Cross-Tier Overview
**Shift:** 14 | TORA: SHIFT-14 | VERA: VSHIFT-14
**Patterns identified:** 9
**Open questions raised:** 6
**Pattern types:** pipeline_gap: 1 | campaign_confirmation: 2 | containment_failure: 1 | triage_calibration: 2 | hypothesis_accuracy: 1 | infrastructure_reuse: 1 | telemetry_gap: 1
**Confidence distribution:** HIGH: 9 | MEDIUM: 0 | LOW: 0
What the Shift Revealed
TORA and VERA agreed on direction with a consistency I rarely see across tiers: all 20 of TORA’s escalations were confirmed by VERA at immediate urgency, no hypothesis was refuted, and every campaign cluster TORA flagged in real time was validated as a single coordinated operation. Where the tiers diverged was not on disposition but on depth — 18 of 20 hypotheses required REFINED resolution, and the direction of refinement was the same every time: TORA understated how far the intrusion had already progressed at escalation time, because active compromise pre-dated the triggering alert. That divergence traces to two specific T1 blind spots — gateway quarantine treated as a reliable no-interaction signal (TORA-20260708-0014, where c.wardlaw’s “click” landed 38 minutes after malware was already executing on srv-file-01… on srv-backup-01), and precursor process-behavior alerts under-weighted when co-occurring with DNS alerts on critical hosts (the LSASS access on ws-hr-099 closed at low severity, the encoded command line on srv-ad-01.corp.local never dispositioned). The cross-shift lens is what makes this shift legible: Formbook and at least six confirmed-compromised assets — srv-ad-01, srv-jump-01, srv-file-01, ws-fin-015, ws-legal-077, srv-backup-01 — carry over from Shift 13 under fully rotated delivery infrastructure, so Shift 14 is not a new campaign but the continuation of one that was never contained. The starkest symptom is ws-dev-022.corp.local (10.10.8.22): a host confirmed in Shift 13’s blast radius, now querying Cobalt Strike C2, that Shift 14 could not triage at all because the CMDB has no record it exists. Neither tier alone could see that the pipeline’s binding constraint this shift was enrichment and telemetry infrastructure, not detection sensitivity — that only shows up when you read TORA’s CMDB failures and VERA’s check_reputation failures against the same asset set.
Patterns Worth Naming
P1 | pipeline_gap | confidence: HIGH
ws-dev-022.corp.local (10.10.8.22) generated all three of TORA’s INSUFFICIENT_CONTEXT verdicts this shift — twice on Cobalt Strike C2 domain ping-health-relay.com, once on session-relay-node.io (Mettle) — blocked by a total CMDB/identity enrichment failure across 11 fields. The cross-shift context shows this exact host was in Shift 13’s CONFIRMED blast radius. A host already confirmed compromised in the prior shift is currently untriageable on serious C2 IOCs because it has no CMDB record.
Evidence: TORA cases TORA-20260706-0005, TORA-20260706-0006, TORA-20260709-0022; indicators ping-health-relay.com, session-relay-node.io, 10.10.8.22
What would confirm this: TORA also observed that tora_meta.missing_fields understated the actual null-field count — the pipeline’s self-reported gap metadata is itself unreliable for this host.
P3 | containment_failure | confidence: HIGH
srv-ad-01.corp.local — the production domain controller — was in Shift 13’s confirmed blast radius (GootLoader C2 callback after SSH access by 176.9.10.20), then was confirmed compromised twice more within Shift 14 under two different execution accounts (Formbook under alee in VERA-20260707-0011; ncat reverse shell under mjones in VERA-20260709-0023), plus two confirmed credential submissions from it (contractor_1, ctaylor). Three shift-window compromise confirmations on the same DC indicate containment between cases and shifts is not holding.
Evidence: TORA cases TORA-20260706-0003, TORA-20260707-0011, TORA-20260709-0023; VERA cases VERA-20260706-0003, VERA-20260707-0011, VERA-20260709-0023; indicators srv-ad-01.corp.local, 10.10.5.10, 176.9.10.20
What would confirm this: VERA already requires krbtgt double-reset; the cross-shift view adds that this host’s compromise predates Shift 14 entirely, so NTDS.dit exposure assessment should cover the Shift 13 window too.
P2 | campaign_confirmation | confidence: HIGH
Shift 14 shows strong campaign continuity with Shift 13 via multiple independent indicators: Formbook was confirmed in both shifts (Shift 13 VERA-20260702-0020; Shift 14 VERA-20260707-0011 and VERA-20260710-0026), and at least six assets in Shift 13’s confirmed blast radius reappear as confirmed compromised in Shift 14 — srv-ad-01.corp.local, srv-jump-01.corp.local (10.10.5.20), srv-file-01.corp.local (10.10.6.50), ws-fin-015.corp.local (10.10.2.15), ws-legal-077.corp.local (10.10.3.21), and srv-backup-01.corp.local (10.10.7.80). This is consistent with a single sustained campaign persisting across shifts with rotated delivery infrastructure, not coincidental reuse — the domains and attacker IPs rotated completely between shifts while malware family and asset set recurred together.
Evidence: TORA cases TORA-20260707-0011, TORA-20260710-0026; VERA cases VERA-20260707-0011, VERA-20260710-0026, VERA-20260706-0003, VERA-20260709-0023; indicators dist-lib-fetch.io, srv-ad-01.corp.local, srv-jump-01.corp.local, srv-file-01.corp.local, ws-fin-015.corp.local, srv-backup-01.corp.local
What would confirm this: Distinguishing test — shared post-exploitation tradecraft (ncat/LOLBin masquerade chains, scheduled-task-to-temp persistence) matching across shifts would raise this to certainty; identical tradecraft is already documented within Shift 14.
P4 | triage_calibration | confidence: HIGH
TORA’s email triage paths treat gateway quarantine status as a reliable no-interaction signal, but VERA found SIEM proxy telemetry showing user clicks or malware-scripted clicks had already occurred in at least five quarantine-marked cases. Related: in VERA-20260708-0014 the ‘click’ attributed to c.wardlaw occurred 38 minutes after malware was already executing on srv-backup-01 — the click was a downstream artifact of an existing implant, which also resolved TORA’s flagged user-agent anomaly.
Evidence: TORA cases TORA-20260708-0014, TORA-20260709-0019, TORA-20260709-0024; VERA cases VERA-20260708-0014, VERA-20260709-0024, VERA-20260709-0020; indicators dropbox-file-relay.io, adp-secure-portal.com, payroll-update.co
What would confirm this: VERA explicitly named this the single most operationally significant calibration issue this shift; a proxy-log pre-check in TORA’s email click path would close it.
P5 | triage_calibration | confidence: HIGH
Critical precursor alerts co-occurring with DNS-category alerts on the same host are being under-weighted at triage: an LSASS Memory Access alert (IDS-216676) on ws-hr-099 was CLOSED at low severity before the Emotet escalation, and an Encoded Command Line alert (IDS-335756) on srv-ad-01 fired more than three hours before the Formbook C2 callback and was never dispositioned. In both cases containment could have preceded C2 establishment had the precursor escalated.
Evidence: TORA cases TORA-20260707-0008, TORA-20260707-0011; VERA cases VERA-20260707-0008, VERA-20260707-0011; indicators pool-node-relay.io, dist-lib-fetch.io
What would confirm this: VERA judged this systematic rather than individual triage error — a threshold calibration gap for process-behavior alerts on critical assets, visible only across cases at T2.
Open Questions
- Was ws-dev-022.corp.local (10.10.8.22) — confirmed in Shift 13’s blast radius and now querying Cobalt Strike C2 infrastructure while untriageable — ever contained after Shift 13, and why does it still have no CMDB record?
- Does mjones appear in Shift 13’s endpoint process telemetry? If so, the campaign-level credential compromise predates Shift 14 and the containment scope from Shift 13 was incomplete.
- The two srv-ad-01 compromises within Shift 14 used different execution accounts (alee, then mjones) and Shift 13 recorded GootLoader on the same host — is this one attacker with sustained access or multiple independent intrusions on the same DC?
- Which host is the unidentified second asset behind same_domain_count=2 on dist-lib-fetch.io (Formbook C2)? It remains unconfirmed in both notebooks.
- Shift 14’s phishing/C2 domains share no overlap with Shift 13’s (slack-notify-app.io, box-file-share.co, get-resource-pkg.net cluster) despite identical targeting — is the actor rotating infrastructure on a per-shift cadence, and can registration/hosting pivots link the two domain sets?
- srv-file-01.corp.local received SSH brute-force from different IPs in consecutive shifts (60.191.82.124 CN in Shift 13 with success, 138.199.21.9 NL in Shift 14 without) — same actor retrying, or is this host externally exposed and attracting independent attackers?
Where the Pipeline Showed Its Seams
The binding constraint this shift was enrichment and telemetry infrastructure, not detection sensitivity — and it seamed at both tiers in ways neither could fully see alone. At T1, ws-dev-022 was untriageable on Cobalt Strike IOCs purely because the CMDB had no record of a host that was confirmed compromised the shift before, and TORA’s own gap metadata understated how many fields were null. At T2, check_reputation returned infrastructure errors across the majority of VERA’s cases, leaving dozens of pivot IOCs — the cdn-*-assets.net set, multiple C2 candidate IPs, and telemetry-cloud-api.com — unclassified; the highest-criticality assets (srv-jump-01, domain controllers, backup servers) were disproportionately the ones lacking EDR or network-flow coverage, which is exactly backwards from where coverage should concentrate. Two whole classes of signal were structurally invisible to TORA: the mjones credential surfacing in active malware process trees across five independently investigated hosts (ws-mktg-042, srv-ad-01, ws-legal-077, ws-fin-015, srv-file-01), and the shared redirect/payload layer (payroll-update.co, login-microsofft-com.net, telemetry-cloud-api.com) that only became a single operation once VERA joined cases — meaning TORA’s clean escalation precision (P6: zero false positives) coexisted with a systematic underestimate of progression that no single T1 case could correct. This shift survived those gaps only because behavioral evidence was strong enough to carry CONFIRMED verdicts through failed enrichment; on thinner future cases the same check_reputation failure pattern forces HOLD dispositions, and the CMDB gap on already-compromised hosts becomes a place where confirmed intrusions go quiet.
NOVA — Cross-Shift Pattern Analysis
Eyes on the Glass | eyesontheglass.ai
Shift 14 | Analysis ID: NOVA-14-20260718