Skip to content
Security ArtifactsDFIR Intelligence
SearchSign inSubscribe
  • Latest
  • Threat Wire
  • Research
  • Observations
  • Learn
    • Start here
    • Labs
    • Case studies
    • SOC tabletop
    • ATT&CK index
  • Desk
    • Triage collection
    • Rule packs and sheets
    • First-hour playbooks
    • Hardening guides
    • Event IDs
    • Metrics
    • The framework
  • Reference
    • Artifact reference
    • Evidence-gap checker
    • Analyst tools
    • Library
  • For teams
  • Community
  • About

Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics.

Behavioral TradecraftFalse-Positive Hall of FameEvidence Gap Challenge

A scenario with something deliberately missing. You work out what you cannot prove and what you would have needed to collect, then compare with everyone else who tried.

All0amsiatomic-red-teamattackbecbeginnercarvingci-cdcisacloudcode-injectioncommand-injectioncredential-access
63 more tags
detection-engineeringdfirdfir-reportdnsentra-ideolevtxfilesystemfundamentalsgitgiteahomelabidentityincident-responseintermediatekevlablateral-movementlockbitlogsm365mailmethodologymetricsmitreno-vmoauthoktapatch-managementpcappersistencephishingplasopowershellpre-authprivilege-escalationproxmoxransomwareregistryrule-packscheduled-tasksseries-cloudseries-foundationsseries-observationsseries-persistenceseries-reportsservicessigmasleuthkitstatisticssupply-chainsuricatasysmontimelinetunnellingvelociraptorvmvulnerability-managementwindowswmiyarazeekzimbra

Nothing filed under evidence-gap-challenge. Show everything.

Follow by feed

New articles in your reader, with no email address and nothing that records whether you read them.

How to subscribe

Browse by technique

The same archive arranged by the ATT&CK technique each piece exercises, in kill-chain order, with the gaps shown.

ATT&CK index

Practise it

Reading about a technique and recognising one are different skills. The labs make you generate the artifact yourself.

Guided labs

The Artifact Briefing

One email a week: what actually moved on the wire, and anything new from the lab. Double opt-in, one-click unsubscribe, no tracking pixel.

Sections

  • Start here
  • Research
  • Threat Wire
  • Corrections
  • Labs
  • ATT&CK index
  • Library
  • Community
  • Members Archive
  • Subscriptions

Masthead

  • Masthead
  • Write for us
  • About & contact
  • Community guidelines
  • RSS feed
  • Terms
  • Privacy

Security Artifacts. Digital forensics, incident response, and threat intelligence. © 2026 Maysoon Ammar. All rights reserved. No analytics, no trackers. The only third-party script is the sign-in bot check, loaded on the login page alone.