A beacon called home eleven minutes ago. There is a person on the other end of it, and they are working through your network right now — hunting credentials, moving sideways, heading for the database. They do not stop while you think.
A safe, fictional simulation — nothing on your machine is touched. The attack path mirrors real intrusions: phished credentials, a beaconing implant, credential dumping, lateral movement and staged exfiltration over HTTPS.
The event stream names the compromised account and the C2 address if you are watching. Everything you need to act correctly is in there before the attacker uses it.
Revoke the account, kill the beacon process, isolate the host they landed on, and block the exfil IP. Each one removes a capability they were relying on.
revoke j.mehta, kill 4471, isolate WS-FIN-03, block 185.220.101.44, status. Type help for the full list.