AnalysisMembers
A trusted software update that carried a backdoor, worked as a case. Signing proved the build was the vendor's; it proved nothing about what was in it. Eight questions on detection, scope and the uncomfortable part, which is that nothing your endpoint controls were watching for was wrong.
Full write-up available to members subscribers. See what is included.
AnalysisMembers
CL0P against MOVEit Transfer, worked as a case rather than read as news. A zero-day in an internet-facing file transfer product, a web shell, and a scope question that has nothing to do with how many hosts were touched. Nine questions, and the answers are in the advisory.
Full write-up available to members subscribers. See what is included.
AnalysisConstructed
A supplier is out €96,000 and the only endpoint that mattered was wiped on day one, by a helpdesk following the documented process correctly. Here is every artefact that still exists. Work out what you can prove, what you can only say is consistent, and the one collection change that would have moved the most from the second column to the first.
AnalysisMembers
Timestomping is a decision, not an accident, and the decision is visible. NTFS keeps eight timestamps per file and the ordinary Windows API writes four of them. What the other four say about the tool the operator chose, the checklist they were working from, and where they stopped.
Full write-up available to members subscribers. See what is included.
Guided LabMembersConstructed
A business email compromise where the obvious finding is a decoy. Ninety minutes on Microsoft 365 audit logs, OAuth consent grants, and why resetting the password does not end this incident.
Full write-up available to members subscribers. See what is included.
Analysis
Issue one. A control that existed and had been disabled nine weeks earlier, a signup flow that failed silently for anyone behind a VPN, and the retention number that decides whether any of the rest matters.
AnalysisMembersConstructed
A full DFIR report on a constructed ransomware incident, written the way one gets handed to a board. Three hours twenty from first execution to encryption, four separate points where it could have been stopped, and the write-up that follows.
Full write-up available to members subscribers. See what is included.
Guided LabMembersConstructed
A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.
Full write-up available to members subscribers. See what is included.
AnalysisMembers
A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.
Full write-up available to members subscribers. See what is included.