> This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.
Well, that may be correct for the second, local, analysis attempt... but seems funny to tout this as an advantage after already having tried the opposite...
[flagged]
It's even funnier because an attack, until proven otherwise, should make you assume the data has already left the environment.