| 2026-06-13T06:11:24.233Z |
case_created |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"case_name": "Automated Triage 2026-06-13"
}
|
| 2026-06-13T06:11:24.253Z |
automation_started |
{
"evidence_count": 7,
"evidence_path": "/mnt/data/Evidence",
"profile": "quick_triage",
"skip_hashing": true
}
|
| 2026-06-13T06:11:24.257Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "c2adc4df-9f95-4026-a12d-390fdd04d28e",
"label": "base-dc-cdrive"
}
|
| 2026-06-13T06:11:35.317Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-dc-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-dc-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:11:35.320Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:11:35.341Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/runkeys.csv",
"duration_seconds": 0.020936,
"function": "runkeys",
"record_count": 4
}
|
| 2026-06-13T06:11:35.344Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:11:35.506Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/tasks.csv",
"duration_seconds": 0.162232,
"function": "tasks",
"record_count": 369
}
|
| 2026-06-13T06:11:35.518Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:11:38.046Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/services.csv",
"duration_seconds": 2.52813,
"function": "services",
"record_count": 2111
}
|
| 2026-06-13T06:11:38.054Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:13:13.065Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shimcache.csv",
"duration_seconds": 95.011233,
"function": "shimcache",
"record_count": 2380
}
|
| 2026-06-13T06:13:13.072Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:13:13.892Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/amcache.csv",
"duration_seconds": 0.819973,
"function": "amcache",
"record_count": 1123
}
|
| 2026-06-13T06:13:13.903Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:13:13.928Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/userassist.csv",
"duration_seconds": 0.025229,
"function": "userassist",
"record_count": 88
}
|
| 2026-06-13T06:13:13.931Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:13:13.937Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/recyclebin.csv",
"duration_seconds": 0.006282,
"function": "recyclebin",
"record_count": 0
}
|
| 2026-06-13T06:13:13.940Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:13:15.977Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.history.csv",
"duration_seconds": 2.036834,
"function": "browser.history",
"record_count": 35
}
|
| 2026-06-13T06:13:15.982Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:13:17.952Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.downloads.csv",
"duration_seconds": 1.970638,
"function": "browser.downloads",
"record_count": 2
}
|
| 2026-06-13T06:13:17.957Z |
parsing_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"function": "powershell_history"
}
|
| 2026-06-13T06:13:17.986Z |
parsing_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/powershell_history.csv",
"duration_seconds": 0.02984,
"function": "powershell_history",
"record_count": 291
}
|
| 2026-06-13T06:13:17.989Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:13:18.272Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 0.282419,
"function": "jumplist.automatic_destination",
"record_count": 45
}
|
| 2026-06-13T06:13:18.275Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:13:18.298Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.023141,
"function": "jumplist.custom_destination",
"record_count": 6
}
|
| 2026-06-13T06:13:18.301Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:13:18.384Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shellbags.csv",
"duration_seconds": 0.082957,
"function": "shellbags",
"record_count": 149
}
|
| 2026-06-13T06:13:18.388Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:13:18.395Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/sam.csv",
"duration_seconds": 0.00711,
"function": "sam",
"record_count": 6
}
|
| 2026-06-13T06:13:18.398Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:13:18.405Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/defender.quarantine.csv",
"duration_seconds": 0.007063,
"function": "defender.quarantine",
"record_count": 2
}
|
| 2026-06-13T06:13:18.434Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:13:18.451Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/network_history.csv",
"duration_seconds": 0.017204,
"function": "network_history",
"record_count": 6
}
|
| 2026-06-13T06:13:18.456Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "66190324-1efb-42d2-b2c4-316e91c91631",
"label": "base-file-cdrive"
}
|
| 2026-06-13T06:13:27.968Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-file-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-file-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:13:27.972Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:13:27.987Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/runkeys.csv",
"duration_seconds": 0.014263,
"function": "runkeys",
"record_count": 4
}
|
| 2026-06-13T06:13:28.006Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:13:28.104Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/tasks.csv",
"duration_seconds": 0.097986,
"function": "tasks",
"record_count": 235
}
|
| 2026-06-13T06:13:28.107Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:13:29.879Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/services.csv",
"duration_seconds": 1.771925,
"function": "services",
"record_count": 1616
}
|
| 2026-06-13T06:13:29.882Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:13:46.616Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shimcache.csv",
"duration_seconds": 16.733912,
"function": "shimcache",
"record_count": 1108
}
|
| 2026-06-13T06:13:46.621Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:13:47.067Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/amcache.csv",
"duration_seconds": 0.445647,
"function": "amcache",
"record_count": 1319
}
|
| 2026-06-13T06:13:47.074Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:13:47.104Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/userassist.csv",
"duration_seconds": 0.030598,
"function": "userassist",
"record_count": 83
}
|
| 2026-06-13T06:13:47.107Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:13:47.167Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/recyclebin.csv",
"duration_seconds": 0.059848,
"function": "recyclebin",
"record_count": 21
}
|
| 2026-06-13T06:13:47.170Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:13:50.539Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.history.csv",
"duration_seconds": 3.36926,
"function": "browser.history",
"record_count": 50
}
|
| 2026-06-13T06:13:50.543Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:13:53.383Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.downloads.csv",
"duration_seconds": 2.840331,
"function": "browser.downloads",
"record_count": 5
}
|
| 2026-06-13T06:13:53.389Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:13:53.495Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 0.106322,
"function": "jumplist.automatic_destination",
"record_count": 21
}
|
| 2026-06-13T06:13:53.498Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:13:53.532Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.034177,
"function": "jumplist.custom_destination",
"record_count": 18
}
|
| 2026-06-13T06:13:53.536Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:13:53.648Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shellbags.csv",
"duration_seconds": 0.112554,
"function": "shellbags",
"record_count": 242
}
|
| 2026-06-13T06:13:53.655Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:13:53.661Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/sam.csv",
"duration_seconds": 0.006791,
"function": "sam",
"record_count": 8
}
|
| 2026-06-13T06:13:53.664Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:13:53.668Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/defender.quarantine.csv",
"duration_seconds": 0.003952,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:13:53.671Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:13:53.688Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/network_history.csv",
"duration_seconds": 0.017025,
"function": "network_history",
"record_count": 6
}
|
| 2026-06-13T06:13:53.693Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "a66612b5-ee40-416e-8eb2-49ec34b9b3b1",
"label": "base-rd-01-cdrive"
}
|
| 2026-06-13T06:14:09.807Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-rd-01-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-rd-01-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:14:09.811Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:14:09.826Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/runkeys.csv",
"duration_seconds": 0.01576,
"function": "runkeys",
"record_count": 16
}
|
| 2026-06-13T06:14:09.829Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:14:10.201Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/tasks.csv",
"duration_seconds": 0.371466,
"function": "tasks",
"record_count": 1020
}
|
| 2026-06-13T06:14:10.211Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:14:10.919Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/services.csv",
"duration_seconds": 0.707896,
"function": "services",
"record_count": 625
}
|
| 2026-06-13T06:14:10.923Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:15:02.905Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shimcache.csv",
"duration_seconds": 51.98168,
"function": "shimcache",
"record_count": 796
}
|
| 2026-06-13T06:15:02.909Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:15:03.644Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/amcache.csv",
"duration_seconds": 0.735245,
"function": "amcache",
"record_count": 1001
}
|
| 2026-06-13T06:15:03.648Z |
parsing_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"function": "bam"
}
|
| 2026-06-13T06:15:03.664Z |
parsing_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/bam.csv",
"duration_seconds": 0.015261,
"function": "bam",
"record_count": 57
}
|
| 2026-06-13T06:15:03.667Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:15:03.708Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/userassist.csv",
"duration_seconds": 0.041293,
"function": "userassist",
"record_count": 121
}
|
| 2026-06-13T06:15:03.711Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:15:03.843Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/recyclebin.csv",
"duration_seconds": 0.132037,
"function": "recyclebin",
"record_count": 51
}
|
| 2026-06-13T06:15:03.847Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:15:05.991Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.history.csv",
"duration_seconds": 2.144603,
"function": "browser.history",
"record_count": 1226
}
|
| 2026-06-13T06:15:05.995Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:15:08.522Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.downloads.csv",
"duration_seconds": 2.527062,
"function": "browser.downloads",
"record_count": 61
}
|
| 2026-06-13T06:15:08.532Z |
parsing_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"function": "powershell_history"
}
|
| 2026-06-13T06:15:08.540Z |
parsing_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/powershell_history.csv",
"duration_seconds": 0.007413,
"function": "powershell_history",
"record_count": 50
}
|
| 2026-06-13T06:15:08.542Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:15:09.510Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 0.967906,
"function": "jumplist.automatic_destination",
"record_count": 171
}
|
| 2026-06-13T06:15:09.514Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:15:09.567Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.053053,
"function": "jumplist.custom_destination",
"record_count": 40
}
|
| 2026-06-13T06:15:09.570Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:15:09.698Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shellbags.csv",
"duration_seconds": 0.128018,
"function": "shellbags",
"record_count": 244
}
|
| 2026-06-13T06:15:09.701Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:15:09.707Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/sam.csv",
"duration_seconds": 0.006238,
"function": "sam",
"record_count": 6
}
|
| 2026-06-13T06:15:09.710Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:15:09.714Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/defender.quarantine.csv",
"duration_seconds": 0.003598,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:15:09.717Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:15:09.723Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/network_history.csv",
"duration_seconds": 0.005803,
"function": "network_history",
"record_count": 2
}
|
| 2026-06-13T06:15:09.727Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "c165a62c-fcc2-4feb-b9a0-5e42fe834047",
"label": "base-rd-02-cdrive"
}
|
| 2026-06-13T06:15:27.285Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-rd-02-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-rd-02-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:15:27.300Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:15:27.319Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/runkeys.csv",
"duration_seconds": 0.018695,
"function": "runkeys",
"record_count": 17
}
|
| 2026-06-13T06:15:27.322Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:15:27.821Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/tasks.csv",
"duration_seconds": 0.498675,
"function": "tasks",
"record_count": 1015
}
|
| 2026-06-13T06:15:27.828Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:15:28.633Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/services.csv",
"duration_seconds": 0.80569,
"function": "services",
"record_count": 620
}
|
| 2026-06-13T06:15:28.651Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:16:00.400Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shimcache.csv",
"duration_seconds": 31.748515,
"function": "shimcache",
"record_count": 626
}
|
| 2026-06-13T06:16:00.404Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:16:01.132Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/amcache.csv",
"duration_seconds": 0.728271,
"function": "amcache",
"record_count": 836
}
|
| 2026-06-13T06:16:01.139Z |
parsing_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"function": "bam"
}
|
| 2026-06-13T06:16:01.148Z |
parsing_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/bam.csv",
"duration_seconds": 0.00881,
"function": "bam",
"record_count": 33
}
|
| 2026-06-13T06:16:01.151Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:16:01.193Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/userassist.csv",
"duration_seconds": 0.041515,
"function": "userassist",
"record_count": 133
}
|
| 2026-06-13T06:16:01.196Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:16:01.214Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/recyclebin.csv",
"duration_seconds": 0.018058,
"function": "recyclebin",
"record_count": 0
}
|
| 2026-06-13T06:16:01.218Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:16:06.998Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/browser.history.csv",
"duration_seconds": 5.779925,
"function": "browser.history",
"record_count": 12714
}
|
| 2026-06-13T06:16:07.001Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:16:09.116Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/browser.downloads.csv",
"duration_seconds": 2.115887,
"function": "browser.downloads",
"record_count": 0
}
|
| 2026-06-13T06:16:09.124Z |
parsing_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"function": "powershell_history"
}
|
| 2026-06-13T06:16:09.128Z |
parsing_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/powershell_history.csv",
"duration_seconds": 0.004062,
"function": "powershell_history",
"record_count": 4
}
|
| 2026-06-13T06:16:09.131Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:16:36.979Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 27.848323,
"function": "jumplist.automatic_destination",
"record_count": 5538
}
|
| 2026-06-13T06:16:36.983Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:16:37.018Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.035633,
"function": "jumplist.custom_destination",
"record_count": 18
}
|
| 2026-06-13T06:16:37.022Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:16:37.060Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shellbags.csv",
"duration_seconds": 0.037989,
"function": "shellbags",
"record_count": 62
}
|
| 2026-06-13T06:16:37.063Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:16:37.070Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/sam.csv",
"duration_seconds": 0.006768,
"function": "sam",
"record_count": 6
}
|
| 2026-06-13T06:16:37.073Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:16:37.077Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/defender.quarantine.csv",
"duration_seconds": 0.003242,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:16:37.079Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:16:37.084Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/network_history.csv",
"duration_seconds": 0.004915,
"function": "network_history",
"record_count": 1
}
|
| 2026-06-13T06:16:37.089Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "6d4f645a-4d9c-46c3-a93f-317ae2800b3b",
"label": "base-wkstn-01-c-drive"
}
|
| 2026-06-13T06:16:55.871Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-wkstn-01-c-drive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-wkstn-01-c-drive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:16:55.875Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:16:55.890Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/runkeys.csv",
"duration_seconds": 0.014463,
"function": "runkeys",
"record_count": 21
}
|
| 2026-06-13T06:16:55.893Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:16:56.238Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/tasks.csv",
"duration_seconds": 0.345659,
"function": "tasks",
"record_count": 1037
}
|
| 2026-06-13T06:16:56.253Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:16:56.885Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/services.csv",
"duration_seconds": 0.63175,
"function": "services",
"record_count": 620
}
|
| 2026-06-13T06:16:56.892Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:17:35.991Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shimcache.csv",
"duration_seconds": 39.098977,
"function": "shimcache",
"record_count": 488
}
|
| 2026-06-13T06:17:36.004Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:17:38.478Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/amcache.csv",
"duration_seconds": 2.474147,
"function": "amcache",
"record_count": 2869
}
|
| 2026-06-13T06:17:38.531Z |
parsing_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"function": "bam"
}
|
| 2026-06-13T06:17:38.541Z |
parsing_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/bam.csv",
"duration_seconds": 0.009375,
"function": "bam",
"record_count": 39
}
|
| 2026-06-13T06:17:38.544Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:17:38.574Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/userassist.csv",
"duration_seconds": 0.030079,
"function": "userassist",
"record_count": 133
}
|
| 2026-06-13T06:17:38.577Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:17:38.628Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/recyclebin.csv",
"duration_seconds": 0.051131,
"function": "recyclebin",
"record_count": 19
}
|
| 2026-06-13T06:17:38.632Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:17:40.910Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.history.csv",
"duration_seconds": 2.278833,
"function": "browser.history",
"record_count": 2871
}
|
| 2026-06-13T06:17:40.915Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:17:43.174Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.downloads.csv",
"duration_seconds": 2.258994,
"function": "browser.downloads",
"record_count": 75
}
|
| 2026-06-13T06:17:43.187Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:17:44.244Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 1.056654,
"function": "jumplist.automatic_destination",
"record_count": 256
}
|
| 2026-06-13T06:17:44.251Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:17:44.292Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.040638,
"function": "jumplist.custom_destination",
"record_count": 29
}
|
| 2026-06-13T06:17:44.295Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:17:44.366Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shellbags.csv",
"duration_seconds": 0.070379,
"function": "shellbags",
"record_count": 139
}
|
| 2026-06-13T06:17:44.369Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:17:44.374Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/sam.csv",
"duration_seconds": 0.005622,
"function": "sam",
"record_count": 6
}
|
| 2026-06-13T06:17:44.377Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:17:44.381Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/defender.quarantine.csv",
"duration_seconds": 0.003344,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:17:44.384Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:17:44.391Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/network_history.csv",
"duration_seconds": 0.006802,
"function": "network_history",
"record_count": 3
}
|
| 2026-06-13T06:17:44.395Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "801988de-0f5b-4a11-848b-ad1e6011fb88",
"label": "base-wkstn-05-cdrive"
}
|
| 2026-06-13T06:17:52.844Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/base-wkstn-05-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/base-wkstn-05-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:17:52.852Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:17:52.871Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/runkeys.csv",
"duration_seconds": 0.018909,
"function": "runkeys",
"record_count": 15
}
|
| 2026-06-13T06:17:52.874Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:17:52.969Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/tasks.csv",
"duration_seconds": 0.0952,
"function": "tasks",
"record_count": 268
}
|
| 2026-06-13T06:17:52.972Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:17:54.930Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/services.csv",
"duration_seconds": 1.957701,
"function": "services",
"record_count": 1822
}
|
| 2026-06-13T06:17:54.946Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:18:00.447Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shimcache.csv",
"duration_seconds": 5.50145,
"function": "shimcache",
"record_count": 1164
}
|
| 2026-06-13T06:18:00.491Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:18:01.245Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/amcache.csv",
"duration_seconds": 0.753566,
"function": "amcache",
"record_count": 795
}
|
| 2026-06-13T06:18:01.250Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:18:01.294Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/userassist.csv",
"duration_seconds": 0.043377,
"function": "userassist",
"record_count": 167
}
|
| 2026-06-13T06:18:01.297Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:18:01.389Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/recyclebin.csv",
"duration_seconds": 0.092216,
"function": "recyclebin",
"record_count": 37
}
|
| 2026-06-13T06:18:01.399Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:18:03.583Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.history.csv",
"duration_seconds": 2.183343,
"function": "browser.history",
"record_count": 483
}
|
| 2026-06-13T06:18:03.586Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:18:06.445Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.downloads.csv",
"duration_seconds": 2.859366,
"function": "browser.downloads",
"record_count": 59
}
|
| 2026-06-13T06:18:06.450Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:18:08.659Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 2.209174,
"function": "jumplist.automatic_destination",
"record_count": 20
}
|
| 2026-06-13T06:18:08.666Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:18:08.765Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.099365,
"function": "jumplist.custom_destination",
"record_count": 55
}
|
| 2026-06-13T06:18:08.768Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:18:08.859Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shellbags.csv",
"duration_seconds": 0.090993,
"function": "shellbags",
"record_count": 196
}
|
| 2026-06-13T06:18:08.862Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:18:08.869Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/sam.csv",
"duration_seconds": 0.006741,
"function": "sam",
"record_count": 6
}
|
| 2026-06-13T06:18:08.873Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:18:08.876Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/defender.quarantine.csv",
"duration_seconds": 0.003296,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:18:08.879Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:18:08.887Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/network_history.csv",
"duration_seconds": 0.007271,
"function": "network_history",
"record_count": 2
}
|
| 2026-06-13T06:18:08.891Z |
image_added |
{
"case_id": "3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96",
"image_id": "cb5dd4d0-e9da-4b7f-abd5-a1652671f61e",
"label": "dmz-ftp-cdrive"
}
|
| 2026-06-13T06:18:15.890Z |
evidence_intake |
{
"dissect_path": "/mnt/data/Evidence/dmz-ftp-cdrive.E01",
"evidence_file_hashes": [],
"file": "/mnt/data/Evidence/dmz-ftp-cdrive.E01",
"md5": "N/A (skipped)",
"sha256": "N/A (skipped)",
"size_bytes": 0,
"source_mode": "path"
}
|
| 2026-06-13T06:18:15.900Z |
parsing_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"function": "runkeys"
}
|
| 2026-06-13T06:18:15.915Z |
parsing_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/runkeys.csv",
"duration_seconds": 0.014542,
"function": "runkeys",
"record_count": 2
}
|
| 2026-06-13T06:18:15.918Z |
parsing_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"function": "tasks"
}
|
| 2026-06-13T06:18:16.006Z |
parsing_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/tasks.csv",
"duration_seconds": 0.087616,
"function": "tasks",
"record_count": 252
}
|
| 2026-06-13T06:18:16.010Z |
parsing_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"function": "services"
}
|
| 2026-06-13T06:18:17.780Z |
parsing_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/services.csv",
"duration_seconds": 1.769605,
"function": "services",
"record_count": 1650
}
|
| 2026-06-13T06:18:17.783Z |
parsing_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"function": "shimcache"
}
|
| 2026-06-13T06:18:33.263Z |
parsing_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shimcache.csv",
"duration_seconds": 15.480796,
"function": "shimcache",
"record_count": 1096
}
|
| 2026-06-13T06:18:33.266Z |
parsing_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"function": "amcache"
}
|
| 2026-06-13T06:18:33.664Z |
parsing_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/amcache.csv",
"duration_seconds": 0.397682,
"function": "amcache",
"record_count": 1059
}
|
| 2026-06-13T06:18:33.671Z |
parsing_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"function": "userassist"
}
|
| 2026-06-13T06:18:33.706Z |
parsing_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/userassist.csv",
"duration_seconds": 0.035286,
"function": "userassist",
"record_count": 81
}
|
| 2026-06-13T06:18:33.714Z |
parsing_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"function": "recyclebin"
}
|
| 2026-06-13T06:18:33.733Z |
parsing_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/recyclebin.csv",
"duration_seconds": 0.01841,
"function": "recyclebin",
"record_count": 3
}
|
| 2026-06-13T06:18:33.736Z |
parsing_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"function": "browser.history"
}
|
| 2026-06-13T06:18:36.098Z |
parsing_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.history.csv",
"duration_seconds": 2.362024,
"function": "browser.history",
"record_count": 66
}
|
| 2026-06-13T06:18:36.104Z |
parsing_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"function": "browser.downloads"
}
|
| 2026-06-13T06:18:38.913Z |
parsing_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.downloads.csv",
"duration_seconds": 2.80885,
"function": "browser.downloads",
"record_count": 7
}
|
| 2026-06-13T06:18:38.917Z |
parsing_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"function": "jumplist.automatic_destination"
}
|
| 2026-06-13T06:18:39.069Z |
parsing_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.automatic_destination.csv",
"duration_seconds": 0.151831,
"function": "jumplist.automatic_destination",
"record_count": 34
}
|
| 2026-06-13T06:18:39.072Z |
parsing_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"function": "jumplist.custom_destination"
}
|
| 2026-06-13T06:18:39.096Z |
parsing_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.custom_destination.csv",
"duration_seconds": 0.023857,
"function": "jumplist.custom_destination",
"record_count": 14
}
|
| 2026-06-13T06:18:39.099Z |
parsing_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"function": "shellbags"
}
|
| 2026-06-13T06:18:39.156Z |
parsing_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shellbags.csv",
"duration_seconds": 0.057345,
"function": "shellbags",
"record_count": 117
}
|
| 2026-06-13T06:18:39.160Z |
parsing_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"function": "sam"
}
|
| 2026-06-13T06:18:39.170Z |
parsing_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/sam.csv",
"duration_seconds": 0.010819,
"function": "sam",
"record_count": 16
}
|
| 2026-06-13T06:18:39.174Z |
parsing_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"function": "defender.quarantine"
}
|
| 2026-06-13T06:18:39.178Z |
parsing_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/defender.quarantine.csv",
"duration_seconds": 0.003942,
"function": "defender.quarantine",
"record_count": 0
}
|
| 2026-06-13T06:18:39.181Z |
parsing_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"function": "network_history"
}
|
| 2026-06-13T06:18:39.195Z |
parsing_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"csv_path": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/network_history.csv",
"duration_seconds": 0.013964,
"function": "network_history",
"record_count": 4
}
|
| 2026-06-13T06:18:39.554Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:18:39.558Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/runkeys.csv"
}
|
| 2026-06-13T06:18:39.561Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__runkeys.csv",
"annotated_rows": 2,
"artifact_key": "runkeys",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:19:02.715Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 23.157413,
"status": "success",
"token_count": 373
}
|
| 2026-06-13T06:19:02.718Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "HKEY_LOCAL_MACHINE",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
},
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'HKEY_LOCAL_MACHINE' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:19:02.721Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:19:03.398Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/tasks.csv"
}
|
| 2026-06-13T06:19:03.404Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__tasks.csv",
"annotated_rows": 22,
"artifact_key": "tasks",
"removed_records": 36,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T06:21:23.493Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 140.768844,
"status": "success",
"token_count": 622
}
|
| 2026-06-13T06:21:23.499Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "System",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "task_path",
"match_status": "exact",
"matched_header": "task_path"
},
{
"cited": "author",
"match_status": "exact",
"matched_header": "author"
},
{
"cited": "user_id",
"match_status": "exact",
"matched_header": "user_id"
},
{
"cited": "command",
"match_status": "exact",
"matched_header": "command"
},
{
"cited": "arguments",
"match_status": "exact",
"matched_header": "arguments"
},
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'System' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:21:23.502Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:21:23.575Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/services.csv"
}
|
| 2026-06-13T06:21:23.578Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__services.csv",
"annotated_rows": 531,
"artifact_key": "services",
"removed_records": 1579,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:24:41.616Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 198.108465,
"status": "success",
"token_count": 968
}
|
| 2026-06-13T06:24:41.626Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SYSTEM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "cdrive",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Amcache",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ShimCache",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 6,
"warnings": [
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SYSTEM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'cdrive' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Amcache' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ShimCache' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:24:41.630Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:24:41.689Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shimcache.csv"
}
|
| 2026-06-13T06:24:41.692Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__shimcache.csv",
"annotated_rows": 595,
"artifact_key": "shimcache",
"removed_records": 1785,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T06:27:03.257Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 141.624378,
"status": "success",
"token_count": 843
}
|
| 2026-06-13T06:27:03.266Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Autorunsc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "gflags.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Autorunsc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'gflags.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:27:03.270Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:27:03.358Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"mtime_regf",
"program_id",
"digest",
"path",
"hash_path",
"name",
"publisher",
"version",
"bin_file_version",
"product_name",
"product_version",
"link_date",
"bin_product_version",
"size",
"language",
"is_pefile",
"is_oscomponent",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"install_date_arp_last_modified",
"install_date_from_link_file",
"language_code",
"msi_package_code",
"msi_product_code",
"package_full_name",
"type",
"manifest_path",
"os_version_at_install_time",
"program_instance_id",
"registry_key_path",
"root_dir_path",
"source",
"uninstall_string",
"categories",
"discovery_method",
"friendly_name",
"icon",
"is_active",
"is_connected",
"is_machine_container",
"is_networked",
"is_paired",
"manufacturer",
"model_id",
"model_name",
"model_number",
"primary_category",
"state",
"driver_name",
"inf",
"driver_version",
"product",
"wdf_version",
"driver_company",
"driver_package_strong_name",
"service",
"driver_signed",
"driver_is_kernel_mode",
"last_write_time",
"driver_timestamp",
"image_size",
"last_modified_timestamp",
"last_modified_store_timestamp",
"link_timestamp",
"created_timestamp",
"reference",
"pe_header_checksum",
"pe_size_of_image",
"company_name",
"file_size"
],
"missing_columns": [
"ts"
]
}
|
| 2026-06-13T06:27:03.430Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp",
"path",
"name",
"publisher",
"version",
"product_name",
"company_name",
"digest",
"file_size",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/amcache.csv"
}
|
| 2026-06-13T06:27:03.434Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__amcache.csv",
"annotated_rows": 22,
"artifact_key": "amcache",
"removed_records": 35,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/amcache.csv",
"variant_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp"
]
}
|
| 2026-06-13T06:29:41.835Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 158.562073,
"status": "success",
"token_count": 773
}
|
| 2026-06-13T06:29:41.844Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 7,
"skipped": 0,
"total": 7
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "install_date",
"match_status": "exact",
"matched_header": "install_date"
},
{
"cited": "cdb.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "kd.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ntsd.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "windbg.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "publisher",
"match_status": "exact",
"matched_header": "publisher"
},
{
"cited": "version",
"match_status": "exact",
"matched_header": "version"
},
{
"cited": "product_name",
"match_status": "exact",
"matched_header": "product_name"
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'cdb.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'kd.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ntsd.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'windbg.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:29:41.847Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:29:41.854Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/userassist.csv"
}
|
| 2026-06-13T06:29:41.856Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__userassist.csv",
"annotated_rows": 2,
"artifact_key": "userassist",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:32:26.267Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 164.41796,
"status": "success",
"token_count": 956
}
|
| 2026-06-13T06:32:26.272Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 8,
"skipped": 0,
"total": 8
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T06:32:26.275Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:32:26.280Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.history.csv"
}
|
| 2026-06-13T06:32:26.286Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__browser.history.csv",
"annotated_rows": 0,
"artifact_key": "browser.history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:34:31.412Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"duration_seconds": 125.13483,
"status": "success",
"token_count": 1604
}
|
| 2026-06-13T06:34:31.418Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 16,
"skipped": 0,
"total": 16
},
"timestamps": {
"checked": 17,
"skipped": 0,
"total": 17
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "title",
"match_status": "exact",
"matched_header": "title"
},
{
"cited": "host",
"match_status": "exact",
"matched_header": "host"
},
{
"cited": "visit_type",
"match_status": "exact",
"matched_header": "visit_type"
},
{
"cited": "typed",
"match_status": "exact",
"matched_header": "typed"
},
{
"cited": "hidden",
"match_status": "exact",
"matched_header": "hidden"
},
{
"cited": "from_url",
"match_status": "exact",
"matched_header": "from_url"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T06:34:31.421Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:34:31.424Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.downloads.csv"
}
|
| 2026-06-13T06:34:31.428Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T06:35:22.212Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 50.788466,
"status": "success",
"token_count": 569
}
|
| 2026-06-13T06:35:22.215Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "iexplore",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "wdksetup.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "WDK.zip",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_start",
"match_status": "exact",
"matched_header": "ts_start"
},
{
"cited": "size",
"match_status": "exact",
"matched_header": "size"
},
{
"cited": "state",
"match_status": "exact",
"matched_header": "state"
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'iexplore' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'wdksetup.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'WDK.zip' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:35:22.219Z |
analysis_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:35:22.233Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__powershell_history.csv",
"artifact_key": "powershell_history",
"projection_columns": [
"mtime",
"order",
"command",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/powershell_history.csv"
}
|
| 2026-06-13T06:35:22.236Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__powershell_history.csv",
"annotated_rows": 0,
"artifact_key": "powershell_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/powershell_history.csv",
"variant_columns": [
"mtime"
]
}
|
| 2026-06-13T06:36:47.162Z |
analysis_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"duration_seconds": 84.939814,
"status": "success",
"token_count": 2434
}
|
| 2026-06-13T06:36:47.168Z |
citation_validation |
{
"artifact_key": "powershell_history",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 21,
"skipped": 0,
"total": 21
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "hiberfil.sys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mtime",
"match_status": "exact",
"matched_header": "mtime"
},
{
"cited": "order",
"match_status": "exact",
"matched_header": "order"
},
{
"cited": "ConsoleHost_history.txt",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'hiberfil.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ConsoleHost_history.txt' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:36:47.171Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:36:47.179Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T06:36:47.182Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__jumplist.automatic_destination.csv",
"annotated_rows": 2,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T06:39:32.657Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 165.482244,
"status": "success",
"token_count": 1263
}
|
| 2026-06-13T06:39:32.665Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 9,
"skipped": 0,
"total": 9
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T06:39:32.668Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:39:32.672Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T06:39:32.675Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__jumplist.custom_destination.csv",
"annotated_rows": 2,
"artifact_key": "jumplist.custom_destination",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T06:40:28.626Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 55.955418,
"status": "success",
"token_count": 1101
}
|
| 2026-06-13T06:40:28.631Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 10,
"skipped": 0,
"total": 10
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "powershell_ise.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_arguments",
"match_status": "exact",
"matched_header": "lnk_arguments"
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "lnk_device_name",
"match_status": "exact",
"matched_header": "lnk_device_name"
},
{
"cited": "lnk_workdir",
"match_status": "exact",
"matched_header": "lnk_workdir"
},
{
"cited": "certutil",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mshta",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "wscript",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 6,
"warnings": [
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell_ise.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'certutil' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mshta' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'wscript' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:40:28.635Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:40:28.646Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shellbags.csv"
}
|
| 2026-06-13T06:40:28.650Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__shellbags.csv",
"annotated_rows": 37,
"artifact_key": "shellbags",
"removed_records": 41,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T06:42:22.357Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 113.717747,
"status": "success",
"token_count": 1469
}
|
| 2026-06-13T06:42:22.360Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 14,
"skipped": 0,
"total": 14
},
"row_refs": {
"checked": 10,
"skipped": 0,
"total": 10
},
"timestamps": {
"checked": 9,
"skipped": 0,
"total": 9
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Prefetch",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Proxy",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SAM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SECURITY",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SYSTEM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "config",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "ts_mtime",
"match_status": "exact",
"matched_header": "ts_mtime"
}
],
"warning_count": 11,
"warnings": [
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Prefetch' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Proxy' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SAM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SECURITY' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SYSTEM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'config' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Startup' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'MFT' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'USN' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:42:22.364Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:42:22.368Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/sam.csv"
}
|
| 2026-06-13T06:42:22.371Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__sam.csv",
"annotated_rows": 3,
"artifact_key": "sam",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T06:44:39.991Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 137.624566,
"status": "success",
"token_count": 431
}
|
| 2026-06-13T06:44:39.996Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "lastlogin",
"match_status": "exact",
"matched_header": "lastlogin"
},
{
"cited": "lastpasswordset",
"match_status": "exact",
"matched_header": "lastpasswordset"
},
{
"cited": "lastincorrectlogin",
"match_status": "exact",
"matched_header": "lastincorrectlogin"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T06:44:39.999Z |
analysis_started |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:44:40.005Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__defender.quarantine.csv",
"artifact_key": "defender.quarantine",
"projection_columns": [
"ts",
"threat_id",
"detection_name",
"detection_type",
"detection_path",
"quarantine_id",
"scan_id",
"resource_id",
"creation_time",
"last_write_time",
"last_accessed_time"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/defender.quarantine.csv"
}
|
| 2026-06-13T06:44:40.019Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__defender.quarantine.csv",
"annotated_rows": 0,
"artifact_key": "defender.quarantine",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/defender.quarantine.csv",
"variant_columns": [
"ts",
"creation_time",
"last_write_time",
"last_accessed_time"
]
}
|
| 2026-06-13T06:46:36.280Z |
analysis_completed |
{
"artifact_key": "defender.quarantine",
"artifact_name": "Defender Quarantine",
"duration_seconds": 116.278516,
"status": "success",
"token_count": 725
}
|
| 2026-06-13T06:46:36.284Z |
citation_validation |
{
"artifact_key": "defender.quarantine",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "detection_name",
"match_status": "exact",
"matched_header": "detection_name"
},
{
"cited": "detection_path",
"match_status": "exact",
"matched_header": "detection_path"
},
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
},
{
"cited": "resource_id",
"match_status": "exact",
"matched_header": "resource_id"
},
{
"cited": "B75CD675E081064BB6713A34D76AB15557448BDE",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_write_time",
"match_status": "exact",
"matched_header": "last_write_time"
},
{
"cited": "quarantine_id",
"match_status": "exact",
"matched_header": "quarantine_id"
},
{
"cited": "scan_id",
"match_status": "exact",
"matched_header": "scan_id"
},
{
"cited": "creation_time",
"match_status": "exact",
"matched_header": "creation_time"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited timestamp 2018-08-31T22:17:00Z which could not be verified in the source data.",
"Note: AI cited timestamp 2018-08-31T22:21:00Z which could not be verified in the source data.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'B75CD675E081064BB6713A34D76AB15557448BDE' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'n.ps1' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:46:36.288Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:46:36.292Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/network_history.csv"
}
|
| 2026-06-13T06:46:36.297Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed_deduplicated/c2adc4df-9f95-4026-a12d-390fdd04d28e__network_history.csv",
"annotated_rows": 3,
"artifact_key": "network_history",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c2adc4df-9f95-4026-a12d-390fdd04d28e/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T06:49:22.434Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 166.142661,
"status": "success",
"token_count": 501
}
|
| 2026-06-13T06:49:22.438Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "last_connected",
"match_status": "exact",
"matched_header": "last_connected"
},
{
"cited": "created",
"match_status": "exact",
"matched_header": "created"
},
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "default_gateway_mac",
"match_status": "exact",
"matched_header": "default_gateway_mac"
},
{
"cited": "a2c6c7000702",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'a2c6c7000702' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:49:22.443Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:49:22.447Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/runkeys.csv"
}
|
| 2026-06-13T06:49:22.450Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__runkeys.csv",
"annotated_rows": 2,
"artifact_key": "runkeys",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:49:54.723Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 32.276238,
"status": "success",
"token_count": 461
}
|
| 2026-06-13T06:49:54.728Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Run",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RunOnce",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RunOnceEx",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'Run' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RunOnce' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RunOnceEx' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:49:54.732Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:49:55.240Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/tasks.csv"
}
|
| 2026-06-13T06:49:55.251Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__tasks.csv",
"annotated_rows": 15,
"artifact_key": "tasks",
"removed_records": 35,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T06:51:58.589Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 123.8525,
"status": "success",
"token_count": 958
}
|
| 2026-06-13T06:51:58.595Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 20,
"skipped": 0,
"total": 20
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "task_path",
"match_status": "exact",
"matched_header": "task_path"
},
{
"cited": "author",
"match_status": "exact",
"matched_header": "author"
},
{
"cited": "user_id",
"match_status": "exact",
"matched_header": "user_id"
},
{
"cited": "System",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "run_level",
"match_status": "exact",
"matched_header": "run_level"
},
{
"cited": "HighestAvailable",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "logon_type",
"match_status": "exact",
"matched_header": "logon_type"
},
{
"cited": "InteractiveTokenOrPassword",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "command",
"match_status": "exact",
"matched_header": "command"
},
{
"cited": "arguments",
"match_status": "exact",
"matched_header": "arguments"
}
],
"warning_count": 6,
"warnings": [
"Note: AI cited column 'System' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'HighestAvailable' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'InteractiveTokenOrPassword' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'True' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'vssadmin.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'sc.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:51:58.598Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:51:58.655Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/services.csv"
}
|
| 2026-06-13T06:51:58.658Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__services.csv",
"annotated_rows": 406,
"artifact_key": "services",
"removed_records": 1210,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T06:55:51.475Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 232.874349,
"status": "success",
"token_count": 1466
}
|
| 2026-06-13T06:55:51.484Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 9,
"skipped": 0,
"total": 9
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 6,
"skipped": 0,
"total": 6
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Program.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Microsoft.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Advanced.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Mnemosyne.sys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_32.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_64.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Program.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Microsoft.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Advanced.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Mnemosyne.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_32.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_64.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T06:55:51.487Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:55:51.625Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shimcache.csv"
}
|
| 2026-06-13T06:55:51.628Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__shimcache.csv",
"annotated_rows": 277,
"artifact_key": "shimcache",
"removed_records": 831,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T06:57:42.154Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 110.66333,
"status": "success",
"token_count": 1159
}
|
| 2026-06-13T06:57:42.161Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 10,
"skipped": 0,
"total": 10
},
"timestamps": {
"checked": 11,
"skipped": 0,
"total": 11
}
},
"citation_validation": "warnings_found",
"warning_count": 1,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data."
]
}
|
| 2026-06-13T06:57:42.164Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T06:57:42.212Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"last_modified_timestamp",
"last_modified_store_timestamp",
"link_timestamp",
"created_timestamp",
"mtime_regf",
"reference",
"path",
"language_code",
"digest",
"program_id",
"pe_header_checksum",
"pe_size_of_image",
"product_name",
"company_name",
"file_size",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"name",
"version",
"publisher",
"entry_type",
"uninstall_key",
"product_code",
"package_code",
"msi_package_code",
"msi_package_code2"
],
"missing_columns": [
"ts",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent"
]
}
|
| 2026-06-13T06:57:42.257Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp",
"path",
"name",
"publisher",
"version",
"product_name",
"company_name",
"digest",
"file_size",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/amcache.csv"
}
|
| 2026-06-13T06:57:42.261Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__amcache.csv",
"annotated_rows": 30,
"artifact_key": "amcache",
"removed_records": 31,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/amcache.csv",
"variant_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp"
]
}
|
| 2026-06-13T07:00:04.130Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 141.962507,
"status": "success",
"token_count": 1479
}
|
| 2026-06-13T07:00:04.142Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 11,
"skipped": 0,
"total": 11
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "f18a9425d17da9067304409ec0a8b73e35279c85",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi_32",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi_64",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "d4206fc233e3a708b54439e1c2bc12b48a755ed1",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_32.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_64.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited timestamp 2018-09-07 which could not be verified in the source data.",
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'f18a9425d17da9067304409ec0a8b73e35279c85' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi_32' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi_64' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'd4206fc233e3a708b54439e1c2bc12b48a755ed1' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_32.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_64.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:00:04.145Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:00:04.152Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/userassist.csv"
}
|
| 2026-06-13T07:00:04.155Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__userassist.csv",
"annotated_rows": 5,
"artifact_key": "userassist",
"removed_records": 7,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:02:18.326Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 134.177848,
"status": "success",
"token_count": 1013
}
|
| 2026-06-13T07:02:18.332Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 8,
"skipped": 0,
"total": 8
},
"timestamps": {
"checked": 8,
"skipped": 0,
"total": 8
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "ri.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Microsoft.Windows.RemoteDesktop",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'ri.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Microsoft.Windows.RemoteDesktop' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:02:18.335Z |
analysis_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:02:18.340Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__recyclebin.csv",
"artifact_key": "recyclebin",
"projection_columns": [
"ts",
"path",
"deleted_path",
"filesize",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/recyclebin.csv"
}
|
| 2026-06-13T07:02:18.344Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__recyclebin.csv",
"annotated_rows": 0,
"artifact_key": "recyclebin",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/recyclebin.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:04:48.649Z |
analysis_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"duration_seconds": 150.31057,
"status": "success",
"token_count": 945
}
|
| 2026-06-13T07:04:48.653Z |
citation_validation |
{
"artifact_key": "recyclebin",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "private_keys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "certs",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "certificate_requests",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "puppet",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ruby",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "vss39",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 7,
"warnings": [
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'private_keys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'certs' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'certificate_requests' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'puppet' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ruby' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'vss39' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:04:48.656Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:04:48.664Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.history.csv"
}
|
| 2026-06-13T07:04:48.667Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__browser.history.csv",
"annotated_rows": 0,
"artifact_key": "browser.history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:08:35.312Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"duration_seconds": 226.652696,
"status": "success",
"token_count": 935
}
|
| 2026-06-13T07:08:35.316Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 8,
"skipped": 0,
"total": 8
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "row_ref",
"match_status": "exact",
"matched_header": "row_ref"
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "from_url",
"match_status": "exact",
"matched_header": "from_url"
},
{
"cited": "typed",
"match_status": "exact",
"matched_header": "typed"
},
{
"cited": "hidden",
"match_status": "exact",
"matched_header": "hidden"
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:08:35.319Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:08:35.324Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.downloads.csv"
}
|
| 2026-06-13T07:08:35.327Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T07:09:53.324Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 78.002068,
"status": "success",
"token_count": 1153
}
|
| 2026-06-13T07:09:53.329Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "iexplore",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "WebCacheV01.dat",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "size",
"match_status": "exact",
"matched_header": "size"
},
{
"cited": "state",
"match_status": "exact",
"matched_header": "state"
},
{
"cited": "ts_start",
"match_status": "exact",
"matched_header": "ts_start"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'iexplore' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'WebCacheV01.dat' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:09:53.332Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:09:53.338Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T07:09:53.341Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__jumplist.automatic_destination.csv",
"annotated_rows": 0,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T07:12:32.079Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 158.74409,
"status": "success",
"token_count": 1106
}
|
| 2026-06-13T07:12:32.085Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 9,
"skipped": 0,
"total": 9
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "application_name",
"match_status": "exact",
"matched_header": "application_name"
},
{
"cited": "lnk_name",
"match_status": "exact",
"matched_header": "lnk_name"
},
{
"cited": "lnk_arguments",
"match_status": "exact",
"matched_header": "lnk_arguments"
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
},
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "lnk_device_name",
"match_status": "exact",
"matched_header": "lnk_device_name"
},
{
"cited": "common_path_suffix",
"match_status": "exact",
"matched_header": "common_path_suffix"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:12:32.089Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:12:32.094Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T07:12:32.097Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__jumplist.custom_destination.csv",
"annotated_rows": 6,
"artifact_key": "jumplist.custom_destination",
"removed_records": 9,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T07:13:23.849Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 51.756555,
"status": "success",
"token_count": 416
}
|
| 2026-06-13T07:13:23.852Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "customDestinations",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "AutomaticDestinations",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_arguments",
"match_status": "exact",
"matched_header": "lnk_arguments"
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
},
{
"cited": "lnk_atime",
"match_status": "exact",
"matched_header": "lnk_atime"
},
{
"cited": "lnk_ctime",
"match_status": "exact",
"matched_header": "lnk_ctime"
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "lnk_device_name",
"match_status": "exact",
"matched_header": "lnk_device_name"
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'customDestinations' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'AutomaticDestinations' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:13:23.857Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:13:23.893Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shellbags.csv"
}
|
| 2026-06-13T07:13:23.896Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__shellbags.csv",
"annotated_rows": 34,
"artifact_key": "shellbags",
"removed_records": 45,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T07:15:45.500Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 141.61787,
"status": "success",
"token_count": 1865
}
|
| 2026-06-13T07:15:45.507Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 23,
"skipped": 0,
"total": 23
},
"row_refs": {
"checked": 20,
"skipped": 0,
"total": 20
},
"timestamps": {
"checked": 13,
"skipped": 0,
"total": 13
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Windows",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "System32",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SysWOW64",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Temp",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Logs",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RegBack",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SAM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SECURITY",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SYSTEM",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 20,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Windows' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'System32' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SysWOW64' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Temp' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Logs' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RegBack' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SAM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SECURITY' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SYSTEM' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:15:45.511Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:15:45.515Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/sam.csv"
}
|
| 2026-06-13T07:15:45.518Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__sam.csv",
"annotated_rows": 4,
"artifact_key": "sam",
"removed_records": 4,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T07:20:48.596Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 303.082526,
"status": "success",
"token_count": 492
}
|
| 2026-06-13T07:20:48.599Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T07:20:48.602Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:20:48.607Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/network_history.csv"
}
|
| 2026-06-13T07:20:48.611Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed_deduplicated/66190324-1efb-42d2-b2c4-316e91c91631__network_history.csv",
"annotated_rows": 3,
"artifact_key": "network_history",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/66190324-1efb-42d2-b2c4-316e91c91631/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T07:21:26.001Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 37.395326,
"status": "success",
"token_count": 475
}
|
| 2026-06-13T07:21:26.004Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_connected",
"match_status": "exact",
"matched_header": "last_connected"
},
{
"cited": "default_gateway_mac",
"match_status": "exact",
"matched_header": "default_gateway_mac"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:21:26.007Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:21:26.011Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/runkeys.csv"
}
|
| 2026-06-13T07:21:26.014Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__runkeys.csv",
"annotated_rows": 0,
"artifact_key": "runkeys",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:22:49.223Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 83.213502,
"status": "success",
"token_count": 1185
}
|
| 2026-06-13T07:22:49.227Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 9,
"skipped": 0,
"total": 9
},
"row_refs": {
"checked": 6,
"skipped": 0,
"total": 6
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalService",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "NetworkService",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "OneDriveSetup.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Dashlane",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "tdungan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "DashlanePlugin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RegBack",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalService' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'NetworkService' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'OneDriveSetup.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Dashlane' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'tdungan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'DashlanePlugin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RegBack' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:22:49.230Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:22:51.056Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/tasks.csv"
}
|
| 2026-06-13T07:22:51.457Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__tasks.csv",
"annotated_rows": 257,
"artifact_key": "tasks",
"removed_records": 343,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T07:26:04.478Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 195.244816,
"status": "success",
"token_count": 911
}
|
| 2026-06-13T07:26:04.486Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "True",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Exec",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "CreateExplorerShellUnelevatedTask",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Explorer.EXE",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ExplorerShellUnelevated",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
},
{
"cited": "date",
"match_status": "exact",
"matched_header": "date"
},
{
"cited": "action_type",
"match_status": "exact",
"matched_header": "action_type"
},
{
"cited": "ComHandler",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "action",
"match_status": "exact",
"matched_header": "action"
}
],
"warning_count": 6,
"warnings": [
"Note: AI cited column 'True' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Exec' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'CreateExplorerShellUnelevatedTask' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Explorer.EXE' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ExplorerShellUnelevated' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ComHandler' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:26:04.490Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:26:04.522Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/services.csv"
}
|
| 2026-06-13T07:26:04.525Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__services.csv",
"annotated_rows": 0,
"artifact_key": "services",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:28:19.074Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 134.581024,
"status": "success",
"token_count": 1545
}
|
| 2026-06-13T07:28:19.086Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 15,
"skipped": 0,
"total": 15
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "npf",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mfeavfk01",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "imagepath",
"match_status": "exact",
"matched_header": "imagepath"
},
{
"cited": "description",
"match_status": "exact",
"matched_header": "description"
},
{
"cited": "objectname",
"match_status": "exact",
"matched_header": "objectname"
},
{
"cited": "servicedll",
"match_status": "exact",
"matched_header": "servicedll"
},
{
"cited": "mfeavfk",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mfeavfk01.sys",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 10,
"warnings": [
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'npf' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mfeavfk01' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mfeavfk' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mfeavfk01.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Mnemosyne.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'npf.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'FailureActions' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:28:19.094Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:28:19.135Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shimcache.csv"
}
|
| 2026-06-13T07:28:19.138Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__shimcache.csv",
"annotated_rows": 0,
"artifact_key": "shimcache",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T07:31:27.483Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 188.384093,
"status": "success",
"token_count": 1992
}
|
| 2026-06-13T07:31:27.508Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 14,
"skipped": 0,
"total": 14
},
"row_refs": {
"checked": 25,
"skipped": 0,
"total": 25
},
"timestamps": {
"checked": 19,
"skipped": 0,
"total": 19
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "csrss.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "volrest.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ri.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "p.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "pa.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "pb.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "install_wormhole",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_modified",
"match_status": "exact",
"matched_header": "last_modified"
}
],
"warning_count": 13,
"warnings": [
"Note: AI cited column 'csrss.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'volrest.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ri.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'p.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'pa.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'pb.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'install_wormhole' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Autorunsc.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:31:27.511Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:31:27.595Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"mtime_regf",
"program_id",
"digest",
"path",
"hash_path",
"name",
"publisher",
"version",
"bin_file_version",
"product_name",
"product_version",
"link_date",
"bin_product_version",
"size",
"language",
"is_pefile",
"is_oscomponent",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"install_date_arp_last_modified",
"install_date_from_link_file",
"language_code",
"msi_package_code",
"msi_product_code",
"package_full_name",
"type",
"manifest_path",
"os_version_at_install_time",
"program_instance_id",
"registry_key_path",
"root_dir_path",
"source",
"uninstall_string",
"categories",
"discovery_method",
"friendly_name",
"icon",
"is_active",
"is_connected",
"is_machine_container",
"is_networked",
"is_paired",
"manufacturer",
"model_id",
"model_name",
"model_number",
"primary_category",
"state",
"driver_name",
"inf",
"driver_version",
"product",
"wdf_version",
"driver_company",
"driver_package_strong_name",
"service",
"driver_signed",
"driver_is_kernel_mode",
"last_write_time",
"driver_timestamp",
"image_size"
],
"missing_columns": [
"ts",
"last_modified_timestamp",
"created_timestamp",
"company_name",
"file_size"
]
}
|
| 2026-06-13T07:31:27.660Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"path",
"name",
"publisher",
"version",
"product_name",
"digest",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/amcache.csv"
}
|
| 2026-06-13T07:31:27.668Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__amcache.csv",
"annotated_rows": 2,
"artifact_key": "amcache",
"removed_records": 9,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/amcache.csv",
"variant_columns": [
"install_date"
]
}
|
| 2026-06-13T07:33:40.503Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 132.988418,
"status": "success",
"token_count": 1778
}
|
| 2026-06-13T07:33:40.511Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 10,
"skipped": 0,
"total": 10
},
"row_refs": {
"checked": 10,
"skipped": 0,
"total": 10
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "f6b2ac3a5bcdd89d15348320323c14039a4139c0",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "procdump.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "desktop",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "f718ce10e0190870edcbee77ab6a11e39d154584",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "winpcap",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "c99aa678f387c00c4470fa3cd7b037d26720960d",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rpcapd",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "install_date",
"match_status": "exact",
"matched_header": "install_date"
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited column 'f6b2ac3a5bcdd89d15348320323c14039a4139c0' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'procdump.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'desktop' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'f718ce10e0190870edcbee77ab6a11e39d154584' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'winpcap' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'c99aa678f387c00c4470fa3cd7b037d26720960d' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rpcapd' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:33:40.515Z |
analysis_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:33:40.520Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__bam.csv",
"artifact_key": "bam",
"projection_columns": [
"ts",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/bam.csv"
}
|
| 2026-06-13T07:33:40.524Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__bam.csv",
"annotated_rows": 10,
"artifact_key": "bam",
"removed_records": 24,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/bam.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:37:21.731Z |
analysis_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"duration_seconds": 221.212458,
"status": "success",
"token_count": 772
}
|
| 2026-06-13T07:37:21.735Z |
citation_validation |
{
"artifact_key": "bam",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "cmd.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mstsc.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'cmd.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mstsc.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:37:21.738Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:37:21.747Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/userassist.csv"
}
|
| 2026-06-13T07:37:21.750Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__userassist.csv",
"annotated_rows": 3,
"artifact_key": "userassist",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:41:04.095Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 222.354141,
"status": "success",
"token_count": 1186
}
|
| 2026-06-13T07:41:04.104Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "sc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "schtasks.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "sdelete.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'sc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'schtasks.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'sdelete.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:41:04.109Z |
analysis_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:41:04.115Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__recyclebin.csv",
"artifact_key": "recyclebin",
"projection_columns": [
"ts",
"path",
"deleted_path",
"filesize",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/recyclebin.csv"
}
|
| 2026-06-13T07:41:04.128Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__recyclebin.csv",
"annotated_rows": 0,
"artifact_key": "recyclebin",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/recyclebin.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:43:30.760Z |
analysis_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"duration_seconds": 146.647487,
"status": "success",
"token_count": 507
}
|
| 2026-06-13T07:43:30.763Z |
citation_validation |
{
"artifact_key": "recyclebin",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:43:30.766Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:43:30.834Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.history.csv"
}
|
| 2026-06-13T07:43:30.837Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__browser.history.csv",
"annotated_rows": 135,
"artifact_key": "browser.history",
"removed_records": 210,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T07:43:30.999Z |
chunked_analysis_started |
{
"artifact_key": "browser.history",
"chunk_reason": "prompt_plus_inlined_CSV_attachment_fallback",
"csv_budget_per_chunk": 195770,
"total_chunks": 2
}
|
| 2026-06-13T07:51:10.127Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"chunked": true,
"duration_seconds": 459.358526,
"processing_warnings": [],
"status": "success",
"token_count": 1980
}
|
| 2026-06-13T07:51:10.144Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 7,
"skipped": 0,
"total": 7
},
"timestamps": {
"checked": 18,
"skipped": 0,
"total": 18
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "sendspace.com",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "tdungan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "bitcoinwhoswho.com",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "iexplore",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "title",
"match_status": "exact",
"matched_header": "title"
},
{
"cited": "host",
"match_status": "exact",
"matched_header": "host"
},
{
"cited": "visit_type",
"match_status": "exact",
"matched_header": "visit_type"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'sendspace.com' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'tdungan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'bitcoinwhoswho.com' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'iexplore' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:51:10.148Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:51:10.154Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.downloads.csv"
}
|
| 2026-06-13T07:51:10.159Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T07:52:18.837Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 68.686012,
"status": "success",
"token_count": 487
}
|
| 2026-06-13T07:52:18.843Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "DashlaneInst.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_start",
"match_status": "exact",
"matched_header": "ts_start"
},
{
"cited": "size",
"match_status": "exact",
"matched_header": "size"
},
{
"cited": "state",
"match_status": "exact",
"matched_header": "state"
},
{
"cited": "tdungan",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'DashlaneInst.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'tdungan' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:52:18.846Z |
analysis_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:52:18.851Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__powershell_history.csv",
"artifact_key": "powershell_history",
"projection_columns": [
"mtime",
"order",
"command",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/powershell_history.csv"
}
|
| 2026-06-13T07:52:18.855Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__powershell_history.csv",
"annotated_rows": 0,
"artifact_key": "powershell_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/powershell_history.csv",
"variant_columns": [
"mtime"
]
}
|
| 2026-06-13T07:53:45.765Z |
analysis_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"duration_seconds": 86.915856,
"status": "success",
"token_count": 1560
}
|
| 2026-06-13T07:53:45.771Z |
citation_validation |
{
"artifact_key": "powershell_history",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 9,
"skipped": 0,
"total": 9
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "ntdsutil",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "NTDS.dit",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SYSTEM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SECURITY",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "perfmon",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "del",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "copy",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mv",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "robocopy",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 11,
"warnings": [
"Note: AI cited column 'ntdsutil' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'NTDS.dit' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SYSTEM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SECURITY' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'perfmon' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'del' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'copy' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mv' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'robocopy' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:53:45.775Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:53:45.793Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T07:53:45.797Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__jumplist.automatic_destination.csv",
"annotated_rows": 2,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 5,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T07:58:13.845Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 268.066422,
"status": "success",
"token_count": 1582
}
|
| 2026-06-13T07:58:13.872Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 16,
"skipped": 0,
"total": 16
},
"row_refs": {
"checked": 13,
"skipped": 0,
"total": 13
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "common_path_suffix",
"match_status": "exact",
"matched_header": "common_path_suffix"
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
},
{
"cited": "MH_Eyes_Only",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Targets",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "tdungan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
},
{
"cited": "application_name",
"match_status": "exact",
"matched_header": "application_name"
},
{
"cited": "local_base_path",
"match_status": "exact",
"matched_header": "local_base_path"
}
],
"warning_count": 7,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'MH_Eyes_Only' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Targets' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'tdungan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'StarkExpo' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'explorer.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Perfmon' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T07:58:13.876Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T07:58:13.889Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T07:58:13.892Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__jumplist.custom_destination.csv",
"annotated_rows": 9,
"artifact_key": "jumplist.custom_destination",
"removed_records": 19,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T08:00:28.867Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 134.983408,
"status": "success",
"token_count": 693
}
|
| 2026-06-13T08:00:28.875Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Temp",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Downloads",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Public",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_arguments",
"match_status": "exact",
"matched_header": "lnk_arguments"
},
{
"cited": "CustomDestinations",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "AutomaticDestinations",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "lnk_device_name",
"match_status": "exact",
"matched_header": "lnk_device_name"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'Temp' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Downloads' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Public' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'CustomDestinations' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'AutomaticDestinations' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:00:28.895Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:00:28.931Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shellbags.csv"
}
|
| 2026-06-13T08:00:28.941Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__shellbags.csv",
"annotated_rows": 59,
"artifact_key": "shellbags",
"removed_records": 77,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T08:04:57.919Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 269.01064,
"status": "success",
"token_count": 1705
}
|
| 2026-06-13T08:04:57.925Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 48,
"skipped": 0,
"total": 48
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "perfmon",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "ts_mtime",
"match_status": "exact",
"matched_header": "ts_mtime"
},
{
"cited": "cmd.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'perfmon' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'cmd.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:04:57.928Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:04:57.932Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/sam.csv"
}
|
| 2026-06-13T08:04:57.935Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__sam.csv",
"annotated_rows": 0,
"artifact_key": "sam",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T08:09:34.798Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 276.867268,
"status": "success",
"token_count": 1153
}
|
| 2026-06-13T08:09:34.805Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 2,
"skipped": 0,
"total": 2
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
},
{
"cited": "lastpasswordset",
"match_status": "exact",
"matched_header": "lastpasswordset"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T08:09:34.808Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:09:34.817Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/network_history.csv"
}
|
| 2026-06-13T08:09:34.820Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed_deduplicated/a66612b5-ee40-416e-8eb2-49ec34b9b3b1__network_history.csv",
"annotated_rows": 0,
"artifact_key": "network_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/a66612b5-ee40-416e-8eb2-49ec34b9b3b1/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T08:10:45.284Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 70.467839,
"status": "success",
"token_count": 445
}
|
| 2026-06-13T08:10:45.292Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:10:45.295Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:10:45.299Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/runkeys.csv"
}
|
| 2026-06-13T08:10:45.302Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__runkeys.csv",
"annotated_rows": 0,
"artifact_key": "runkeys",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T08:13:30.340Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 165.042573,
"status": "success",
"token_count": 821
}
|
| 2026-06-13T08:13:30.344Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "lariat.cmd",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "OneDrive",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rundll32",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "regsvr32",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'lariat.cmd' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'OneDrive' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rundll32' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'regsvr32' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:13:30.348Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:13:32.107Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/tasks.csv"
}
|
| 2026-06-13T08:13:32.111Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__tasks.csv",
"annotated_rows": 254,
"artifact_key": "tasks",
"removed_records": 344,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T08:15:24.157Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 113.805401,
"status": "success",
"token_count": 968
}
|
| 2026-06-13T08:15:24.174Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "ExplorerShellUnelevated",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "False",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Exec",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "date",
"match_status": "exact",
"matched_header": "date"
},
{
"cited": "Explorer.EXE",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rangeadmin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
},
{
"cited": "CreateExplorerShellUnelevatedTask",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 6,
"warnings": [
"Note: AI cited column 'ExplorerShellUnelevated' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'False' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Exec' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Explorer.EXE' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rangeadmin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'CreateExplorerShellUnelevatedTask' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:15:24.178Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:15:24.207Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/services.csv"
}
|
| 2026-06-13T08:15:24.210Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__services.csv",
"annotated_rows": 0,
"artifact_key": "services",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T08:18:17.467Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 173.286605,
"status": "success",
"token_count": 1675
}
|
| 2026-06-13T08:18:17.479Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Mnemosyne.sys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "prunsrv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LARIAT",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "npf",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RUNNING",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "STOPPED",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_32.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi2_64.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 10,
"warnings": [
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Mnemosyne.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'prunsrv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LARIAT' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'npf' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RUNNING' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'STOPPED' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_32.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_64.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:18:17.482Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:18:17.504Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shimcache.csv"
}
|
| 2026-06-13T08:18:17.508Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__shimcache.csv",
"annotated_rows": 0,
"artifact_key": "shimcache",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T08:22:23.446Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 245.96112,
"status": "success",
"token_count": 1933
}
|
| 2026-06-13T08:22:23.456Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 13,
"skipped": 0,
"total": 13
},
"timestamps": {
"checked": 19,
"skipped": 0,
"total": 19
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "sd.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "perfmon",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "BrowsingHistoryView.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Autorunsc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_modified",
"match_status": "exact",
"matched_header": "last_modified"
},
{
"cited": "wsmprovhost.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mstsc.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 7,
"warnings": [
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'sd.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'perfmon' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'BrowsingHistoryView.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Autorunsc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'wsmprovhost.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mstsc.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:22:23.459Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:22:23.523Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"mtime_regf",
"program_id",
"digest",
"path",
"hash_path",
"name",
"publisher",
"version",
"bin_file_version",
"product_name",
"product_version",
"link_date",
"bin_product_version",
"size",
"language",
"is_pefile",
"is_oscomponent",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"install_date_arp_last_modified",
"install_date_from_link_file",
"language_code",
"msi_package_code",
"msi_product_code",
"package_full_name",
"type",
"manifest_path",
"os_version_at_install_time",
"program_instance_id",
"registry_key_path",
"root_dir_path",
"source",
"uninstall_string",
"categories",
"discovery_method",
"friendly_name",
"icon",
"is_active",
"is_connected",
"is_machine_container",
"is_networked",
"is_paired",
"manufacturer",
"model_id",
"model_name",
"model_number",
"primary_category",
"state",
"driver_name",
"inf",
"driver_version",
"product",
"wdf_version",
"driver_company",
"driver_package_strong_name",
"service",
"driver_signed",
"driver_is_kernel_mode",
"last_write_time",
"driver_timestamp",
"image_size"
],
"missing_columns": [
"ts",
"last_modified_timestamp",
"created_timestamp",
"company_name",
"file_size"
]
}
|
| 2026-06-13T08:22:23.575Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"path",
"name",
"publisher",
"version",
"product_name",
"digest",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/amcache.csv"
}
|
| 2026-06-13T08:22:23.578Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__amcache.csv",
"annotated_rows": 2,
"artifact_key": "amcache",
"removed_records": 8,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/amcache.csv",
"variant_columns": [
"install_date"
]
}
|
| 2026-06-13T08:24:21.707Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 118.244122,
"status": "success",
"token_count": 1651
}
|
| 2026-06-13T08:24:21.715Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 12,
"skipped": 0,
"total": 12
},
"row_refs": {
"checked": 15,
"skipped": 0,
"total": 15
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "beb067d29fe33cee31784011729e7355daf562b9",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi_32",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "msadvapi_64",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SystemInit",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "elevate.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nssm.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "delprof.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "pscp.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nssm",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "install_date",
"match_status": "exact",
"matched_header": "install_date"
}
],
"warning_count": 11,
"warnings": [
"Note: AI cited column 'beb067d29fe33cee31784011729e7355daf562b9' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi_32' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi_64' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SystemInit' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'elevate.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nssm.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'delprof.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'pscp.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nssm' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'msadvapi2_32.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:24:21.718Z |
analysis_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:24:21.723Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__bam.csv",
"artifact_key": "bam",
"projection_columns": [
"ts",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/bam.csv"
}
|
| 2026-06-13T08:24:21.727Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__bam.csv",
"annotated_rows": 6,
"artifact_key": "bam",
"removed_records": 17,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/bam.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T08:25:57.472Z |
analysis_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"duration_seconds": 95.749399,
"status": "success",
"token_count": 520
}
|
| 2026-06-13T08:25:57.477Z |
citation_validation |
{
"artifact_key": "bam",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:25:57.481Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:25:57.491Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/userassist.csv"
}
|
| 2026-06-13T08:25:57.494Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__userassist.csv",
"annotated_rows": 5,
"artifact_key": "userassist",
"removed_records": 5,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T08:27:49.886Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 112.401201,
"status": "success",
"token_count": 1250
}
|
| 2026-06-13T08:27:49.894Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 8,
"skipped": 0,
"total": 8
},
"timestamps": {
"checked": 10,
"skipped": 0,
"total": 10
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "E7CF176E110C211B",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "kellee.espinoza",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "cmd.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'E7CF176E110C211B' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'kellee.espinoza' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'cmd.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T08:27:49.897Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T08:27:50.643Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/browser.history.csv"
}
|
| 2026-06-13T08:27:50.647Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__browser.history.csv",
"annotated_rows": 6,
"artifact_key": "browser.history",
"removed_records": 6,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T08:27:51.668Z |
chunked_analysis_started |
{
"artifact_key": "browser.history",
"chunk_reason": "prompt_plus_inlined_CSV_attachment_fallback",
"csv_budget_per_chunk": 197439,
"total_chunks": 11
}
|
| 2026-06-13T09:03:33.830Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"chunked": true,
"duration_seconds": 2143.929459,
"processing_warnings": [],
"status": "success",
"token_count": 2655
}
|
| 2026-06-13T09:03:33.970Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 13,
"skipped": 0,
"total": 13
},
"row_refs": {
"checked": 20,
"skipped": 0,
"total": 20
},
"timestamps": {
"checked": 20,
"skipped": 0,
"total": 20
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "jpallen",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "live.com",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "kellee.espinoza",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "iexplore.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "hidden",
"match_status": "exact",
"matched_header": "hidden"
},
{
"cited": "True",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "title",
"match_status": "exact",
"matched_header": "title"
},
{
"cited": "host",
"match_status": "exact",
"matched_header": "host"
},
{
"cited": "visit_type",
"match_status": "exact",
"matched_header": "visit_type"
}
],
"warning_count": 8,
"warnings": [
"Note: AI cited timestamp 2018-05-23T05:57:56.627573+00:00 which could not be verified in the source data.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'jpallen' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'live.com' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'kellee.espinoza' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'iexplore.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'True' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'runas' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T09:03:33.975Z |
analysis_started |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T09:03:33.979Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__powershell_history.csv",
"artifact_key": "powershell_history",
"projection_columns": [
"mtime",
"order",
"command",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/powershell_history.csv"
}
|
| 2026-06-13T09:03:33.981Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__powershell_history.csv",
"annotated_rows": 0,
"artifact_key": "powershell_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/powershell_history.csv",
"variant_columns": [
"mtime"
]
}
|
| 2026-06-13T09:04:38.307Z |
analysis_completed |
{
"artifact_key": "powershell_history",
"artifact_name": "PowerShell History",
"duration_seconds": 64.329231,
"status": "success",
"token_count": 1174
}
|
| 2026-06-13T09:04:38.314Z |
citation_validation |
{
"artifact_key": "powershell_history",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "squirrreldirectory",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mtime",
"match_status": "exact",
"matched_header": "mtime"
},
{
"cited": "ConsoleHost_history.txt",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'squirrreldirectory' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ConsoleHost_history.txt' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T09:04:38.317Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T09:04:38.723Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T09:04:38.726Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__jumplist.automatic_destination.csv",
"annotated_rows": 0,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T09:04:40.174Z |
chunked_analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"chunk_reason": "prompt_plus_inlined_CSV_attachment_fallback",
"csv_budget_per_chunk": 188232,
"total_chunks": 17
}
|
| 2026-06-13T10:19:34.006Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"chunked": true,
"duration_seconds": 4495.680423,
"processing_warnings": [],
"status": "success",
"token_count": 3575
}
|
| 2026-06-13T10:19:34.274Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 25,
"skipped": 0,
"total": 25
},
"row_refs": {
"checked": 16,
"skipped": 0,
"total": 16
},
"timestamps": {
"checked": 27,
"skipped": 0,
"total": 27
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_atime",
"match_status": "exact",
"matched_header": "lnk_atime"
},
{
"cited": "target_ctime",
"match_status": "exact",
"matched_header": "target_ctime"
},
{
"cited": "jpallen",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Carbonadium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Vibranium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Unobtanium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_ctime",
"match_status": "exact",
"matched_header": "lnk_ctime"
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
},
{
"cited": "f01b4d95cf55d32a",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 15,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'jpallen' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Carbonadium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Vibranium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Unobtanium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'f01b4d95cf55d32a' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'userAccountControl' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'kellee.espinoza' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'collaborationSpreadSheetDoc3513012194788184988.xls' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:19:34.279Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:19:34.284Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T10:19:34.287Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__jumplist.custom_destination.csv",
"annotated_rows": 4,
"artifact_key": "jumplist.custom_destination",
"removed_records": 8,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T10:21:26.201Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 111.919157,
"status": "success",
"token_count": 765
}
|
| 2026-06-13T10:21:26.207Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 10,
"skipped": 0,
"total": 10
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
},
{
"cited": "lnk_path",
"match_status": "exact",
"matched_header": "lnk_path"
},
{
"cited": "local_base_path",
"match_status": "exact",
"matched_header": "local_base_path"
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
},
{
"cited": "lnk_atime",
"match_status": "exact",
"matched_header": "lnk_atime"
},
{
"cited": "lnk_ctime",
"match_status": "exact",
"matched_header": "lnk_ctime"
},
{
"cited": "AutomaticDestinations",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_full_path",
"match_status": "exact",
"matched_header": "lnk_full_path"
},
{
"cited": "lnk_arguments",
"match_status": "exact",
"matched_header": "lnk_arguments"
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'AutomaticDestinations' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:21:26.210Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:21:26.216Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shellbags.csv"
}
|
| 2026-06-13T10:21:26.218Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__shellbags.csv",
"annotated_rows": 0,
"artifact_key": "shellbags",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T10:24:54.846Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 208.633526,
"status": "success",
"token_count": 1322
}
|
| 2026-06-13T10:24:54.851Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 18,
"skipped": 0,
"total": 18
},
"timestamps": {
"checked": 15,
"skipped": 0,
"total": 15
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Carbonadium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Unobtanium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Vibranium",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'Carbonadium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Unobtanium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Vibranium' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:24:54.854Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:24:54.858Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/sam.csv"
}
|
| 2026-06-13T10:24:54.860Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__sam.csv",
"annotated_rows": 0,
"artifact_key": "sam",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T10:26:26.625Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 91.767829,
"status": "success",
"token_count": 976
}
|
| 2026-06-13T10:26:26.629Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 6,
"skipped": 0,
"total": 6
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "range_admin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lastlogin",
"match_status": "exact",
"matched_header": "lastlogin"
},
{
"cited": "lsass",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "NTDS.dit",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SECURITY",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'range_admin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'lsass' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'NTDS.dit' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SECURITY' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:26:26.633Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:26:26.636Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/network_history.csv"
}
|
| 2026-06-13T10:26:26.639Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed_deduplicated/c165a62c-fcc2-4feb-b9a0-5e42fe834047__network_history.csv",
"annotated_rows": 0,
"artifact_key": "network_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/c165a62c-fcc2-4feb-b9a0-5e42fe834047/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T10:28:32.148Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 125.511885,
"status": "success",
"token_count": 423
}
|
| 2026-06-13T10:28:32.153Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "a2c6c7000704",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'a2c6c7000704' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:28:32.156Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:28:32.162Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/runkeys.csv"
}
|
| 2026-06-13T10:28:32.165Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__runkeys.csv",
"annotated_rows": 0,
"artifact_key": "runkeys",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:29:34.002Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 61.841836,
"status": "success",
"token_count": 738
}
|
| 2026-06-13T10:29:34.006Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "OneDrive",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalService",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "NetworkService",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'OneDrive' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalService' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'NetworkService' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:29:34.009Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:29:35.891Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/tasks.csv"
}
|
| 2026-06-13T10:29:35.895Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__tasks.csv",
"annotated_rows": 260,
"artifact_key": "tasks",
"removed_records": 350,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T10:33:28.012Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 234.00034,
"status": "success",
"token_count": 417
}
|
| 2026-06-13T10:33:28.021Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 2,
"skipped": 0,
"total": 2
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
},
{
"cited": "date",
"match_status": "exact",
"matched_header": "date"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T10:33:28.023Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:33:28.055Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/services.csv"
}
|
| 2026-06-13T10:33:28.057Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__services.csv",
"annotated_rows": 0,
"artifact_key": "services",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:36:24.113Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 176.086681,
"status": "success",
"token_count": 972
}
|
| 2026-06-13T10:36:24.130Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Mnemosyne.sys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "WinDefend",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Manual",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "McShield",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "enterceptAgent",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 8,
"warnings": [
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Mnemosyne.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'WinDefend' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Manual' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'McShield' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'enterceptAgent' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:36:24.134Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:36:24.151Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shimcache.csv"
}
|
| 2026-06-13T10:36:24.154Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__shimcache.csv",
"annotated_rows": 0,
"artifact_key": "shimcache",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T10:39:17.979Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 173.841886,
"status": "success",
"token_count": 802
}
|
| 2026-06-13T10:39:17.987Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Services",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Run",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "AppCompatCacheParser.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Services' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Run' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'AppCompatCacheParser.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:39:17.990Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:39:18.191Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"mtime_regf",
"program_id",
"digest",
"path",
"hash_path",
"name",
"publisher",
"version",
"bin_file_version",
"product_name",
"product_version",
"link_date",
"bin_product_version",
"size",
"language",
"is_pefile",
"is_oscomponent",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"install_date_arp_last_modified",
"install_date_from_link_file",
"language_code",
"msi_package_code",
"msi_product_code",
"package_full_name",
"type",
"manifest_path",
"os_version_at_install_time",
"program_instance_id",
"registry_key_path",
"root_dir_path",
"source",
"uninstall_string",
"categories",
"discovery_method",
"friendly_name",
"icon",
"is_active",
"is_connected",
"is_machine_container",
"is_networked",
"is_paired",
"manufacturer",
"model_id",
"model_name",
"model_number",
"primary_category",
"state",
"driver_name",
"inf",
"driver_version",
"product",
"wdf_version",
"driver_company",
"driver_package_strong_name",
"service",
"driver_signed",
"driver_is_kernel_mode",
"last_write_time",
"driver_timestamp",
"image_size"
],
"missing_columns": [
"ts",
"last_modified_timestamp",
"created_timestamp",
"company_name",
"file_size"
]
}
|
| 2026-06-13T10:39:18.375Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"path",
"name",
"publisher",
"version",
"product_name",
"digest",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/amcache.csv"
}
|
| 2026-06-13T10:39:18.377Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__amcache.csv",
"annotated_rows": 3,
"artifact_key": "amcache",
"removed_records": 11,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/amcache.csv",
"variant_columns": [
"install_date"
]
}
|
| 2026-06-13T10:39:20.773Z |
chunked_analysis_started |
{
"artifact_key": "amcache",
"chunk_reason": "prompt_plus_inlined_CSV_attachment_fallback",
"csv_budget_per_chunk": 192807,
"total_chunks": 4
}
|
| 2026-06-13T10:53:16.716Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"chunked": true,
"duration_seconds": 838.722126,
"processing_warnings": [],
"status": "success",
"token_count": 2796
}
|
| 2026-06-13T10:53:16.729Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 13,
"skipped": 0,
"total": 13
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 0,
"skipped": 0,
"total": 0
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "ProgramData",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "k.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "googleupdatesetup.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "setup.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "NTUSER.DAT",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "UsrClass.dat",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "eqnedt32.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rpcapd.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 12,
"warnings": [
"Note: AI cited column 'ProgramData' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'k.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'googleupdatesetup.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'setup.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'NTUSER.DAT' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'UsrClass.dat' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'eqnedt32.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rpcapd.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:53:16.734Z |
analysis_started |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:53:16.739Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__bam.csv",
"artifact_key": "bam",
"projection_columns": [
"ts",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/bam.csv"
}
|
| 2026-06-13T10:53:16.741Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__bam.csv",
"annotated_rows": 9,
"artifact_key": "bam",
"removed_records": 18,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/bam.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:53:54.217Z |
analysis_completed |
{
"artifact_key": "bam",
"artifact_name": "BAM/DAM",
"duration_seconds": 37.479925,
"status": "success",
"token_count": 515
}
|
| 2026-06-13T10:53:54.226Z |
citation_validation |
{
"artifact_key": "bam",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Microsoft.Windows.Cortana_cw5n1h2txyewy",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Microsoft.WindowsStore_8wekyb3d8bbwe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "row_ref",
"match_status": "exact",
"matched_header": "row_ref"
},
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
},
{
"cited": "path",
"match_status": "exact",
"matched_header": "path"
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'Microsoft.Windows.Cortana_cw5n1h2txyewy' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Microsoft.WindowsStore_8wekyb3d8bbwe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:53:54.229Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:53:54.238Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/userassist.csv"
}
|
| 2026-06-13T10:53:54.241Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__userassist.csv",
"annotated_rows": 3,
"artifact_key": "userassist",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:55:29.710Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 95.47719,
"status": "success",
"token_count": 1450
}
|
| 2026-06-13T10:55:29.716Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "E7CF176E110C211B",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'E7CF176E110C211B' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:55:29.719Z |
analysis_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:55:29.723Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__recyclebin.csv",
"artifact_key": "recyclebin",
"projection_columns": [
"ts",
"path",
"deleted_path",
"filesize",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/recyclebin.csv"
}
|
| 2026-06-13T10:55:29.726Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__recyclebin.csv",
"annotated_rows": 0,
"artifact_key": "recyclebin",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/recyclebin.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:56:55.764Z |
analysis_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"duration_seconds": 86.041816,
"status": "success",
"token_count": 562
}
|
| 2026-06-13T10:56:55.769Z |
citation_validation |
{
"artifact_key": "recyclebin",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "TargetList",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "del",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rmdir",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'TargetList' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'del' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rmdir' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T10:56:55.772Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T10:56:55.942Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.history.csv"
}
|
| 2026-06-13T10:56:55.946Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__browser.history.csv",
"annotated_rows": 188,
"artifact_key": "browser.history",
"removed_records": 465,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T10:56:56.406Z |
chunked_analysis_started |
{
"artifact_key": "browser.history",
"chunk_reason": "prompt_plus_inlined_CSV_attachment_fallback",
"csv_budget_per_chunk": 193566,
"total_chunks": 5
}
|
| 2026-06-13T11:15:03.779Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"chunked": true,
"duration_seconds": 1088.003075,
"processing_warnings": [],
"status": "success",
"token_count": 2487
}
|
| 2026-06-13T11:15:03.811Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 10,
"skipped": 0,
"total": 10
},
"row_refs": {
"checked": 33,
"skipped": 0,
"total": 33
},
"timestamps": {
"checked": 35,
"skipped": 0,
"total": 35
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Object.getOwnPropertyNames",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "apply.bind",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spiderfoot.net",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mail.protonmail.com",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "visit_type",
"match_status": "exact",
"matched_header": "visit_type"
},
{
"cited": "typed",
"match_status": "exact",
"matched_header": "typed"
},
{
"cited": "hidden",
"match_status": "exact",
"matched_header": "hidden"
},
{
"cited": "title",
"match_status": "exact",
"matched_header": "title"
}
],
"warning_count": 7,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'Object.getOwnPropertyNames' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'apply.bind' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spiderfoot.net' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mail.protonmail.com' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:15:03.815Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:15:03.823Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.downloads.csv"
}
|
| 2026-06-13T11:15:03.825Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T11:16:00.193Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 56.37543,
"status": "success",
"token_count": 752
}
|
| 2026-06-13T11:16:00.206Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "sf.py",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spiderfoot.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "tdungan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'sf.py' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spiderfoot.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'tdungan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:16:00.208Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:16:00.236Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T11:16:00.243Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__jumplist.automatic_destination.csv",
"annotated_rows": 1,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T11:17:36.386Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 96.170469,
"status": "success",
"token_count": 1517
}
|
| 2026-06-13T11:17:36.407Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 6,
"skipped": 0,
"total": 6
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "administrator.shieldbase",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Competitive_Intel_Metals_Cybernetics.docx",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ProgramData",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_mtime",
"match_status": "exact",
"matched_header": "lnk_mtime"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'administrator.shieldbase' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Competitive_Intel_Metals_Cybernetics.docx' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ProgramData' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:17:36.410Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:17:36.416Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T11:17:36.419Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__jumplist.custom_destination.csv",
"annotated_rows": 6,
"artifact_key": "jumplist.custom_destination",
"removed_records": 12,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T11:19:39.141Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 122.727716,
"status": "success",
"token_count": 534
}
|
| 2026-06-13T11:19:39.147Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T11:19:39.151Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:19:39.161Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shellbags.csv"
}
|
| 2026-06-13T11:19:39.164Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__shellbags.csv",
"annotated_rows": 6,
"artifact_key": "shellbags",
"removed_records": 17,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T11:22:41.265Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 182.110064,
"status": "success",
"token_count": 892
}
|
| 2026-06-13T11:22:41.271Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "mhill",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Quarantine",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SAM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SECURITY",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Run",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "ts_mtime",
"match_status": "exact",
"matched_header": "ts_mtime"
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'mhill' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Quarantine' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SAM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SECURITY' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Run' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:22:41.275Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:22:41.279Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/sam.csv"
}
|
| 2026-06-13T11:22:41.282Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__sam.csv",
"annotated_rows": 0,
"artifact_key": "sam",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T11:27:55.060Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 313.781688,
"status": "success",
"token_count": 939
}
|
| 2026-06-13T11:27:55.064Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "range_admin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "defaultuser0",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "flags",
"match_status": "exact",
"matched_header": "flags"
},
{
"cited": "lastlogin",
"match_status": "exact",
"matched_header": "lastlogin"
},
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'range_admin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'defaultuser0' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:27:55.067Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:27:55.071Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/network_history.csv"
}
|
| 2026-06-13T11:27:55.074Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed_deduplicated/6d4f645a-4d9c-46c3-a93f-317ae2800b3b__network_history.csv",
"annotated_rows": 0,
"artifact_key": "network_history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/6d4f645a-4d9c-46c3-a93f-317ae2800b3b/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T11:29:25.970Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 90.899849,
"status": "success",
"token_count": 539
}
|
| 2026-06-13T11:29:25.975Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "default_gateway_mac",
"match_status": "exact",
"matched_header": "default_gateway_mac"
},
{
"cited": "a2c6c7000705",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_connected",
"match_status": "exact",
"matched_header": "last_connected"
},
{
"cited": "profile_name",
"match_status": "exact",
"matched_header": "profile_name"
},
{
"cited": "description",
"match_status": "exact",
"matched_header": "description"
},
{
"cited": "Network",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "signature",
"match_status": "exact",
"matched_header": "signature"
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'a2c6c7000705' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Network' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:29:25.978Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:29:25.982Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/runkeys.csv"
}
|
| 2026-06-13T11:29:25.985Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__runkeys.csv",
"annotated_rows": 3,
"artifact_key": "runkeys",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:30:09.320Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 43.339048,
"status": "success",
"token_count": 392
}
|
| 2026-06-13T11:30:09.331Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "mctadmin.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "spsql",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Sidebar",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mctadmin",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'mctadmin.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'spsql' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Sidebar' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mctadmin' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:30:09.334Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:30:09.833Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/tasks.csv"
}
|
| 2026-06-13T11:30:09.845Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__tasks.csv",
"annotated_rows": 14,
"artifact_key": "tasks",
"removed_records": 28,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T11:32:31.817Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 142.479611,
"status": "success",
"token_count": 617
}
|
| 2026-06-13T11:32:31.823Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Update_Sysmon_Rules",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "SYSTEM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "HighestAvailable",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "True",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'Update_Sysmon_Rules' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'SYSTEM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'HighestAvailable' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'True' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:32:31.827Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:32:31.889Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/services.csv"
}
|
| 2026-06-13T11:32:31.892Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__services.csv",
"annotated_rows": 460,
"artifact_key": "services",
"removed_records": 1360,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:34:40.995Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 129.162043,
"status": "success",
"token_count": 1082
}
|
| 2026-06-13T11:34:41.007Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 10,
"skipped": 0,
"total": 10
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "tbbd05",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "LocalSystem",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "b6a1458f396",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mnemosyne",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "PerfMon",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "perfmonsvc64.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Mnemosyne.sys",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "subject_srv.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "imagepath",
"match_status": "exact",
"matched_header": "imagepath"
},
{
"cited": "description",
"match_status": "exact",
"matched_header": "description"
}
],
"warning_count": 8,
"warnings": [
"Note: AI cited column 'tbbd05' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'LocalSystem' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'b6a1458f396' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mnemosyne' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'PerfMon' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'perfmonsvc64.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Mnemosyne.sys' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'subject_srv.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:34:41.010Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:34:41.035Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shimcache.csv"
}
|
| 2026-06-13T11:34:41.038Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__shimcache.csv",
"annotated_rows": 272,
"artifact_key": "shimcache",
"removed_records": 892,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T11:37:50.956Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 189.943358,
"status": "success",
"token_count": 1108
}
|
| 2026-06-13T11:37:50.965Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Autorunsc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "sysmon64.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Install_Sysmon.bat",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "wsmprovhost.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "schtasks.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "wevtutil.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 7,
"warnings": [
"Note: AI cited column 'Autorunsc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'sysmon64.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Install_Sysmon.bat' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'wsmprovhost.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'schtasks.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'wevtutil.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:37:50.969Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:37:51.051Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"mtime_regf",
"program_id",
"digest",
"path",
"hash_path",
"name",
"publisher",
"version",
"bin_file_version",
"product_name",
"product_version",
"link_date",
"bin_product_version",
"size",
"language",
"is_pefile",
"is_oscomponent",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"install_date_arp_last_modified",
"install_date_from_link_file",
"language_code",
"msi_package_code",
"msi_product_code",
"package_full_name",
"type",
"manifest_path",
"os_version_at_install_time",
"program_instance_id",
"registry_key_path",
"root_dir_path",
"source",
"uninstall_string",
"categories",
"discovery_method",
"friendly_name",
"icon",
"is_active",
"is_connected",
"is_machine_container",
"is_networked",
"is_paired",
"manufacturer",
"model_id",
"model_name",
"model_number",
"primary_category",
"state",
"driver_name",
"inf",
"driver_version",
"product",
"wdf_version",
"driver_company",
"driver_package_strong_name",
"service",
"driver_signed",
"driver_is_kernel_mode",
"last_write_time",
"driver_timestamp",
"image_size"
],
"missing_columns": [
"ts",
"last_modified_timestamp",
"created_timestamp",
"company_name",
"file_size"
]
}
|
| 2026-06-13T11:37:51.121Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"path",
"name",
"publisher",
"version",
"product_name",
"digest",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/amcache.csv"
}
|
| 2026-06-13T11:37:51.123Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__amcache.csv",
"annotated_rows": 2,
"artifact_key": "amcache",
"removed_records": 10,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/amcache.csv",
"variant_columns": [
"install_date"
]
}
|
| 2026-06-13T11:39:25.707Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 94.735868,
"status": "success",
"token_count": 538
}
|
| 2026-06-13T11:39:25.715Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "install_date",
"match_status": "exact",
"matched_header": "install_date"
},
{
"cited": "Microsoft.Workflow.Compiler.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "csc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "MavInject32.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "GoogleUpdateComRegisterShell64.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ncpa_listener.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "OSPPREARM.EXE",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited timestamp 2018-08-08 which could not be verified in the source data.",
"Note: AI cited timestamp 2018-09-06 which could not be verified in the source data.",
"Note: AI cited column 'Microsoft.Workflow.Compiler.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'csc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'MavInject32.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'GoogleUpdateComRegisterShell64.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ncpa_listener.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'OSPPREARM.EXE' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:39:25.718Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:39:25.729Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/userassist.csv"
}
|
| 2026-06-13T11:39:25.732Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__userassist.csv",
"annotated_rows": 4,
"artifact_key": "userassist",
"removed_records": 4,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:42:26.181Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 180.459829,
"status": "success",
"token_count": 576
}
|
| 2026-06-13T11:42:26.188Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T11:42:26.191Z |
analysis_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:42:26.198Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__recyclebin.csv",
"artifact_key": "recyclebin",
"projection_columns": [
"ts",
"path",
"deleted_path",
"filesize",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/recyclebin.csv"
}
|
| 2026-06-13T11:42:26.201Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__recyclebin.csv",
"annotated_rows": 0,
"artifact_key": "recyclebin",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/recyclebin.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:43:49.762Z |
analysis_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"duration_seconds": 83.567306,
"status": "success",
"token_count": 748
}
|
| 2026-06-13T11:43:49.767Z |
citation_validation |
{
"artifact_key": "recyclebin",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "username",
"match_status": "exact",
"matched_header": "username"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T11:43:49.770Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:43:49.802Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.history.csv"
}
|
| 2026-06-13T11:43:49.804Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__browser.history.csv",
"annotated_rows": 60,
"artifact_key": "browser.history",
"removed_records": 182,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:45:08.723Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"duration_seconds": 78.950354,
"status": "success",
"token_count": 542
}
|
| 2026-06-13T11:45:08.730Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:45:08.733Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:45:08.741Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.downloads.csv"
}
|
| 2026-06-13T11:45:08.744Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T11:47:15.139Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 126.402409,
"status": "success",
"token_count": 853
}
|
| 2026-06-13T11:47:15.145Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Project_800724_WireTransferInfo.docx",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_start",
"match_status": "exact",
"matched_header": "ts_start"
},
{
"cited": "size",
"match_status": "exact",
"matched_header": "size"
},
{
"cited": "state",
"match_status": "exact",
"matched_header": "state"
},
{
"cited": "perfmonsvc64.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "technicalbird.com",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'Project_800724_WireTransferInfo.docx' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'perfmonsvc64.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'technicalbird.com' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:47:15.148Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:47:15.153Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T11:47:15.156Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__jumplist.automatic_destination.csv",
"annotated_rows": 0,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T11:48:50.977Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 95.825262,
"status": "success",
"token_count": 501
}
|
| 2026-06-13T11:48:50.981Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 3,
"skipped": 0,
"total": 3
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "range_admin",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'range_admin' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:48:50.984Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:48:51.001Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T11:48:51.005Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__jumplist.custom_destination.csv",
"annotated_rows": 4,
"artifact_key": "jumplist.custom_destination",
"removed_records": 11,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T11:50:14.141Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 83.145895,
"status": "success",
"token_count": 417
}
|
| 2026-06-13T11:50:14.147Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "lnk_workdir",
"match_status": "exact",
"matched_header": "lnk_workdir"
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "lnk_device_name",
"match_status": "exact",
"matched_header": "lnk_device_name"
},
{
"cited": "common_path_suffix",
"match_status": "exact",
"matched_header": "common_path_suffix"
},
{
"cited": "GettingStarted.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "application_name",
"match_status": "exact",
"matched_header": "application_name"
},
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "range_admin",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited column 'GettingStarted.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'range_admin' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:50:14.150Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:50:14.159Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shellbags.csv"
}
|
| 2026-06-13T11:50:14.161Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__shellbags.csv",
"annotated_rows": 23,
"artifact_key": "shellbags",
"removed_records": 89,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T11:51:30.589Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 76.436353,
"status": "success",
"token_count": 1448
}
|
| 2026-06-13T11:51:30.594Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 11,
"skipped": 0,
"total": 11
},
"timestamps": {
"checked": 8,
"skipped": 0,
"total": 8
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "ts_mtime",
"match_status": "exact",
"matched_header": "ts_mtime"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'administrator' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:51:30.597Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:51:30.601Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/sam.csv"
}
|
| 2026-06-13T11:51:30.604Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__sam.csv",
"annotated_rows": 3,
"artifact_key": "sam",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T11:57:42.736Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 372.136074,
"status": "success",
"token_count": 704
}
|
| 2026-06-13T11:57:42.741Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 6,
"skipped": 0,
"total": 6
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "range_admin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts",
"match_status": "exact",
"matched_header": "ts"
},
{
"cited": "lastlogin",
"match_status": "exact",
"matched_header": "lastlogin"
},
{
"cited": "lastpasswordset",
"match_status": "exact",
"matched_header": "lastpasswordset"
},
{
"cited": "lastincorrectlogin",
"match_status": "exact",
"matched_header": "lastincorrectlogin"
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'range_admin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:57:42.744Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:57:42.752Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/network_history.csv"
}
|
| 2026-06-13T11:57:42.754Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed_deduplicated/801988de-0f5b-4a11-848b-ad1e6011fb88__network_history.csv",
"annotated_rows": 1,
"artifact_key": "network_history",
"removed_records": 1,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/801988de-0f5b-4a11-848b-ad1e6011fb88/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T11:58:07.873Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 25.121712,
"status": "success",
"token_count": 481
}
|
| 2026-06-13T11:58:07.877Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "shieldbase.lan",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'shieldbase.lan' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:58:07.880Z |
analysis_started |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:58:07.884Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__runkeys.csv",
"artifact_key": "runkeys",
"projection_columns": [
"ts",
"name",
"command",
"key",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/runkeys.csv"
}
|
| 2026-06-13T11:58:07.887Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__runkeys.csv",
"annotated_rows": 1,
"artifact_key": "runkeys",
"removed_records": 1,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/runkeys.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T11:59:33.262Z |
analysis_completed |
{
"artifact_key": "runkeys",
"artifact_name": "Run/RunOnce Keys",
"duration_seconds": 85.378646,
"status": "success",
"token_count": 360
}
|
| 2026-06-13T11:59:33.270Z |
citation_validation |
{
"artifact_key": "runkeys",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 1,
"skipped": 0,
"total": 1
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "HKLM",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "HKCU",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "RunOnce",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "vmtoolsd.exe",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'HKLM' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'HKCU' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'RunOnce' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'vmtoolsd.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T11:59:33.274Z |
analysis_started |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T11:59:33.757Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__tasks.csv",
"artifact_key": "tasks",
"projection_columns": [
"task_path",
"uri",
"date",
"last_run_date",
"author",
"task_name",
"display_name",
"enabled",
"hidden",
"user_id",
"run_as",
"logon_type",
"group_id",
"run_level",
"action_type",
"action",
"command",
"arguments",
"args",
"working_directory",
"start_in",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/tasks.csv"
}
|
| 2026-06-13T11:59:33.760Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__tasks.csv",
"annotated_rows": 16,
"artifact_key": "tasks",
"removed_records": 43,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/tasks.csv",
"variant_columns": [
"date",
"last_run_date",
"arguments"
]
}
|
| 2026-06-13T12:01:20.050Z |
analysis_completed |
{
"artifact_key": "tasks",
"artifact_name": "Scheduled Tasks",
"duration_seconds": 106.774094,
"status": "success",
"token_count": 886
}
|
| 2026-06-13T12:01:20.056Z |
citation_validation |
{
"artifact_key": "tasks",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Update_Sysmon_Rules",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "HighestAvailable",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ProgramData",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "System",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "InteractiveTokenOrPassword",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "vssadmin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ShadowCopyVolume",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "date",
"match_status": "exact",
"matched_header": "date"
},
{
"cited": "last_run_date",
"match_status": "exact",
"matched_header": "last_run_date"
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited column 'Update_Sysmon_Rules' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'HighestAvailable' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ProgramData' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'System' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'InteractiveTokenOrPassword' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'vssadmin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ShadowCopyVolume' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Auto_Update.bat' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:01:20.059Z |
analysis_started |
{
"artifact_key": "services",
"artifact_name": "Services",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:01:20.115Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__services.csv",
"artifact_key": "services",
"projection_columns": [
"ts",
"name",
"displayname",
"description",
"servicedll",
"imagepath",
"imagepath_args",
"objectname",
"start",
"type",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/services.csv"
}
|
| 2026-06-13T12:01:20.119Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__services.csv",
"annotated_rows": 414,
"artifact_key": "services",
"removed_records": 1235,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/services.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T12:04:17.949Z |
analysis_completed |
{
"artifact_key": "services",
"artifact_name": "Services",
"duration_seconds": 177.883458,
"status": "success",
"token_count": 655
}
|
| 2026-06-13T12:04:17.957Z |
citation_validation |
{
"artifact_key": "services",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 1,
"skipped": 0,
"total": 1
},
"timestamps": {
"checked": 2,
"skipped": 0,
"total": 2
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T12:04:17.961Z |
analysis_started |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:04:18.085Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__shimcache.csv",
"artifact_key": "shimcache",
"projection_columns": [
"last_modified",
"index",
"name",
"path",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shimcache.csv"
}
|
| 2026-06-13T12:04:18.088Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__shimcache.csv",
"annotated_rows": 292,
"artifact_key": "shimcache",
"removed_records": 804,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shimcache.csv",
"variant_columns": [
"last_modified",
"index"
]
}
|
| 2026-06-13T12:07:46.737Z |
analysis_completed |
{
"artifact_key": "shimcache",
"artifact_name": "Shimcache",
"duration_seconds": 208.773261,
"status": "success",
"token_count": 1182
}
|
| 2026-06-13T12:07:46.744Z |
citation_validation |
{
"artifact_key": "shimcache",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 6,
"skipped": 0,
"total": 6
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"warning_count": 1,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data."
]
}
|
| 2026-06-13T12:07:46.749Z |
analysis_started |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:07:46.792Z |
artifact_ai_projection_warning |
{
"artifact_key": "amcache",
"available_columns": [
"hostname",
"domain",
"last_modified_timestamp",
"last_modified_store_timestamp",
"link_timestamp",
"created_timestamp",
"mtime_regf",
"reference",
"path",
"language_code",
"digest",
"program_id",
"pe_header_checksum",
"pe_size_of_image",
"product_name",
"company_name",
"file_size",
"_source",
"_classification",
"_generated",
"_version",
"install_date",
"name",
"version",
"publisher",
"entry_type",
"uninstall_key",
"product_code",
"package_code",
"msi_package_code",
"msi_package_code2"
],
"missing_columns": [
"ts",
"size",
"driver_name",
"service",
"driver_signed",
"is_pefile",
"is_oscomponent"
]
}
|
| 2026-06-13T12:07:46.827Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__amcache.csv",
"artifact_key": "amcache",
"projection_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp",
"path",
"name",
"publisher",
"version",
"product_name",
"company_name",
"digest",
"file_size",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/amcache.csv"
}
|
| 2026-06-13T12:07:46.830Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__amcache.csv",
"annotated_rows": 28,
"artifact_key": "amcache",
"removed_records": 29,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/amcache.csv",
"variant_columns": [
"install_date",
"last_modified_timestamp",
"created_timestamp"
]
}
|
| 2026-06-13T12:09:20.421Z |
analysis_completed |
{
"artifact_key": "amcache",
"artifact_name": "Amcache",
"duration_seconds": 93.667928,
"status": "success",
"token_count": 1328
}
|
| 2026-06-13T12:09:20.434Z |
citation_validation |
{
"artifact_key": "amcache",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 4,
"skipped": 0,
"total": 4
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "PSEXESVC.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "created_timestamp",
"match_status": "exact",
"matched_header": "created_timestamp"
},
{
"cited": "last_modified_timestamp",
"match_status": "exact",
"matched_header": "last_modified_timestamp"
},
{
"cited": "install_date",
"match_status": "exact",
"matched_header": "install_date"
}
],
"warning_count": 1,
"warnings": [
"Note: AI cited column 'PSEXESVC.exe' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:09:20.437Z |
analysis_started |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:09:20.444Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__userassist.csv",
"artifact_key": "userassist",
"projection_columns": [
"ts",
"path",
"number_of_executions",
"application_focus_count",
"application_focus_duration",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/userassist.csv"
}
|
| 2026-06-13T12:09:20.448Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__userassist.csv",
"annotated_rows": 3,
"artifact_key": "userassist",
"removed_records": 4,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/userassist.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T12:12:19.707Z |
analysis_completed |
{
"artifact_key": "userassist",
"artifact_name": "UserAssist",
"duration_seconds": 179.266936,
"status": "success",
"token_count": 1139
}
|
| 2026-06-13T12:12:19.713Z |
citation_validation |
{
"artifact_key": "userassist",
"citation_counts": {
"columns": {
"checked": 8,
"skipped": 0,
"total": 8
},
"row_refs": {
"checked": 6,
"skipped": 0,
"total": 6
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "application_focus_duration",
"match_status": "exact",
"matched_header": "application_focus_duration"
},
{
"cited": "number_of_executions",
"match_status": "exact",
"matched_header": "number_of_executions"
},
{
"cited": "application_focus_count",
"match_status": "exact",
"matched_header": "application_focus_count"
},
{
"cited": "powershell.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ServerManager.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "mmc.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "regsvr32",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 5,
"warnings": [
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'powershell.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'ServerManager.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'mmc.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'regsvr32' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:12:19.716Z |
analysis_started |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:12:19.728Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__recyclebin.csv",
"artifact_key": "recyclebin",
"projection_columns": [
"ts",
"path",
"deleted_path",
"filesize",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/recyclebin.csv"
}
|
| 2026-06-13T12:12:19.731Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__recyclebin.csv",
"annotated_rows": 0,
"artifact_key": "recyclebin",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/recyclebin.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T12:13:01.470Z |
analysis_completed |
{
"artifact_key": "recyclebin",
"artifact_name": "Recycle Bin",
"duration_seconds": 41.743525,
"status": "success",
"token_count": 745
}
|
| 2026-06-13T12:13:01.477Z |
citation_validation |
{
"artifact_key": "recyclebin",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 3,
"skipped": 0,
"total": 3
}
},
"citation_validation": "checked",
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T12:13:01.481Z |
analysis_started |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:13:01.489Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__browser.history.csv",
"artifact_key": "browser.history",
"projection_columns": [
"ts",
"browser",
"url",
"title",
"host",
"visit_type",
"visit_count",
"typed",
"hidden",
"from_url",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.history.csv"
}
|
| 2026-06-13T12:13:01.492Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__browser.history.csv",
"annotated_rows": 0,
"artifact_key": "browser.history",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.history.csv",
"variant_columns": [
"ts"
]
}
|
| 2026-06-13T12:18:25.142Z |
analysis_completed |
{
"artifact_key": "browser.history",
"artifact_name": "Browser History",
"duration_seconds": 323.657128,
"status": "success",
"token_count": 1769
}
|
| 2026-06-13T12:18:25.148Z |
citation_validation |
{
"artifact_key": "browser.history",
"citation_counts": {
"columns": {
"checked": 7,
"skipped": 0,
"total": 7
},
"row_refs": {
"checked": 17,
"skipped": 0,
"total": 17
},
"timestamps": {
"checked": 19,
"skipped": 0,
"total": 19
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "team_admin",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nfury",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "from_url",
"match_status": "exact",
"matched_header": "from_url"
},
{
"cited": "host",
"match_status": "exact",
"matched_header": "host"
},
{
"cited": "visit_type",
"match_status": "exact",
"matched_header": "visit_type"
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'team_admin' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:18:25.152Z |
analysis_started |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:18:25.157Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__browser.downloads.csv",
"artifact_key": "browser.downloads",
"projection_columns": [
"ts_start",
"ts_end",
"browser",
"path",
"url",
"size",
"state",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.downloads.csv"
}
|
| 2026-06-13T12:18:25.160Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__browser.downloads.csv",
"annotated_rows": 0,
"artifact_key": "browser.downloads",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/browser.downloads.csv",
"variant_columns": [
"ts_start",
"ts_end"
]
}
|
| 2026-06-13T12:20:55.124Z |
analysis_completed |
{
"artifact_key": "browser.downloads",
"artifact_name": "Browser Downloads",
"duration_seconds": 149.968771,
"status": "success",
"token_count": 630
}
|
| 2026-06-13T12:20:55.128Z |
citation_validation |
{
"artifact_key": "browser.downloads",
"citation_counts": {
"columns": {
"checked": 6,
"skipped": 0,
"total": 6
},
"row_refs": {
"checked": 3,
"skipped": 0,
"total": 3
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "nxlog",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_end",
"match_status": "exact",
"matched_header": "ts_end"
},
{
"cited": "nxlog.conf",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_start",
"match_status": "exact",
"matched_header": "ts_start"
},
{
"cited": "size",
"match_status": "exact",
"matched_header": "size"
},
{
"cited": "state",
"match_status": "exact",
"matched_header": "state"
}
],
"warning_count": 3,
"warnings": [
"Note: AI cited timestamp 2026-06-13 which could not be verified in the source data.",
"Note: AI cited column 'nxlog' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nxlog.conf' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:20:55.130Z |
analysis_started |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:20:55.137Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__jumplist.automatic_destination.csv",
"artifact_key": "jumplist.automatic_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.automatic_destination.csv"
}
|
| 2026-06-13T12:20:55.140Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__jumplist.automatic_destination.csv",
"annotated_rows": 1,
"artifact_key": "jumplist.automatic_destination",
"removed_records": 3,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.automatic_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T12:23:39.959Z |
analysis_completed |
{
"artifact_key": "jumplist.automatic_destination",
"artifact_name": "Automatic Jump Lists",
"duration_seconds": 164.825226,
"status": "success",
"token_count": 1397
}
|
| 2026-06-13T12:23:39.966Z |
citation_validation |
{
"artifact_key": "jumplist.automatic_destination",
"citation_counts": {
"columns": {
"checked": 11,
"skipped": 0,
"total": 11
},
"row_refs": {
"checked": 9,
"skipped": 0,
"total": 9
},
"timestamps": {
"checked": 7,
"skipped": 0,
"total": 7
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_net_name",
"match_status": "exact",
"matched_header": "lnk_net_name"
},
{
"cited": "u_ex180625.log",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "u_ex180803.log",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "u_ex180807.log",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "lnk_atime",
"match_status": "exact",
"matched_header": "lnk_atime"
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "nxlog.conf",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "u_ex180508.log",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "PowerShell_Examples_v4.pdf",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 9,
"warnings": [
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'u_ex180625.log' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'u_ex180803.log' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'u_ex180807.log' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nxlog.conf' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'u_ex180508.log' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'PowerShell_Examples_v4.pdf' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'nfury' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:23:39.970Z |
analysis_started |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:23:39.974Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__jumplist.custom_destination.csv",
"artifact_key": "jumplist.custom_destination",
"projection_columns": [
"type",
"application_name",
"lnk_name",
"lnk_full_path",
"lnk_arguments",
"local_base_path",
"common_path_suffix",
"lnk_path",
"lnk_workdir",
"lnk_net_name",
"lnk_device_name",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime",
"username",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.custom_destination.csv"
}
|
| 2026-06-13T12:23:39.977Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__jumplist.custom_destination.csv",
"annotated_rows": 5,
"artifact_key": "jumplist.custom_destination",
"removed_records": 6,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/jumplist.custom_destination.csv",
"variant_columns": [
"lnk_arguments",
"lnk_mtime",
"lnk_atime",
"lnk_ctime",
"target_mtime",
"target_atime",
"target_ctime"
]
}
|
| 2026-06-13T12:24:17.352Z |
analysis_completed |
{
"artifact_key": "jumplist.custom_destination",
"artifact_name": "Custom Jump Lists",
"duration_seconds": 37.379922,
"status": "success",
"token_count": 591
}
|
| 2026-06-13T12:24:17.357Z |
citation_validation |
{
"artifact_key": "jumplist.custom_destination",
"citation_counts": {
"columns": {
"checked": 4,
"skipped": 0,
"total": 4
},
"row_refs": {
"checked": 0,
"skipped": 0,
"total": 0
},
"timestamps": {
"checked": 4,
"skipped": 0,
"total": 4
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "powershell_ise.exe",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Administrator",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "rsydow",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "DestList",
"match_status": "unverifiable",
"matched_header": ""
}
],
"warning_count": 4,
"warnings": [
"Note: AI cited column 'powershell_ise.exe' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Administrator' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'rsydow' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'DestList' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:24:17.360Z |
analysis_started |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:24:17.373Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__shellbags.csv",
"artifact_key": "shellbags",
"projection_columns": [
"ts_mtime",
"ts_atime",
"ts_btime",
"type",
"path",
"username"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shellbags.csv"
}
|
| 2026-06-13T12:24:17.376Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__shellbags.csv",
"annotated_rows": 0,
"artifact_key": "shellbags",
"removed_records": 0,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/shellbags.csv",
"variant_columns": [
"ts_mtime",
"ts_atime",
"ts_btime"
]
}
|
| 2026-06-13T12:26:32.308Z |
analysis_completed |
{
"artifact_key": "shellbags",
"artifact_name": "Shellbags",
"duration_seconds": 134.939905,
"status": "success",
"token_count": 1660
}
|
| 2026-06-13T12:26:32.314Z |
citation_validation |
{
"artifact_key": "shellbags",
"citation_counts": {
"columns": {
"checked": 5,
"skipped": 0,
"total": 5
},
"row_refs": {
"checked": 19,
"skipped": 0,
"total": 19
},
"timestamps": {
"checked": 15,
"skipped": 0,
"total": 15
}
},
"citation_validation": "warnings_found",
"column_match_results": [
{
"cited": "Uses",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "Users",
"match_status": "unverifiable",
"matched_header": ""
},
{
"cited": "ts_atime",
"match_status": "exact",
"matched_header": "ts_atime"
},
{
"cited": "ts_btime",
"match_status": "exact",
"matched_header": "ts_btime"
},
{
"cited": "ts_mtime",
"match_status": "exact",
"matched_header": "ts_mtime"
}
],
"warning_count": 2,
"warnings": [
"Note: AI cited column 'Uses' which does not match any column in the source data; citation is unverifiable.",
"Note: AI cited column 'Users' which does not match any column in the source data; citation is unverifiable."
]
}
|
| 2026-06-13T12:26:32.322Z |
analysis_started |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:26:32.327Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__sam.csv",
"artifact_key": "sam",
"projection_columns": [
"ts",
"rid",
"username",
"fullname",
"admincomment",
"usercomment",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin",
"failedlogins",
"logins",
"flags",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/sam.csv"
}
|
| 2026-06-13T12:26:32.330Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__sam.csv",
"annotated_rows": 6,
"artifact_key": "sam",
"removed_records": 6,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/sam.csv",
"variant_columns": [
"ts",
"lastlogin",
"lastpasswordset",
"lastincorrectlogin"
]
}
|
| 2026-06-13T12:33:09.868Z |
analysis_completed |
{
"artifact_key": "sam",
"artifact_name": "SAM Users",
"duration_seconds": 397.542315,
"status": "success",
"token_count": 1049
}
|
| 2026-06-13T12:33:09.874Z |
citation_validation |
{
"artifact_key": "sam",
"citation_counts": {
"columns": {
"checked": 1,
"skipped": 0,
"total": 1
},
"row_refs": {
"checked": 5,
"skipped": 0,
"total": 5
},
"timestamps": {
"checked": 8,
"skipped": 0,
"total": 8
}
},
"citation_validation": "checked",
"column_match_results": [
{
"cited": "flags",
"match_status": "exact",
"matched_header": "flags"
}
],
"warning_count": 0,
"warnings": []
}
|
| 2026-06-13T12:33:09.877Z |
analysis_started |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:33:09.880Z |
artifact_ai_projection |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__network_history.csv",
"artifact_key": "network_history",
"projection_columns": [
"created",
"last_connected",
"profile_name",
"description",
"dns_suffix",
"first_network",
"default_gateway_mac",
"signature",
"_dedup_comment"
],
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/network_history.csv"
}
|
| 2026-06-13T12:33:09.883Z |
artifact_deduplicated |
{
"analysis_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed_deduplicated/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e__network_history.csv",
"annotated_rows": 2,
"artifact_key": "network_history",
"removed_records": 2,
"source_csv": "/home/sansforensics/Desktop/AIFT/cases/3bc3102d-8474-4ee5-8b85-9c4ae7ec0b96/images/cb5dd4d0-e9da-4b7f-abd5-a1652671f61e/parsed/network_history.csv",
"variant_columns": [
"created",
"last_connected",
"first_network"
]
}
|
| 2026-06-13T12:35:07.096Z |
analysis_completed |
{
"artifact_key": "network_history",
"artifact_name": "Network History",
"duration_seconds": 117.216937,
"status": "success",
"token_count": 542
}
|
| 2026-06-13T12:35:07.100Z |
citation_validation |
{
"artifact_key": "network_history",
"citation_counts": {
"columns": {
"checked": 0,
"skipped": 0,
"total": 0
},
"row_refs": {
"checked": 2,
"skipped": 0,
"total": 2
},
"timestamps": {
"checked": 5,
"skipped": 0,
"total": 5
}
},
"citation_validation": "warnings_found",
"warning_count": 1,
"warnings": [
"Note: AI cited timestamp 2018-05-25T15:26:00Z which could not be verified in the source data."
]
}
|
| 2026-06-13T12:35:07.103Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:37:13.817Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 126.70952,
"status": "success",
"token_count": 3564
}
|
| 2026-06-13T12:37:13.820Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:41:59.100Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 285.276581,
"status": "success",
"token_count": 3075
}
|
| 2026-06-13T12:41:59.105Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:47:19.666Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 320.557538,
"status": "success",
"token_count": 3619
}
|
| 2026-06-13T12:47:19.669Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:50:30.643Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 190.970333,
"status": "success",
"token_count": 2974
}
|
| 2026-06-13T12:50:30.646Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:55:28.481Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 297.830313,
"status": "success",
"token_count": 3465
}
|
| 2026-06-13T12:55:28.485Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T12:56:56.428Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 87.939994,
"status": "success",
"token_count": 2342
}
|
| 2026-06-13T12:56:56.436Z |
analysis_started |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T13:00:26.462Z |
analysis_completed |
{
"artifact_key": "cross_artifact_summary",
"artifact_name": "Cross-Artifact Summary",
"duration_seconds": 210.023494,
"status": "success",
"token_count": 2724
}
|
| 2026-06-13T13:00:26.470Z |
analysis_started |
{
"artifact_key": "cross_image_correlation",
"artifact_name": "Cross-Image Correlation",
"image_count": 7,
"model": "kimi-k2.6",
"provider": "kimi"
}
|
| 2026-06-13T13:08:56.964Z |
analysis_completed |
{
"artifact_key": "cross_image_correlation",
"artifact_name": "Cross-Image Correlation",
"duration_seconds": 510.490155,
"status": "success",
"token_count": 5370
}
|
| 2026-06-13T13:08:56.979Z |
hash_verification |
{
"computed_sha256": "N/A (skipped); N/A (skipped); N/A (skipped); N/A (skipped); N/A (skipped); N/A (skipped); N/A (skipped)",
"expected_sha256": "N/A (skipped)",
"image_count": 7,
"match": true,
"multi_image": true,
"skipped": true,
"verification_status": "SKIPPED",
"verified_files": [
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-dc-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-dc-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-file-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-file-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-rd-01-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-rd-01-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-rd-02-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-rd-02-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-wkstn-01-c-drive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-wkstn-01-c-drive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "base-wkstn-05-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/base-wkstn-05-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
},
{
"computed": "N/A (skipped)",
"expected": "N/A (skipped)",
"filename": "dmz-ftp-cdrive.E01",
"match": null,
"path": "/mnt/data/Evidence/dmz-ftp-cdrive.E01",
"skipped": true,
"status": "SKIPPED"
}
]
}
|