UTC
proxy_access.log         Web proxy PROXY01 (squid)             Unix epoch; see header lines
dns.log                  Zeek, on the resolver NS01 (all sites) Unix epoch
conn.log                 Zeek, SPAN of the HQ client VLAN      Unix epoch
                         10.10.20.0/24 and the VPN pool
                         10.99.0.0/24 only
netflow.csv              Edge router edge-rtr01, exported on   collector time (UTC)
                         the inside interfaces (before NAT)
mail_tracking.csv        Exchange message tracking (EXCH01)    UTC
crm_audit.jsonl          CRM application audit log (CRM01)     local time with offset
alerts.json              SIEM alert export                     UTC
ids_capture.pcap         IDS on the HQ client VLAN SPAN,       pcap (UTC epoch)
                         triggered capture (ring buffer)
mail/*.eml               Mails from the mailboxes of nvogt and  RFC 5322 Date / Received headers
                         tlindqvist (legal hold, HR + works council approved)
collection_record.txt    SOC handover record                    CET
employees.csv            HR + asset inventory (CMDB/MDM)       -
geoip.csv                GeoIP enrichment used by the SIEM      -

Network: HQ clients 10.10.20.0/24, HQ servers 10.10.1.0/24, Lüneburg 10.20.20.0/24,
Bremen 10.30.20.0/24, staff Wi-Fi (CC-Mobile) 172.16.50/60/70.0/24, VPN pool
10.99.0.0/24. Web access only through the proxy 10.10.1.20:3128 (explicit proxy,
Kerberos authentication). Public addresses: 198.51.100.10 VPN, 198.51.100.20 NAT,
198.51.100.25 MX.
