Skip to content
Security ArtifactsDFIR Intelligence
SearchSign inSubscribe
  • Latest
  • Threat Wire
  • Research
  • Observations
  • Learn
    • Start here
    • Labs
    • Case studies
    • SOC tabletop
    • ATT&CK index
  • Desk
    • Triage collection
    • Rule packs and sheets
    • First-hour playbooks
    • Hardening guides
    • Event IDs
    • Metrics
    • The framework
  • Reference
    • Artifact reference
    • Evidence-gap checker
    • Analyst tools
    • Library
  • For teams
  • Community
  • About

Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to okta.

Behavioral TradecraftFalse-Positive Hall of FameEvidence Gap Challenge
All1detection-engineeringentra-ididentityoktarule-packsigmaamsiatomic-red-teamattackbecbeginnercarving
63 more tags
ci-cdcisacloudcode-injectioncommand-injectioncredential-accessdfirdfir-reportdnseolevtxfilesystemfundamentalsgitgiteahomelabincident-responseintermediatekevlablateral-movementlockbitlogsm365mailmethodologymetricsmitreno-vmoauthpatch-managementpcappersistencephishingplasopowershellpre-authprivilege-escalationproxmoxransomwareregistryscheduled-tasksseries-cloudseries-foundationsseries-observationsseries-persistenceseries-reportsservicessleuthkitstatisticssupply-chainsuricatasysmontimelinetunnellingvelociraptorvmvulnerability-managementwindowswmiyarazeekzimbra
Rule PackMembers

Cloud identity and token theft detection pack — Entra ID and Okta

Four Sigma rules for the cloud identity attacks that actually land: illicit consent grants, authentication methods added after a risky sign-in, help-desk MFA resets, and session tokens replayed from a second address.

3 Sept 20261 min readT1078.004T1556.006T1550.001sigmadetection-engineeringrule-packentra-id

Full write-up available to members subscribers. See what is included.

Follow by feed

New articles in your reader, with no email address and nothing that records whether you read them.

How to subscribe

Browse by technique

The same archive arranged by the ATT&CK technique each piece exercises, in kill-chain order, with the gaps shown.

ATT&CK index

Practise it

Reading about a technique and recognising one are different skills. The labs make you generate the artifact yourself.

Guided labs

The Artifact Briefing

One email a week: what actually moved on the wire, and anything new from the lab. Double opt-in, one-click unsubscribe, no tracking pixel.

Sections

  • Start here
  • Research
  • Threat Wire
  • Corrections
  • Labs
  • ATT&CK index
  • Library
  • Community
  • Members Archive
  • Subscriptions

Masthead

  • Masthead
  • Write for us
  • About & contact
  • Community guidelines
  • RSS feed
  • Terms
  • Privacy

Security Artifacts. Digital forensics, incident response, and threat intelligence. © 2026 Maysoon Ammar. All rights reserved. No analytics, no trackers. The only third-party script is the sign-in bot check, loaded on the login page alone.