Incident report: Kesterline Components, 8 May 2026
A full DFIR report on a constructed ransomware incident, written the way one gets handed to a board. Three hours twenty from first execution to encryption, four separate points where it could have been stopped, and the write-up that follows.
Security Artifacts
about 2 hours of work
Constructed scenario. This case is written for practice. The organisation, the people and the events in it are invented, and no real incident is being described. The techniques, artifact locations and analytic reasoning are real, but the evidence is illustrative rather than exported from a live host, so it is tidier than anything you will meet in production.
This is a complete incident report on an invented company. The organisation, the
people, the hashes and the addresses do not exist. Everything else, the
technique sequence, the artifacts, the timings, the four points at which it
could have been stopped, is how these actually go.
It is written the way a report gets handed over: an executive summary somebody
will read in a lift, a timeline somebody will argue with, and a set of
recommendations somebody will be asked to cost. Read it as a worked example of
the writing as much as of the analysis. The evidence behind it is loaded in the
lab console, so you can work the data first and then
compare what you concluded against what went in the report.
Budget about two hours if you do both.
1. Executive summary
[!] members only
The rest of this teardown: the full timeline, the complete IOC list and the detection rule with its tuning notes, is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.