Learn

Case studies

Worked intrusions: what the evidence said, in what order, and what turned out to be wrong on the way. Every one of ours has a discussion under it, because the disagreements are usually worth more than the write-up.

constructed and real, labelled

Some of these describe invented organisations and invented incidents, written so there is something to practise on. Those are marked Constructed on the card and again at the top of the piece. The techniques, artifact locations and reasoning in them are real; only the company and the people are not.

That label is not modesty. A case study you cannot tell is fictional is one you might cite in a report.

Written for practice

3 constructed
Guided LabMembersConstructed

Guided lab: nine hours at Northwind Freight, from lure to scheduled task

A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.

about 1.5 hours of workT1566.001T1059.001T1003.001

Full write-up available to members subscribers. See what is included.

Analysis and technique

14 pieces
AnalysisMembers

CISA just added four old local privilege escalation bugs to KEV. That is the interesting part.

Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022, most of them local and none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.

5 min readCVE-2015-3246CVE-2015-5287T1068T1190

Full write-up available to members subscribers. See what is included.

Other people’s work, worth your evening

Free to read, all of it, and none of it ours. Linked rather than summarised: the point of a case study is the detail, and a précis that saves you the click also saves the author the credit.

The DFIR Report

Volunteer analysts publishing real intrusions

The closest thing the field has to a case-law library. Each report walks an intrusion from initial access to impact with the actual artifacts, and most carry Sigma rules at the end. Read one a week and your instincts change.

Public reports are free; a paid feed exists separately.

CISA advisories and alerts

US Cybersecurity and Infrastructure Security Agency

Joint advisories carry TTPs and detection guidance for named actors, and being US government work they are public domain, so you can reuse the content in your own runbooks without asking anybody.

Entirely free, no account.

Red Canary Threat Detection Report

A managed detection provider, published annually

Ranks the techniques they actually saw across thousands of environments, with detection guidance for each. The value is the ranking: it tells you what to build detection for first, which is a different question from what is interesting.

Free, email requested for the PDF.

Talos and Unit 42 research

Cisco Talos; Palo Alto Unit 42 publishes comparably

Malware analysis with the reverse engineering shown rather than summarised. Useful when you have a sample and need to know what a family does, rather than when you have a host and need to know what happened.

Free, no account.

Mandiant / Google Cloud threat intelligence

Incident responders publishing from engagements

Long-form intrusion analysis, usually of the more capable end of the spectrum. Their M-Trends report each year is the best single read on how dwell time and initial access are actually trending.

Most reports free; some ask for an email.

Huntress and Volexity write-ups

Two teams that publish quickly during live campaigns

Where to look during an unfolding event. Both tend to publish artifacts and indicators within a day or two of a mass-exploitation campaign starting, which is when you need them rather than a month later.

Free, no account.

Worked something yourself and want it read? The submissions desk takes case studies under your own byline, and the community is where the shorter ones go.