Skip to content
Security ArtifactsDFIR Intelligence
SearchSign inSubscribe
  • Latest
  • Threat Wire
  • Research
  • Observations
  • Learn
    • Start here
    • Labs
    • Case studies
    • ATT&CK index
  • Desk
    • Triage collection
    • First-hour playbooks
    • Hardening guides
    • Event IDs
    • Metrics
    • The framework
  • Reference
    • Artifact reference
    • Evidence-gap checker
    • Analyst tools
    • Library
  • Community
  • About

Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to metrics.

All1detection-engineeringincident-responsemetricsseries-observationsamsiatomic-red-teamattackbecbeginnercarvingci-cdcisa
61 more tags
cloudcode-injectioncommand-injectioncredential-accessdfirdfir-reportdnseolevtxfilesystemfundamentalsgitgiteahomelabidentityintermediatekevlablateral-movementlockbitlogsm365mailmethodologymitreno-vmoauthpatch-managementpcappersistencephishingplasopowershellpre-authprivilege-escalationproxmoxransomwareregistryrule-packscheduled-tasksseries-cloudseries-foundationsseries-persistenceseries-reportsservicessigmasleuthkitstatisticssupply-chainsuricatasysmontimelinetunnellingvelociraptorvmvulnerability-managementwindowswmiyarazeekzimbra
Analysis

The detection that was switched off in March

Issue one. A control that existed and had been disabled nine weeks earlier, a signup flow that failed silently for anyone behind a VPN, and the retention number that decides whether any of the rest matters.

1 Sept 20263 min readT1490series-observationsincident-responsedetection-engineeringmetrics

Follow by feed

New articles in your reader, with no email address and nothing that records whether you read them.

How to subscribe

Browse by technique

The same archive arranged by the ATT&CK technique each piece exercises, in kill-chain order, with the gaps shown.

ATT&CK index

Practise it

Reading about a technique and recognising one are different skills. The labs make you generate the artifact yourself.

Guided labs

The Artifact Briefing

One email a week: what actually moved on the wire, and anything new from the lab. Double opt-in, one-click unsubscribe, no tracking pixel.

Sections

  • Start here
  • Research
  • Threat Wire
  • Corrections
  • Labs
  • ATT&CK index
  • Library
  • Community
  • Members Archive
  • Subscriptions

Masthead

  • Masthead
  • Write for us
  • About & contact
  • Community guidelines
  • RSS feed
  • Terms
  • Privacy

Security Artifacts. Digital forensics, incident response, and threat intelligence. © 2026 Maysoon Ammar. All rights reserved. No analytics, no trackers. The only third-party script is the sign-in bot check, loaded on the login page alone.