Risk AssessmentCritical riskConsensus useful

AI Intrusion Timeline Reconstruction & Attribution Analysis Playbook

Your SOC has isolated a suspected APT intrusion on a federal contractor network. Initial indicators suggest a 90-day dwell time, lateral movement through three network segments, and exfiltration of approximately 40GB via encrypted channel to two external IPs. You have SIEM logs, EDR telemetry, and a partial memory capture from the compromised endpoint.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: Your SOC has isolated a suspected APT intrusion on a federal contractor network.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Intrusion Timeline Reconstruction & Attribution Analysis".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • SIEM log extract (90-day window, JSON) - EDR telemetry for the compromised endpoint - Partial memory capture (strings extract) - OSINT report on the two external IPs

Attachments: Documents (Documents)

The Prompt

You are a federal cyber incident responder reconstructing an APT intrusion timeline for law enforcement referral and remediation planning.  I am attaching: - SIEM log extract (90-day window, JSON) - EDR telemetry for the compromised endpoint - Partial memory capture (strings extract) - OSINT report on the two external IPs

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Reconstruct the full intrusion timeline from initial access through exfiltration — identifying each stage of the MITRE ATT&CK kill chain with supporting log and telemetry evidence.
2. Identify all lateral movement paths across the three network segments, including credential artifacts, tool signatures, and timestamps that establish sequence.
3. Assess the exfiltration volume and channel — identify the protocol, destination, and timing pattern, and estimate the categories of data likely included based on file access logs.
4. Cross-reference the two external IPs against the OSINT report and assess whether the TTPs are consistent with a known threat actor group.
5. Produce a law enforcement referral summary and a remediation priority list ranked by persistence mechanism severity.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Multi-model consensus ATT&CK stage mapping with evidence citations
  • Lateral movement graph with credential reuse flags
  • Exfiltration volume estimate and data category risk assessment
  • Threat actor attribution confidence scoring across models
  • Law enforcement referral summary and ranked remediation list

Review before you act

  • Validate this output against source files before relying on it: Reconstruct the full intrusion timeline from initial access through exfiltration — identifying each stage of the MITRE ATT&CK kill chain with supporting log and telemetry evidence.
  • Validate this output against source files before relying on it: Identify all lateral movement paths across the three network segments, including credential artifacts, tool signatures, and timestamps that establish sequence.
  • Validate this output against source files before relying on it: Assess the exfiltration volume and channel — identify the protocol, destination, and timing pattern, and estimate the categories of data likely included based on file access logs.
  • Validate this output against source files before relying on it: Cross-reference the two external IPs against the OSINT report and assess whether the TTPs are consistent with a known threat actor group.
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Intrusion Timeline Reconstruction & Attribution Analysis, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus att&ck stage mapping with evidence citations; lateral movement graph with credential reuse flags; exfiltration volume estimate and data category risk assessment; threat actor attribution confidence scoring across models. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.

US FederalCybersecurity Threat IntelRisk AssessmentCriticalDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.