A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.
31 August 2026
A first investigation for anyone who has read about persistence but never gone looking for it. You will plant a Run key with Atomic Red Team, then find it three different ways and work out which of the three you would actually trust in production.
31 August 2026
WMI event subscriptions run code on a condition you choose, survive reboots, live nowhere in the filesystem, and log nothing by default. The last of the persistence series, and the one that changes how you think about the other three.
31 August 2026
Plant a scheduled task with Atomic Red Team, then find it four ways and work out which one survives an attacker who names their task properly. Closes the loop on the persistence you found on the domain controller in the Northwind case.
31 August 2026
Windows services run as SYSTEM and start before anyone logs in, which makes them the most valuable persistence on the box and the hardest to spot among the two hundred already there. Part three of the persistence series.
31 August 2026
A beginner's guide to MITRE ATT&CK that does not open with the matrix. What it is, what it is not, why the giant grid is the worst way to meet it, and how to use it on a Tuesday afternoon rather than in a strategy deck.
31 August 2026
Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022, most of them local and none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.
30 August 2026
CVE-2026-60004 turns repository write access into shell execution as the Gitea service account. The interesting part is not the injection. It is that Git hooks are executable files sitting inside a directory your developers write to all day.
30 August 2026
CVE-2026-73570 needs no credentials and no user interaction. A crafted SMTP request executes commands as the zimbra user. Mail servers accept connections from strangers by definition, which is what makes pre-auth bugs in them a different category of problem.
30 August 2026
Eleven Sigma rules and three YARA signatures covering the persistence and execution techniques that showed up most in this quarter's casework, with measured false-positive budgets.
25 August 2026
A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.
18 August 2026
Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.
9 August 2026
Entropy, subdomain cardinality and query-rate shape — three statistics that find a covert channel faster than any rule matching a known tool.
27 July 2026
Six months of a detection lab that was impressive to look at and useless to work in, and the four changes that fixed it.
30 June 2026