Session
demo-critical-exfil
No notes yet. Leave the first one so the next reviewer inherits the context.
| Path | Reason | Op | Process | When |
|---|---|---|---|---|
C:\Users\ci\.aws\credentials
|
aws credentials | open |
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe
pid 9900
|
2026-04-22T20:14:25.406495887Z |
C:\Users\ci\.ssh\id_rsa
|
ssh keys | open |
C:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exe
pid 9900
|
2026-04-22T20:14:26.406495887Z |
| Host | Reason |
|---|---|
pastebin.com |
paste site |
| Command | Reason | Process | When |
|---|---|---|---|
powershell -EncodedCommand JABjACAAPQAgACIASABlAGwAbABvACIAOwAgACQAYwA=
Decoded payload
|
powershell encoded command |
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
pid 9101
|
2026-04-22T20:14:39.406495887Z |
sc.exe create SvcUpdater binPath= "C:\Users\ci\AppData\Local\Temp\svc-updater.exe" start= auto
|
service install |
C:\Windows\System32\sc.exe
pid 9102
|
2026-04-22T20:14:41.406495887Z |
| Key | Value | Op | Reason | Process | When |
|---|---|---|---|---|---|
\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run
|
SvcUpdater |
set | run key | pid 9100 | 2026-04-22T20:14:33.406495887Z |
| Image | Reason | Loaded by | When |
|---|---|---|---|
C:\Users\ci\AppData\Local\Temp\svc-updater.exe
|
session-written |
C:\Windows\System32\cmd.exe
pid 9100
|
2026-04-22T20:14:31.406495887Z |