Skip to main content

Generate an Incident Response Cyber SITREP and in minutes identify the size and scope of the adversarial cyber attack.

REMI analyzes enterprise IT evidence across endpoints, servers, identity systems, VPN activity, firewall logs, DNS, proxy, EDR, SIEM, cloud platforms, SaaS applications, email systems, file shares, USB activity, and case records.

Instead of manually comparing endpoint alerts, Windows event logs, VPN sessions, identity records, firewall flows, cloud audit logs, file-access activity, email telemetry, and EDR detections one source at a time, REMI analyzes the full evidence package together. It reconstructs what happened, how access was achieved, which accounts and devices were involved, where lateral movement occurred, what files or tools appeared, what data was touched, what remains unresolved, and which records support the sequence.

REMI Supports Enterprise IT Event Logs

REMI analyzes evidence from enterprise incident response environments, including endpoint activity, VPN and identity records, firewall logs, EDR telemetry, DNS records, proxy logs, cloud audit events, email activity, server logs, file-access records, USB activity, SIEM alerts, and case notes.

By connecting these records across enterprise IT systems, REMI helps investigators see whether an incident stayed on one endpoint or moved across identity systems, remote access, servers, cloud platforms, file shares, email systems, or data repositories. It reconstructs what happened, which systems were touched, what changed, what evidence supports the findings, and what records are still needed to close the gaps.

IT Event Logs

Endpoint and EDR logsProcess activity, files, scripts, malware paths, hashes, and device telemetry.
Server and Windows event logsLogons, services, scheduled tasks, PowerShell, registry, and system events.
Identity and access logsUsers, admin accounts, MFA, SSO, tokens, groups, permissions, and sign-ins.
Firewall and network logsInternal traffic, external IPs, ports, DNS, VPN sessions, and lateral movement paths.
Cloud platform logsAzure, AWS, Google Cloud, SaaS activity, storage access, app credentials, and API events.

REMI Is Trained to Recognize Advanced Adversarial Cyber Behaviors in IT Environments

samples from nuclear behavioral and pattern analysis

REMI identifies abnormal activity across the available enterprise IT evidence before the incident story is fully known. Detection is the first pass: it names the flagged behaviors, affected systems, accounts, devices, timestamps, commands, files, network connections, and source records that should move forward into correlation.

IT Behavioral Detection

Unusual sign-ins
New locations, impossible travel, off-hours access, failed MFA, token reuse, or abnormal login patterns.
Endpoint activity
Unexpected processes, scripts, malware paths, dropped files, persistence, hashes, and device telemetry.
Network movement
Internal traffic, external callbacks, DNS activity, VPN sessions, ports, protocols, and lateral movement paths.
Privilege and access changes
Admin role changes, permission updates, group membership changes, service accounts, and token activity.
Cloud and SaaS activity
Storage access, mailbox activity, API calls, app credentials, file sharing, downloads, and data movement.
Data exfiltration indicators
Large transfers, unusual downloads, external sharing, archive creation, USB activity, and abnormal outbound traffic.
Insider threat indicators
After-hours access, unusual file access, policy bypasses, removable media use, deleted logs, or access outside job role.
Inside assistance indicators
Shared credentials, approved access used at abnormal times, suspicious vendor coordination, unlocked remote tools, or access enabled before activity.

How REMI Sees Detection

Flagged behavior: Remote VPN login outside the normal access window
Device / account: vendor_maint_02
Found in: VPN authentication records at 2:17 AM
Flagged behavior: New source IP used for the vendor account
Source: 203.0.113.44
Found in: Identity and VPN source-IP history
Flagged behavior: Internal office-network access after VPN authentication
Destination: 192.165.43.18
Found in: Firewall flow records and VPN tunnel records
Flagged behavior: Engineering workstation activity during the same session window
Device: ENG-WS-04
Found in: EDR telemetry, workstation logs, and session records
Flagged behavior: Script execution after remote access began
File path: C:\Temp\stage.ps1
Found in: Endpoint process records and Windows event logs
Flagged behavior: Persistence entry created on the affected workstation
Device: ENG-WS-04
Found in: Scheduled task records and registry activity
Flagged behavior: Outbound network connection after script execution
Device: ENG-WS-04
Found in: Firewall egress logs, DNS records, and EDR network telemetry
Flagged behavior: Activity tied to a valid account during an unusual time window
Account: vendor_maint_02
Found in: Identity logs, VPN records, and account activity history

Correlation Is Where the Incident Story Starts to Form 

REMI connects scattered flagged behaviors into the first clear view of how malware activity connects to operational disruption.


REMI connects related activity across plant, engineering, vendor, security, and control-system records so responders can see how separate events fit together.

A single alert rarely explains a nuclear cyber event. One system may show vendor access, another may show engineering workstation activity, another may show a diagnostic package or file change, and another may show activity near HMI, historian, or control-configuration records. REMI correlates those records by time, account, device, IP address, file, process, session, and repeated behavior to build the first evidence-backed version of the story.

How REMI See's Correlations

Connection: stolen laptop record → VPN login
Details: IR-LT-18 was tied to c.arden, whose VPN login came from 203.0.113.44 one week after the laptop was reported stolen.
Why it matters: The same user’s device history and account activity are now linked to the remote-access event.
Connection: VPN login → corporate network
Details: The c.arden VPN session reached 10.20.18.25 inside the corporate network 13 seconds after login.
Why it matters: The remote session did not stop at authentication; it reached an internal network destination.
Connection: corporate network → employee desktop
Details: The same session moved from 10.20.18.25 to CORP-DT-07 43 seconds later.
Why it matters: The activity moved from network entry into a usable internal desktop environment.
Connection: employee desktop → file server
Details: CORP-DT-07 connected toward FILE-SRV-04 inside the internal file-sharing environment 2 minutes 12 seconds later.
Why it matters: The path crossed from remote access into systems that store business data, shared files, and case-relevant records.
Connection: file server → data access records
Details: FILE-SRV-04 activity aligned with file-access, archive-creation, and outbound network records 2 minutes 38 seconds later.
Why it matters: The file-server path is now connected to data-access behavior that responders need to review for exfiltration, preservation, and containment.

How REMI Explains the Connections

REMI connected the remote-access session, identity activity, endpoint telemetry, file-share records, and outbound network traffic into one evidence path. The first connection showed that **svc-remoteops** authenticated through VPN from **203.0.113.44** during a weekend window when no remote support ticket was open.

The second connection showed that the VPN session did not stop at authentication. Within **18 seconds**, the session reached **10.42.18.25** inside the corporate network. REMI then connected that internal destination to later activity on **FIN-DT-12**, showing that the remote session moved from external access into a usable desktop environment.

From there, REMI connected **FIN-DT-12** to file-share access on **FS-CLIENT-07** and script execution on **APP-SRV-04**. That mattered because the activity was tied to the same account, source IP, session window, endpoint process chain, and file-access records.

The final connection linked **FS-CLIENT-07** to archive creation, large file reads, and outbound transfer records. That gave investigators a clear path from remote access, to internal desktop activity, to server interaction, to data access, and finally to evidence showing what data left the environment.

ANALYSIS EXPLAINS HOW THE ATTACK HAPPENED

How It Happened

1 1 wk earlier
Stolen LaptopNPE-LT-18 reported stolen
7 days later
2 1:14 AM
VPN Loginc.arden from 203.0.113.44
3 sec later
3 1:14 AM
Business Entryconnected to 10.77.18.25
12 sec later
4 1:15 AM
Firewall Flowtoward NPE-ENG-04
2 min later
5 1:17 AM
Engineering ActivityNPE-ENG-04 workstation records
4 min later
6 1:21 AM
Historian Recordssupport activity out of plan

How REMI See's It

Connection: stolen laptop record → VPN login
Details: IR-LT-18 was tied to c.arden, whose VPN login came from 203.0.113.44 one week after the laptop was reported stolen.
Why it matters: The same user’s device history and account activity are now linked to the remote-access event.
Connection: VPN login → corporate network
Details: The c.arden VPN session reached 10.20.18.25 inside the corporate network 13 seconds after login.
Why it matters: The remote session did not stop at authentication; it reached an internal network destination.
Connection: corporate network → employee desktop
Details: The same session moved from 10.20.18.25 to CORP-DT-07 43 seconds later.
Why it matters: The activity moved from network entry into a usable internal desktop environment.
Connection: employee desktop → file server
Details: CORP-DT-07 connected toward FILE-SRV-04 inside the internal file-sharing environment 2 minutes 12 seconds later.
Why it matters: The path crossed from remote access into systems that store business data, shared files, and case-relevant records.
Connection: file server → data access records
Details: FILE-SRV-04 activity aligned with file-access records, archive creation, and outbound network records 2 minutes 38 seconds later.
Why it matters: The file-server path is now connected to data-access behavior that responders need to review for exfiltration, preservation, and containment.

Howe REMI Explains It

Analysis determined that the incident progressed because svc-remoteops established a remote VPN session from 203.0.113.44 and reached the corporate network at 10.42.18.25. The same service account, VPN session window, source IP address, internal destination, and firewall flow records later aligned with activity on FIN-DT-12, APP-SRV-04, and FS-CLIENT-07.

REMI’s Assessment

The alarm bells did not ring early because the activity used a valid account, passed through trusted remote-access infrastructure, and moved through network paths that already existed between the VPN environment, desktop systems, application server, and file-share records. The VPN login, MFA activity, firewall flow records, endpoint process activity, PowerShell execution, file-share access, archive creation, and outbound transfer records were each visible in separate systems, but they did not become a clear incident story until REMI connected them across account, device, IP address, timestamp, destination system, process chain, network path, and data-access activity.

REMI turns correlated evidence into the explanation of how the incident happened and why the warning signs were missed.


Analysis determined that the incident progressed because svc-remoteops established a remote VPN session from 203.0.113.44 and reached the corporate network at 10.42.18.25. The same service account, VPN session window, source IP address, internal destination, and firewall flow records later aligned with activity on FIN-DT-12, APP-SRV-04, and FS-CLIENT-07.

REMI’s Assessment

The alarm bells did not ring early because the activity used a valid account, passed through trusted remote-access infrastructure, and moved through network paths that already existed between the VPN environment, desktop systems, application server, and file-share records. The VPN login, MFA activity, firewall flow records, endpoint process activity, PowerShell execution, file-share access, archive creation, and outbound transfer records were each visible in separate systems, but they did not become a clear incident story until REMI connected them across account, device, IP address, timestamp, destination system, process chain, network path, and data-access activity.

on-the-spot Reporting

Advanced Cyber Attacks On Nuclear Power Facilities

REMI generates both nuclear-specific reports and broader incident response reports from the same evidence package. For nuclear environments, the reports focus on plant, engineering, vendor, security, and control-system activity, including HMI events, historian records, control-configuration changes, vendor maintenance access, portable-media activity, and plant-adjacent IT/OT behavior.

Reporting Package

Executive Summary
What happened, what systems were affected, and what needs attention.
Detection Summary
Flagged behaviors, triggered indicators, affected sources, and first observed activity.
Behavioral Analysis
Suspicious access, unusual process activity, abnormal commands, persistence, tool spawning, and disruption patterns.
Timeline Report
Event-by-event sequence showing when activity began, spread, changed, and ended.
Correlation Report
Connects accounts, devices, IP addresses, files, processes, sessions, and events across separate sources.
Group / Entity Analysis
Related users, vendors, machines, tools, accounts, and systems involved in the event.
Affected Systems Report
Touched devices, high-priority systems, and records showing configuration or settings changes.
Forensic Preservation Report
Files, paths, logs, artifacts, scripts, binaries, hashes, and evidence to preserve.
Cyber SITREP / Next Steps Report
Size, scope, findings, open questions, and prioritized responder actions.

SitRep

What happened
The evidence-backed sequence of events from first activity through affected systems.
Who and what was involved
Accounts, devices, networks, systems, vendors, files, sessions, and source records.
How the activity moved
Entry point, connection path, lateral movement, trusted access paths, and systems touched.
Insider or assisted access review
Account use, approvals, shared access, vendor activity, or open remote tools tied to the evidence.
What is fully answered
Findings supported by source records, timestamps, logs, artifacts, and system activity.
What remains unresolved
Open questions where the current evidence does not yet prove the full answer.
What data is needed next
Logs, approvals, asset-owner records, vendor records, source files, or telemetry needed to close each gap.
What to do right now
Preserve, isolate, sandbox, remove, remediate, verify, escalate, or request additional records.

Story Gaps

Partly answered: REMI confirmed the VPN session used vendor_maint_02 outside the normal access window.
Question: Was the VPN login approved?
Event logs needed: Maintenance ticket, vendor work order, change approval, and MFA approval record.
Partly answered: REMI confirmed the VPN login came from 203.0.113.44, a source IP not seen in prior sessions.
Question: Was this source location expected?
Event logs needed: VPN source-IP history, identity sign-in logs, geolocation records, and vendor access baseline.
Answered: REMI confirmed the session reached 192.165.43.18 after authentication.
Detail gap: Was this an approved intermediate host?
Event logs needed: Asset inventory, firewall flow logs, DHCP/DNS records, system owner records, and approved remote-access path records.
Partly answered: REMI connected the VPN session to traffic toward ENG-WS-04.
Question: Which engineering actions were performed?
Event logs needed: EDR telemetry, engineering workstation logs, project-file access records, tool execution logs, and jump-host records.
Open question: The account owner behind the VPN session is not fully proven.
Question: Who used the VPN account?
Event logs needed: MFA device record, identity provider logs, account-owner record, vendor assignment record, and privileged-access logs.

Actionable items

1 Preserve VPN and endpoint evidence first
Preserve logs for vendor_maint_02, source IP 203.0.113.44, internal host 192.165.43.18, desktop OPS-DT-07, and engineering workstation ENG-WS-04 before removal.
2 Isolate the affected desktop and engineering workstation
Isolate OPS-DT-07 and ENG-WS-04 from the network. Firewall and EDR records show the VPN path moved through these systems.
3 Locate malware paths on ENG-WS-04
Search ENG-WS-04 for C:\Users\Public\update-task.vbs, C:\Temp\stage.ps1, and C:\ProgramData\svc-loader.bat.
4 Locate AI-spawned controller on OPS-DT-07
Search OPS-DT-07 for C:\Users\j.martinez\AppData\Roaming\sysrunner.exe and preserve a forensic copy for sandboxing.
5 Remove confirmed staged scripts after preservation
After preservation, remove C:\Temp\stage.ps1, C:\ProgramData\svc-loader.bat, and C:\Users\Public\update-task.vbs from affected hosts.
6 Disable exposed remote access
Disable vendor_maint_02, revoke active VPN sessions, rotate credentials, reset MFA, and review vendor access tied to 203.0.113.44.
7 Scrub affected engineering folders
Review and remediate project folders on ENG-WS-04, including D:\Engineering\Projects\NorthPump and related control-support files touched during the session.
8 Verify no return activity
Check OPS-DT-07, ENG-WS-04, 192.165.43.18, and VPN logs for new callbacks, scheduled tasks, repeated processes, reopened sessions, or restored persistence.

Use Case:

how REMI turns event logs and source records into a cyber SITREP

AI-Spawned Malware Controller on Enterprise Endpoint

At 8:16 AM, the security operations analyst at Metro Health Administration noticed that an endpoint alert did not match a normal malware pattern. The workstation was online, but the pattern was wrong: generated scripts appeared in a user profile, a child process launched from a temporary directory, and outbound traffic repeated in short bursts to an external IP....

Download remi_ir_ai_malware_controller_endpoint_sitrep_use_case.pdf

Remote Admin Access Into Government IT Systems

At 7:08 AM, the help desk manager at Riverside County Services noticed that several user lockout tickets arrived before business hours. The network was operating, but the pattern was wrong: an administrator account showed overnight VPN access, a domain controller recorded unusual directory queries, and a file server showed access to folders tied to public records operations..

Download:remi_ir_government_remote_admin_access_sitrep_use_case.pdf

AI-Spawned Malware Controller on Enterprise Endpoint

At 8:16 AM, the security operations analyst at Metro Health Administration noticed that an endpoint alert did not match a normal malware pattern. The workstation was online, but the pattern was wrong: generated scripts appeared in a user profile, a child process launched from a temporary directory, and outbound traffic repeated in short bursts to an external IP.

Download: remi_ir_ai_malware_controller_endpoint_sitrep_use_case.pdf