Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics.

What a given artifact proves, what it only suggests, and what it cannot tell you at all. Registry, event logs, the filesystem and the journals underneath them.

AnalysisMembers

Case study: the update was signed, and that was the problem

A trusted software update that carried a backdoor, worked as a case. Signing proved the build was the vendor's; it proved nothing about what was in it. Eight questions on detection, scope and the uncomfortable part, which is that nothing your endpoint controls were watching for was wrong.

about 55 minutes of workT1195.002T1071.004T1553.002

Full write-up available to members subscribers. See what is included.

Guided LabMembersConstructed

Guided lab: nine hours at Northwind Freight, from lure to scheduled task

A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.

about 1.5 hours of workT1566.001T1059.001T1003.001

Full write-up available to members subscribers. See what is included.