Skip to main content

In 10 Minutes, REMI Generates a Fully Automated Airport SITREP That Defines the Size and Scope of the Adversarial Cyber Attack

Airport cyber incident investigations often involve records scattered across enterprise networks, airport operations systems, access-control platforms, badge records, baggage systems, flight-information displays, gate systems, vendor maintenance access, camera metadata, facility-control systems, security tools, and operational event records. REMI AI brings those mixed sources together and generates a cyber SITREP that explains the situation in plain English. It identifies what happened, how access was achieved, which systems were touched, whether airport operations or facility-control activity occurred, where suspicious files or AI-spawned tools appeared, what remains unproven, and which records support the sequence.

Instead of manually comparing SIEM alerts, endpoint logs, VPN activity, vendor-access records, engineering workstation events, HMI logs, control-configuration changes, historian records, and portable-media activity one source at a time, REMI analyzes the full evidence set together. REMI is designed to understand advanced AI-enabled disruption patterns, including state-actor style reconnaissance, delayed execution, lateral movement, tool spawning, configuration probing, and activity that may not look dangerous until it is reconstructed across systems and time.

Benefits Of a Cyber SitRep

✓ Fast airport operating picture
Shows what happened across airport IT, security, access-control, baggage, gate, ramp, vendor, and flight-support records.
✓ Where the activity spread
Identifies which networks, terminals, workstations, systems, zones, vendors, and operational platforms were touched.
✓ Malware and access path review
Connects remote access, endpoint activity, firewall traffic, identity records, scripts, files, and suspicious system behavior.
✓ Airport operations impact
Shows whether activity reached baggage systems, gate support, ramp operations, display systems, restricted areas, or flight-support processes.
✓ Known vs. unresolved
Separates confirmed findings from open questions, including missing logs, unclear account ownership, vendor activity, or unconfirmed system impact.
✓ Records to collect next
Names the additional source records needed, including VPN logs, badge records, camera metadata, endpoint telemetry, firewall flows, and vendor work orders.
✓ Priority responder actions
Lists what to isolate, preserve, review, sandbox, remove, verify, or escalate first so airport teams can act immediately.
✓ Better handoff between teams
Gives airport security, IT, operations, vendors, and leadership the same case picture without waiting days for manual reconstruction.

REMI analyzes tower-system and airport IT event logs to identify flagged behaviors, affected systems, and source records tied to advanced cyber attacks.

REMI ingests airport IT, security, vendor, and operations records from multiple vendors and platforms at the same time, including endpoint activity, VPN and identity records, firewall logs, access-control logs, badge activity, camera metadata, gate system activity, ramp-support records, baggage system logs, flight-support records, vendor access, and maintenance records. REMI aggregates those mixed-source records into one AI-ready investigation dataset, then cleans, normalizes, de-duplicates, timestamps, and organizes them so the full airport incident can be reviewed across systems instead of one tool at a time.

By aggregating airport IT and operations records together, REMI helps investigators see whether a cyber incident stayed inside enterprise systems or moved toward terminal operations, gate support, ramp operations, baggage areas, access-controlled zones, restricted facilities, or flight-support processes. It reconstructs what happened, which systems were touched, what changed, which records support the findings, and what records are still needed to close the gaps.

IT Event Logs

✓
Endpoint and EDR logsProcess activity, files, scripts, malware paths, hashes, and device telemetry.
✓
Server and Windows event logsLogons, services, scheduled tasks, PowerShell, registry, and system events.
✓
Identity and access logsUsers, admin accounts, MFA, SSO, tokens, groups, permissions, and sign-ins.
✓
Firewall and network logsInternal traffic, external IPs, ports, DNS, VPN sessions, and lateral movement paths.
✓
Cloud platform logsAzure, AWS, Google Cloud, SaaS activity, storage access, app credentials, and API events.

Ingestion Output

✓ One normalized investigation dataset
Mixed airport records from different vendors, platforms, formats, and schemas are cleaned, aligned, and organized for AI analysis.
✓ Cross-source event structure
Accounts, devices, IPs, timestamps, systems, badge events, tower-adjacent records, baggage events, gate activity, and vendor records are mapped into a common structure.
✓ AI-ready case data for detection and correlation
The aggregated source records are prepared so REMI can identify flagged behaviors, connect related events, and reconstruct the incident path.

REMI identifies different categories of flagged behaviors and attack patterns associated with state actor cyber operations

REMI is trained to recognize advanced adversarial cyber behaviors in both enterprise incident response and water treatment environments.

REMI connects related activity across airport IT, identity, access control, camera metadata, vendor, firewall, endpoint, gate, ramp, baggage, and flight-support records so responders can see how separate events fit together. One system may show vendor access, another may show a workstation session, another may show badge activity, and another may show operational disruption. REMI correlates those records by time, account, device, IP address, badge ID, location, file, process, session, and repeated behavior.

IT Behavioral Detection

✓ Unusual sign-ins
New locations, impossible travel, off-hours access, failed MFA, token reuse, or abnormal login patterns.
✓ Endpoint activity
Unexpected processes, scripts, malware paths, dropped files, persistence, hashes, and device telemetry.
✓ Network movement
Internal traffic, external callbacks, DNS activity, VPN sessions, ports, protocols, and lateral movement paths.
✓ Privilege and access changes
Admin role changes, permission updates, group membership changes, service accounts, and token activity.
✓ Cloud and SaaS activity
Storage access, mailbox activity, API calls, app credentials, file sharing, downloads, and data movement.
✓ Data exfiltration indicators
Large transfers, unusual downloads, external sharing, archive creation, USB activity, and abnormal outbound traffic.
✓ Insider threat indicators
After-hours access, unusual file access, policy bypasses, removable media use, deleted logs, or access outside job role.
✓ Inside assistance indicators
Shared credentials, approved access used at abnormal times, suspicious vendor coordination, unlocked remote tools, or access enabled before activity.

Behaviors & Pattern Categories

✓Remote access behavior
VPN sessions, jump hosts, RDP/SSH access, vendor maintenance accounts, new source IPs, and off-hours access into airport networks.
✓Identity and account anomalies
MFA activity, token use, privileged accounts, shared accounts, failed access, role changes, PAM activity, and account behavior outside normal patterns.
✓Airport network movement
Traffic moving between enterprise systems, operations desktops, vendor access paths, airport support networks, and operational platforms.
✓Endpoint and workstation activity
Process chains, scripts, PowerShell, registry changes, scheduled tasks, services, dropped files, and activity on airport operations workstations.
✓AI-spawned tools and malware controllers
Generated scripts, staged binaries, beaconing tools, command channels, loaders, rootkits, and malware paths appearing across systems.
✓Firewall, DNS, proxy, and web traffic
Outbound callbacks, DNS tunneling, DoH activity, fast-flux domains, proxy traffic, WAF events, unusual ports, and suspicious external connections.
✓Data staging and archive creation
Compression activity, staged folders, bulk file movement, large exports, temporary archives, and transfer preparation before removal or exfiltration.
✓Mailbox, cloud, and SaaS activity
Email access, cloud sync, eDiscovery exports, OAuth activity, shared storage access, app credentials, and unusual SaaS activity.
✓Database and application access
Bulk queries, dumps, high-volume reads, application exports, passenger-service records, operational databases, and airport application logs.
✓Baggage and display system activity
BHS events, FIDS/BIDS updates, carousel changes, gate display records, route/display mismatches, and abnormal operational screen changes.
✓Gate, terminal, and common-use systems
Boarding systems, kiosks, shared workstations, common-use terminals, check-in systems, passenger-processing tools, and terminal operations records.
✓Access-control and restricted-area activity
Badge activity, door events, secure-zone access, after-hours entry, access denials, camera metadata, and restricted-area movement records.
✓Tower and airfield operations records
Tower event notes, system-status records, outage timing, runway/taxiway support events, communications timing, and operational disruption records.
✓Flight-data and timing anomalies
ADS-B, MLAT, ASTERIX-style feeds, GPS/PTP/NTP timing offsets, aircraft position records, altitude/speed data, and sensor-timing mismatches.
✓Facility control behavior
BMS, HVAC, power, alarms, life-safety systems, building controls, backup systems, and airport facility events tied to disruption timing.
✓Vendor and maintenance activity
Work orders, diagnostics, approved windows, remote support sessions, maintenance packages, update files, and vendor account activity.
✓Portable media and device history
USB activity, removable-media transfers, device insertions, file copies, endpoint device history, and portable diagnostic package use.
✓Logging and monitoring tampering
Disabled logging, audit-policy changes, SIEM suppression, EDR exclusions, deleted records, timestamp changes, and reduced telemetry.
✓Credential and secrets exposure
Credential dumping, LSASS access, Kerberos activity, service-account use, cached logons, tokens, certificates, vault access, and secret retrieval.
✓Disruption preparation indicators
Reconnaissance, delayed execution, staging, tool deployment, repeated probing, backup/snapshot activity, and pre-positioning inside airport networks.
✓Physical-cyber convergence
Cyber activity aligned with access-control records, camera metadata, facility alarms, airport operations timing, vendor presence, or restricted-area movement.

Correlation Maps Detections to Accounts, Networks, Systems, and Exposed Data

Flagged behaviors become connected evidence paths across accounts, devices, networks, badge events, vendor access, airport systems, and operational records.

REMI connects related activity across airport IT, identity, access control, camera metadata, vendor, firewall, endpoint, gate, ramp, baggage, and flight-support records so responders can see how separate events fit together. One system may show vendor access, another may show a workstation session, another may show badge activity, and another may show operational disruption. REMI correlates those records by time, account, device, IP address, badge ID, location, file, process, session, and repeated behavior.

REMI connects scattered flagged behaviors into the first clear view of how malware activity connects to operational disruption.


How REMI Shows The Connections

✓ Connection: stolen-laptop record → VPN login
Details: NPE-LT-18 was tied to c.arden, whose VPN login came from 203.0.113.44 one week after the laptop was reported stolen.
Why it matters: The same engineer’s device history and account activity are now linked to the remote-access event.
✓ Connection: VPN login → nuclear business network
Details: The c.arden VPN session reached 10.77.18.25 inside the nuclear business network 13 seconds after login.
Why it matters: The remote session did not stop at authentication; it reached an internal network destination.
✓ Connection: business network → office desktop
Details: The same session moved from 10.77.18.25 to OPS-DT-07 43 seconds later.
Why it matters: The activity moved from network entry into a usable internal desktop environment.
✓ Connection: office desktop → engineering workstation
Details: OPS-DT-07 connected toward NPE-ENG-04 inside the nuclear engineering support environment 2 minutes 12 seconds later.
Why it matters: The path crossed from business-network access toward engineering support systems.
✓ Connection: engineering workstation → historian-support records
Details: NPE-ENG-04 activity aligned with historian-support records 2 minutes 38 seconds later.
Why it matters: The engineering workstation path is now connected to plant-support records.

How REMI Explains the Connections

REMI connected the vendor login, source IP address, identity activity, internal workstation traffic, access-control records, and gate-support system activity into one evidence path. The first connection showed that vendor_ops_14 established a VPN session from 203.0.113.44 outside the approved maintenance window.

The second connection showed that the VPN session did not stop at authentication. Within 16 seconds, the session reached 10.88.14.25 inside the airport IT network. REMI then connected that internal destination to later activity on OPS-DT-09, showing that the remote session moved from external access into an airport operations desktop environment.

From there, REMI connected OPS-DT-09 to traffic toward GATE-SUP-04 and access-control records near Terminal B Gate 22. That mattered because GATE-SUP-04 was tied to gate-support records used for aircraft-turn and ramp coordination.

The final connection linked GATE-SUP-04 to camera metadata gaps, badge activity, and flight-support records. That gave investigators a clear path from remote access, to airport IT entry, to operations desktop activity, to gate-support systems, and finally to airport operations records.

Analysis Adds the Details, Fills in the Narrative Gaps, and Explains How the Attack Happened and Why the Alarms Stayed Quiet

REMI turns correlated evidence into the supported explanation of how the activity unfolded and why the warning signs did not become obvious sooner.

Analysis uses the connected evidence path to explain how access was achieved, how activity moved, which systems or airport areas were affected, why alerts or controls did not tell the full story, what evidence supports each conclusion, and what remains unresolved.

1 1 wk earlier
Stolen LaptopNPE-LT-18 reported stolen
7 days later
2 1:14 AM
VPN Loginc.arden from 203.0.113.44
3 sec later
3 1:14 AM
Business Entryconnected to 10.77.18.25
12 sec later
4 1:15 AM
Firewall Flowtoward NPE-ENG-04
2 min later
5 1:17 AM
Engineering ActivityNPE-ENG-04 workstation records
4 min later
6 1:21 AM
Historian Recordssupport activity out of plan

REMI turns correlated evidence into the explanation of how the incident happened and why the warning signs were missed.


How REMI Analysis Explains It

Analysis determined that the incident progressed because vendor_ops_14 established a remote VPN session from 203.0.113.44 and reached the airport IT network at 10.88.14.25. The same vendor account, VPN session window, source IP address, airport-network destination, and firewall flow records later aligned with activity on OPS-DT-09, traffic toward GATE-SUP-04, and access-control records near Terminal B Gate 22.

REMI’s Assessment

The alarm bells did not ring early because the activity used a valid vendor account, passed through trusted remote-access infrastructure, and moved through network paths that already existed between airport IT, operations desktops, gate-support systems, and access-control records.

The VPN login, MFA activity, firewall flow records, OPS-DT-09 activity, GATE-SUP-04 activity, badge events, camera metadata, and flight-support records became clear only after REMI connected them across account, device, IP address, timestamp, badge ID, location, destination system, network path, and airport operations activity.

How REMI See's It

✓ Connection Group 1: Vendor VPN login → airport IT network
REMI connected vendor_ops_14, the 2:14 AM VPN session, source IP 203.0.113.44, MFA activity, and firewall records showing entry into 10.88.14.25 inside the airport IT network.
✓ Connection Group 2: Airport IT network → operations desktop
REMI grouped the same VPN session window, source IP address, and internal traffic with activity on OPS-DT-09, showing the session moved from remote access into an airport operations desktop.
✓ Connection Group 3: Operations desktop → gate-support system
REMI connected OPS-DT-09 to traffic toward GATE-SUP-04, using matching timestamps, destination records, firewall flows, and workstation activity from the same session path.
✓ Connection Group 4: Gate-support system → Terminal B access records
REMI linked GATE-SUP-04 activity to access-control records near Terminal B Gate 22, including badge events, door-zone records, location data, and gate-support timestamps.
✓ Connection Group 5: Gate-support activity → airport operations impact
REMI connected gate-support activity with camera metadata gaps, badge activity, and flight-support records, creating one grouped path from remote access to airport operations records.

on-the-spot Reporting

Advanced Cyber Attacks On Nuclear Power Facilities

REMI generates both airport-specific reports and broader incident response reports from the same evidence package. For airport environments, the reports focus on IT, identity, access control, badge activity, camera metadata, gate operations, ramp support, baggage systems, vendor access, maintenance records, and flight-support activity.

Reporting Package

✓ Executive Summary
What happened, what systems were affected, and what needs attention.
✓ Detection Summary
Flagged behaviors, triggered indicators, affected sources, and first observed activity.
✓ Behavioral Analysis
Suspicious access, unusual process activity, abnormal commands, persistence, tool spawning, and disruption patterns.
✓ Timeline Report
Event-by-event sequence showing when activity began, spread, changed, and ended.
✓ Correlation Report
Connects accounts, devices, IP addresses, files, processes, sessions, and events across separate sources.
✓ Group / Entity Analysis
Related users, vendors, machines, tools, accounts, and systems involved in the event.
✓ Affected Systems Report
Touched devices, high-priority systems, and records showing configuration or settings changes.
✓ Forensic Preservation Report
Files, paths, logs, artifacts, scripts, binaries, hashes, and evidence to preserve.
✓ Cyber SITREP / Next Steps Report
Size, scope, findings, open questions, and prioritized responder actions.

SitRep

✓ What happened
The evidence-backed sequence of events from first activity through affected systems.
✓ Who and what was involved
Accounts, devices, networks, systems, vendors, files, sessions, and source records.
✓ How the activity moved
Entry point, connection path, lateral movement, trusted access paths, and systems touched.
✓ Insider or assisted access review
Account use, approvals, shared access, vendor activity, or open remote tools tied to the evidence.
✓ What is fully answered
Findings supported by source records, timestamps, logs, artifacts, and system activity.
✓ What remains unresolved
Open questions where the current evidence does not yet prove the full answer.
✓ What data is needed next
Logs, approvals, asset-owner records, vendor records, source files, or telemetry needed to close each gap.
✓ What to do right now
Preserve, isolate, sandbox, remove, remediate, verify, escalate, or request additional records.

Story Gaps

✓ Partly answered: REMI confirmed the VPN session used vendor_maint_02 outside the normal access window.
Question: Was the VPN login approved?
Event logs needed: Maintenance ticket, vendor work order, change approval, and MFA approval record.
✓ Partly answered: REMI confirmed the VPN login came from 203.0.113.44, a source IP not seen in prior sessions.
Question: Was this source location expected?
Event logs needed: VPN source-IP history, identity sign-in logs, geolocation records, and vendor access baseline.
✓ Answered: REMI confirmed the session reached 192.165.43.18 after authentication.
Detail gap: Was this an approved intermediate host?
Event logs needed: Asset inventory, firewall flow logs, DHCP/DNS records, system owner records, and approved remote-access path records.
✓ Partly answered: REMI connected the VPN session to traffic toward ENG-WS-04.
Question: Which engineering actions were performed?
Event logs needed: EDR telemetry, engineering workstation logs, project-file access records, tool execution logs, and jump-host records.
✓ Open question: The account owner behind the VPN session is not fully proven.
Question: Who used the VPN account?
Event logs needed: MFA device record, identity provider logs, account-owner record, vendor assignment record, and privileged-access logs.

Actionable items

1 Preserve VPN and endpoint evidence first
Preserve logs for vendor_maint_02, source IP 203.0.113.44, internal host 192.165.43.18, desktop OPS-DT-07, and engineering workstation ENG-WS-04 before removal.
2 Isolate the affected desktop and engineering workstation
Isolate OPS-DT-07 and ENG-WS-04 from the network. Firewall and EDR records show the VPN path moved through these systems.
3 Locate malware paths on ENG-WS-04
Search ENG-WS-04 for C:\Users\Public\update-task.vbs, C:\Temp\stage.ps1, and C:\ProgramData\svc-loader.bat.
4 Locate AI-spawned controller on OPS-DT-07
Search OPS-DT-07 for C:\Users\j.martinez\AppData\Roaming\sysrunner.exe and preserve a forensic copy for sandboxing.
5 Remove confirmed staged scripts after preservation
After preservation, remove C:\Temp\stage.ps1, C:\ProgramData\svc-loader.bat, and C:\Users\Public\update-task.vbs from affected hosts.
6 Disable exposed remote access
Disable vendor_maint_02, revoke active VPN sessions, rotate credentials, reset MFA, and review vendor access tied to 203.0.113.44.
7 Scrub affected engineering folders
Review and remediate project folders on ENG-WS-04, including D:\Engineering\Projects\NorthPump and related control-support files touched during the session.
8 Verify no return activity
Check OPS-DT-07, ENG-WS-04, 192.165.43.18, and VPN logs for new callbacks, scheduled tasks, repeated processes, reopened sessions, or restored persistence.

Downloads

Use Case_AI-Spawned Malware Controller Inside Engineering Support

At 5:18 AM, the plant systems engineer at Granite Ridge Nuclear Station noticed that engineering support records did not line up with the overnight work plan. Nothing was fully down, but the pattern was wrong: an engineering workstation showed command activity after the maintenance window, a historian support server recorded...

Download remi_nuclear_ai_malware_controller_sitrep_use_case.pdf

Use Case_AI-Generated Logic Package Disguised as Vendor Maintenance

At 6:04 AM, the control systems engineer at Granite Ridge Nuclear Station noticed that auxiliary support values did not line up with the approved post-maintenance baseline. The plant support system was stable, but the pattern was wrong: a controller showed a new active revision, the upload time came after the approved vendor window, and the package name matched a work order while the behavior did not match the signed baseline.

Download: remi_nuclear_ai_logic_package_sitrep_use_case.pdf

Use Case_AI-Directed Pre-Positioning Across Nuclear Support Systems

At 4:37 AM, the cyber security lead at Granite Ridge Nuclear Station noticed that low-volume access across plant support systems did not line up with the overnight work plan. Nothing triggered a major alarm, but the pattern was wrong: a service account touched historian servers, a jump host launched administrative tools, and an engineering file share recorded folder enumeration during a window with no approved support activity.

Download: remi_nuclear_ai_logic_package_sitrep_use_case.pdf

Airport SitRep_Browser Downloaded Malware From Phishing Attack

Airport SitRep_IT Issue Refresh Rate Changed Causing Extended Delays