CIPHER INTELLIGENCE BRIEFVOL. 04 / ISSUE 02 / FEB 2026
DISTRIBUTION: RESTRICTED
UNCLASSIFIED
INCIDENT — OPERATION SILENT LEDGER

Every satisfactory breach started with a satisfactory audit.

FEBRUARY 2026·OPERATION SILENT LEDGER·UNCLASSIFIED

A supply chain compromise that persisted for 214 days inside a Fortune 500 insurance carrier — dissected lateral movement by lateral movement, until the one misconfigured service account that opened every door.

For authorized security practitioners only — not for redistributionCIP-2026-0402
EXHIBIT 01INITIAL ACCESS VECTOR
MITRE ATT&CK — SUPPLY CHAIN COMPROMISE

The Build Pipeline
as the Attack Surface

Vendor VPNEndpointDMZFirewallBuildServerArtifactRepositoryProductionDeploy Pipelinesvc_build_01[OVERPRIVILEGED]

FIG. 1.1 — Attacker leveraged a trusted vendor VPN tunnel to reach the CI/CD build server. The svc_build_01 service account held write access to 23 production repositories it had no legitimate reason to touch.

ANALYST NOTES
D+0

VPN cert issued to third-party auditor 18 months prior — never revoked after engagement closed.

D+3

First lateral move: build server to artifact repository. No EDR coverage on build nodes.

← pivot point
D+12

svc_build_01 makes first anomalous API call outside its declared service boundary.

D+19

Malicious package injected into internal npm mirror. Hash verification disabled.

← pivot point

"The build server was invisible to the SOC. It had no agent, no log forwarding, and a service account with domain admin equivalent."

— INCIDENT RESPONDER, WEEK 1 DEBRIEF
EXHIBIT 02PRIVILEGE ESCALATION & LATERAL MOVEMENT
WINDOWS SECURITY EVENT LOG — PROD-DC-01

The Fourteen
Minutes That
Owned the Domain

Between 03:17 and 03:31 UTC, the attacker moved from a build server service account to full domain compromise. The SIEM fired one low-severity alert. No analyst triaged it until 11 days later.

Dwell before DC access3 days
from initial access
Time to domain admin14 min
once on build server
SIEM alerts fired1
severity: low — not triaged
Accounts compromised847
after DCSync

"DCSync from a non-DC host is textbook. The detection rule existed. The threshold was set to suppress low-volume alerts."

— THREAT INTEL ANALYST NOTE
Security.evtx — Event ID 4662, 4624, 4688
2025-09-14 03:17:42 [INFO] svc_build_01 authenticated to ldap://corp.internalsilentledger.net
2025-09-14 03:17:43 [INFO] Group membership query: CN=Domain Admins,DC=corp
2025-09-14 03:17:44 [WARN] Unusual LDAP query from non-interactive service account
2025-09-14 03:18:01 [INFO] svc_build_01 executed: net localgroup administrators
2025-09-14 03:18:09 [INFO] WMI remote execution: \\PROD-DC-01\root\cimv2
2025-09-14 03:18:14 [INFO] New scheduled task created: "WindowsDefenderUpdate" on PROD-DC-01
2025-09-14 03:18:22 [INFO] svc_build_01 accessed SYSVOL share: \\corp\SYSVOL\policies\
2025-09-14 03:19:01 [INFO] DCSync operation detected: DRSUAPI replication from non-DC host

* LOG EXCERPT — SANITIZED FOR PUBLICATION. TIMESTAMPS UTC. HOSTNAMES ANONYMIZED.

EXHIBIT 03DWELL TIME & EXFILTRATION MAP
214 DAYS UNDETECTED43.0 GB EXFILTRATED

214 Days.
Seven Months of
Silence.

The attacker operated patiently — moving in bursts, then going dormant for weeks. The exfiltration was timed to coincide with legitimate high-volume backup windows.

Total dwell time214 days
Data exfiltrated43.0 GB
Exfil methodDoH tunnel
C2 infrastructure3 providers
Records exposed1.2M PII

"DNS-over-HTTPS rendered their exfiltration invisible to every network sensor they had deployed."

— FORENSIC REPORT, SECTION 4.3
Incident Timeline — Days from Initial Access
D+0
Initial Access
D+3
Lateral Movement
D+19
Package Poisoning
D+47
Staging Exfil
D+89
First Exfil Burst
D+156
Second Exfil Burst
D+214
Detection
D+3Lateral Movement

WMI remote execution to PROD-DC-01. Domain admin achieved in 14 minutes.

D+89First Exfil Burst

14.3 GB transferred over 6 hours. DNS-over-HTTPS tunneling to C2 infrastructure.

D+156Second Exfil Burst

28.7 GB — policyholder PII, actuarial models, M&A documents.

D+214Detection

DLP alert on anomalous DNS query volume. Incident response team engaged.

ARCHIVEPAST BRIEFINGS — REDACTED PREVIEWS
FULL ACCESS REQUIRES SUBSCRIPTION

Four years of incident post-mortems.
Every one goes to the packet level.

VOL. 04 / ISSUE 01JAN 2026

Operation Copper Thread

Nation-State / Critical Infrastructure

A water treatment facility in the Mid-Atlantic region. The OT network was assumed air-gapped. It was not. The historian note: the jump host had been installed "temporarily" in 2019.

DWELL312 days
VECTORPhishing → OT pivot
The specific CVE exploited in the historian firmware remains under coordinated disclosure.
SCADA vendor name withheld at FBI request.
VOL. 03 / ISSUE 06DEC 2025

The Ledger Worm

Financial / Ransomware-as-a-Service

A regional bank's core banking system encrypted on a Tuesday morning. The ransomware had been dormant for 61 days after initial deployment, waiting for fiscal quarter end.

DWELL61 days
VECTORRDP brute force → domain pivot
Ransom amount and payment decision redacted per source agreement.
RESTRICTED

AVAILABLE TO SUBSCRIBERS

VOL. 03 / ISSUE 03SEP 2025

Phantom Enrollment

Healthcare / Identity Fraud

An insurance carrier's provider portal allowed unauthenticated IDOR traversal. 2.1M patient records extracted over 8 months through what appeared to be normal API traffic.

DWELL247 days
VECTORIDOR → API enumeration
Carrier name under active litigation — full disclosure pending.
CVE assigned but not yet public.

47 issues in the archive. Every one traces a breach from first packet to final post-mortem.

CIPHERMONTHLY INTELLIGENCE BRIEFING
SUBSCRIPTION — NO COST
Read the Full Briefing

The briefing your board needs you to have read.

One incident, dissected to the packet level — every issue.

Written for practitioners who've already sat through the vendor pitch.

Lateral movement, dwell time, and the human error that opened the door.

Forensic diagrams, annotated log excerpts, and real timeline data.

"I forwarded the September issue to my entire threat intel team. It answered questions about the Copper Thread campaign that the vendor reports never touched."

MK
Marcus K. — CISO, Financial Services

Receive the Briefing

Monthly. Free. No vendor content. No sponsored sections. Unsubscribe with one click.

YOUR EMAIL IS NOT SOLD. NOT SHARED.
NOT USED TO PITCH YOU SOFTWARE.