constructed and real, labelled
Some of these describe invented organisations and invented incidents, written so there is something to practise on. Those are marked Constructed on the card and again at the top of the piece. The techniques, artifact locations and reasoning in them are real; only the company and the people are not.
That label is not modesty. A case study you cannot tell is fictional is one you might cite in a report.
Written for practice
3 constructedAnalysisMembersConstructed
A full DFIR report on a constructed ransomware incident, written the way one gets handed to a board. Three hours twenty from first execution to encryption, four separate points where it could have been stopped, and the write-up that follows.
Full write-up available to members subscribers. See what is included.
Guided LabMembersConstructed
A business email compromise where the obvious finding is a decoy. Ninety minutes on Microsoft 365 audit logs, OAuth consent grants, and why resetting the password does not end this incident.
Full write-up available to members subscribers. See what is included.
Guided LabMembersConstructed
A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.
Full write-up available to members subscribers. See what is included.
Analysis and technique
14 piecesGuided Lab
Every other lab here asks for a virtual machine. This one asks for a terminal. Pre-recorded event logs, a cross-platform parser, and the same reasoning, on whatever laptop you already have.
Guided Lab
The first lab for a machine of your own. You create the evidence yourself, delete a file from it, and then recover the file you deleted, which is the only way to be certain the recovery worked.
Guided Lab
Windows services run as SYSTEM and start before anyone logs in, which makes them the most valuable persistence on the box and the hardest to spot among the two hundred already there. Part three of the persistence series.
Guided Lab
Plant a scheduled task with Atomic Red Team, then find it four ways and work out which one survives an attacker who names their task properly. Closes the loop on the persistence you found on the domain controller in the Northwind case.
Guided LabMembers
WMI event subscriptions run code on a condition you choose, survive reboots, live nowhere in the filesystem, and log nothing by default. The last of the persistence series, and the one that changes how you think about the other three.
Full write-up available to members subscribers. See what is included.
Guided Lab
A first investigation for anyone who has read about persistence but never gone looking for it. You will plant a Run key with Atomic Red Team, then find it three different ways and work out which of the three you would actually trust in production.
Analysis
A beginner's guide to MITRE ATT&CK that does not open with the matrix. What it is, what it is not, why the giant grid is the worst way to meet it, and how to use it on a Tuesday afternoon rather than in a strategy deck.
Analysis
CVE-2026-73570 needs no credentials and no user interaction. A crafted SMTP request executes commands as the zimbra user. Mail servers accept connections from strangers by definition, which is what makes pre-auth bugs in them a different category of problem.
Analysis
CVE-2026-60004 turns repository write access into shell execution as the Gitea service account. The interesting part is not the injection. It is that Git hooks are executable files sitting inside a directory your developers write to all day.
AnalysisMembers
Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022, most of them local and none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.
Full write-up available to members subscribers. See what is included.
AnalysisMembers
A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.
Full write-up available to members subscribers. See what is included.
AnalysisMembers
Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.
Full write-up available to members subscribers. See what is included.
Analysis
Entropy, subdomain cardinality and query-rate shape — three statistics that find a covert channel faster than any rule matching a known tool.
Lab Note
Six months of a detection lab that was impressive to look at and useless to work in, and the four changes that fixed it.
Other people’s work, worth your evening
Free to read, all of it, and none of it ours. Linked rather than summarised: the point of a case study is the detail, and a précis that saves you the click also saves the author the credit.
Volunteer analysts publishing real intrusions
The closest thing the field has to a case-law library. Each report walks an intrusion from initial access to impact with the actual artifacts, and most carry Sigma rules at the end. Read one a week and your instincts change.
Public reports are free; a paid feed exists separately.
US Cybersecurity and Infrastructure Security Agency
Joint advisories carry TTPs and detection guidance for named actors, and being US government work they are public domain, so you can reuse the content in your own runbooks without asking anybody.
Entirely free, no account.
A managed detection provider, published annually
Ranks the techniques they actually saw across thousands of environments, with detection guidance for each. The value is the ranking: it tells you what to build detection for first, which is a different question from what is interesting.
Free, email requested for the PDF.
Cisco Talos; Palo Alto Unit 42 publishes comparably
Malware analysis with the reverse engineering shown rather than summarised. Useful when you have a sample and need to know what a family does, rather than when you have a host and need to know what happened.
Free, no account.
Incident responders publishing from engagements
Long-form intrusion analysis, usually of the more capable end of the spectrum. Their M-Trends report each year is the best single read on how dwell time and initial access are actually trending.
Most reports free; some ask for an email.
Two teams that publish quickly during live campaigns
Where to look during an unfolding event. Both tend to publish artifacts and indicators within a day or two of a mass-exploitation campaign starting, which is when you need them rather than a month later.
Free, no account.
Worked something yourself and want it read? The submissions desk takes case studies under your own byline, and the community is where the shorter ones go.