Evidence Gap Challenge No. 3: four people knew that password

An operational technology jump host, a shared engineering account, and a change nobody will own. Every log works, every timestamp is right, and attribution is still impossible. Work out what that costs, and what you would have needed to collect to make a name provable.

The call

Ashgrove Polymers runs a single manufacturing site. Access to the plant network goes through one engineering jump host, and access to that jump host uses a shared local account, eng-ops, because the control system vendor's support contract requires it and four engineers need it at any hour.

On 14 August a safety interlock configuration on a mixing line is changed. The change is within the operator's authority to make, it is not obviously malicious, and nobody has put their name to it. It is found on 2 September during a routine audit.

What is already known

14 August, 21:47. A session to the jump host authenticates as eng-ops from the corporate network.

14 August, 22:06. The interlock configuration is written. The control system records the change, the previous value, and the account, which is the vendor's own shared service account.

14 August, 22:11. The session ends.

2 September. The audit finds it.

The evidence that still exists

SourceRetainedWhat it holds
Jump host security log90 daysLogon and logoff for eng-ops, with source address and session id
Corporate VPN90 daysWhich named employee held which internal address, by time
Control system change log7 yearsThe change, the old value, the new value, and the vendor service account
Jump host command historyNot retainedShell history is per-profile and the profile is shared and overwritten
Badge access12 monthsWho was physically on site, by door, by minute
Corporate Entra ID sign-in30 daysRolled for 14 August before anyone looked
CCTV21 daysRolled

There is no session recording on the jump host. There is no per-engineer account on it. The four engineers are Priya, Dan, Marek and a contractor, Ivo, whose contract ended on 29 August.

The questions

Q1

The VPN log says which named employee held the source address at 21:47.

State exactly what that establishes, and what it does not. Be precise about the gap between "this person's device held that address" and "this person made that change".

Q2

The badge system knows who was physically on site.

Say how you would use it here, and name the two ways it can mislead you in this specific scenario.

Q3

List every claim you can make about the 14 August change that would survive somebody competent arguing against it.

Then list the claims you would like to make and cannot.

Q4

One of the four engineers is a contractor whose access ended on 29 August, fifteen days after the change and four days before it was found.

Say why that matters procedurally, and whether it changes any technical conclusion. Be careful here.

Q5

The plant manager wants a name.

Write what you tell them. It has to be honest about the limits of the evidence without being useless, and it must not name anybody the evidence does not support naming.

Q6

The vendor support contract requires the shared account.

Propose the collection change that makes the next one attributable, given that constraint. It has to be compatible with the contract, workable at 3am for an engineer who is fixing a line that has stopped, and you have to say what it costs.

Q7

Suppose the change turns out to be entirely innocent: a legitimate adjustment somebody forgot to write up.

Say what, if anything, you would still change afterwards, and defend spending money on attribution for an incident that turned out not to be one.

Notes on how this is meant to be worked

Every log in this scenario worked. Nothing rolled that mattered, no retention was too short, and every timestamp is correct. The gap is not a missing log; it is that the identity was shared, and no amount of logging resolves a name that was never distinct in the first place.

That is why this one is here. The reflex answer to an evidence gap is more logging, and it is the wrong reflex about half the time. Question 6 is the exercise: the constraint is real, it is contractual rather than technical, and the useful answer works inside it.

The trap in question 4 is the one worth naming in advance. A contractor whose access ended shortly after an unexplained change is the most available explanation in the room, and availability is not evidence. An investigation that lands on the least powerful person present because the timing is suggestive is the failure mode this format exists to train against.

Post your answer

Post it in the community. As with the others, the two columns first: what you can prove, and what you can only say is consistent.

Sources for the constraints used above: ATT&CK T1078.001 Valid Accounts: Default Accounts · CISA: insider threat mitigation guide · NIST SP 800-61r3, incident response

The scenario is invented. Shared operational accounts on engineering jump hosts, and the attribution problem they create, are real and were the starting point rather than a detail added afterwards. No incident data informed this.

Corrections and additions are welcome: this is a working document. Get in touch, or post a case of your own in the community.

Discussion

Guidelines

Sign in to comment. Corrections and additions are the point: this is a working document.