Digital Forensics Lab · Case CC-2026-031

The Midnight Upload

At 22:44 on a Thursday night, the data-loss-prevention sensor of Crumble & Co. saw almost two gigabytes leave the building. The logs are secured. Find out who did it, what left, and where it went.

1 Briefing

INTERNAL MEMO – CONFIDENTIAL
From: Claudia Reimers, Head of Corporate Security, Crumble & Co.
To: Forensic Examiner (you)
Date: Monday, 23 November 2026
Re: Case CC-2026-031 – large upload to an online storage service

On Thursday, 19 November 2026 at 22:44 our DLP sensor raised a high-severity alert: more than 250 MB within five minutes went from a desktop in the Sales open space to an online storage service that we do not use. The proxy log the next morning showed about 1.8 GB in total. The computer is SALES-PC07, the desktop of Nadine Vogt (Sales Assistant), and the upload ran under her account nvogt.

On Monday morning our managed SOC (NordWacht Security) secured the logs of all relevant systems for the agreed window, the capture of the intrusion detection system and the mailboxes released by HR. Their collection record is part of the package below.

Ms Vogt was suspended on Friday. She denies everything and says she was at home that evening. Her manager cannot imagine her doing this. The works council has asked us to be thorough, and so have I.

Please:

  1. Take over the evidence package, verify it against the SOC's collection record and document the chain of custody.
  2. Find out what happened: what left the company, where it went, when, and who was really at the keyboard. Was it Ms Vogt?
  3. Check the other alerts of the period; tell me which ones matter.
  4. Write a report that HR, the works council and, if needed, a labour court can follow.

The detailed questions, deliverables and deadline are in the assignment on Moodle.

HIGH DLP-VOL-01 · Volumetric DLP
Time
2026-11-19 22:44:10 CET
Rule
> 250 MB within 5 min to unsanctioned online storage
Source
10.10.20.57 (SALES-PC07)
User
CRUMBLE\nvogt (proxy authentication)
Destination
upload.dropvault.example
Volume
296 MB at alert time
Status
new · not triaged overnight
Exhibit: the alert as shown in the SIEM on Friday morning.

Scope and rules of engagement

  • Investigation window: 9 November 2026 00:00 to 22 November 2026 23:59 (Europe/Berlin), agreed with legal and the works council. The SOC exported every source for the whole window.
  • Released mailboxes: nvogt (account in the alert) and tlindqvist (routine legal hold: he resigned on 20 November). Other mailboxes need a separate approval.
  • Data protection: the logs contain personal data of all staff. Use only what the case needs. If you come across private matters that have nothing to do with the case, note that you found unrelated personal data, but do not analyse or report its content.
  • Never alter the evidence. Verify every hash when you receive the package, work on copies, and check the hashes again before you hand in.
  • Mind the clocks. Every source has its own clock and its own idea of time zones. The SOC checked each source's clock at collection time; the results are in collection_record.txt. Correct before you compare.

New to network forensics?

Packets, flows, proxy and Windows logs, e-mail headers and the SIEM method, explained with interactive examples: Network Forensics →

2 Chain of Custody

Logs have no evidence bag. Their chain of custody records who collected what from which system, for which time range, and every handover of the package since, each with the hash that proves nothing changed. The SOC's part is in collection_record.txt; continue the record from the handover to Corporate Security. Print this form or copy it into your report.

#Date / timeReleased byReceived byPurpose / actionHashes verified?
12026-11-23 09:50J. Ohlsen, SOC (NordWacht)C. Reimers, Corporate Security Handover after collection (see collection record)by SOC at 09:44

3 Evidence

This is the evidence package of case CC-2026-031, exactly as the SOC handed it over. Download it and verify the hashes before you start, against SHA256SUMS and against the hashes in the collection record.

ZIP SHA-256
Open the SIEM workbench → Search all logs with a Splunk-like query language, pin events to a case timeline, read the capture packet by packet and inspect the e-mail headers, all locally in your browser.

Verify

sha256sum -c case2_evidence.zip.sha256
unzip case2_evidence.zip && cd CC-2026-031 && sha256sum -c SHA256SUMS

Files in the package

FileSizeSHA-256

You can analyse the logs with the SIEM workbench, with your own tools (grep, awk, Python/pandas, Excel, Wireshark, Splunk Free, Elastic …) or both. Note the tool and version in your report.