Skip to content
Security ArtifactsDFIR Intelligence
SearchSign inSubscribe
  • Latest
  • Threat Wire
  • Research
  • Learn
    • Start here
    • Labs
    • Case studies
    • ATT&CK index
  • Reference
    • Artifact reference
    • Evidence-gap checker
    • Analyst tools
    • Library
  • Community
  • About

Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to series-cloud.

All1beccloudidentityintermediatelabm365oauthseries-cloudamsiatomic-red-teamattackbeginner
59 more tags
carvingci-cdcisacode-injectioncommand-injectioncredential-accessdetection-engineeringdfirdfir-reportdnseolevtxfilesystemfundamentalsgitgiteahomelabincident-responsekevlateral-movementlockbitlogsmailmethodologymitreno-vmpatch-managementpcappersistencephishingplasopowershellpre-authprivilege-escalationproxmoxransomwareregistryrule-packscheduled-tasksseries-foundationsseries-persistenceseries-reportsservicessigmasleuthkitstatisticssupply-chainsuricatasysmontimelinetunnellingvelociraptorvmvulnerability-managementwindowswmiyarazeekzimbra
Guided LabMembersConstructed

Guided lab: the mailbox rule that was not the point

A business email compromise where the obvious finding is a decoy. Ninety minutes on Microsoft 365 audit logs, OAuth consent grants, and why resetting the password does not end this incident.

1 Sept 2026about 1.5 hours of workT1566.002T1078.004T1114.003labcloudm365bec

Full write-up available to members subscribers. See what is included.

Follow by feed

New articles in your reader, with no email address and nothing that records whether you read them.

How to subscribe

Browse by technique

The same archive arranged by the ATT&CK technique each piece exercises, in kill-chain order, with the gaps shown.

ATT&CK index

Practise it

Reading about a technique and recognising one are different skills. The labs make you generate the artifact yourself.

Guided labs

The Artifact Briefing

One email a week: what actually moved on the wire, and anything new from the lab. Double opt-in, one-click unsubscribe, no tracking pixel.

Sections

  • Start here
  • Research
  • Threat Wire
  • Corrections
  • Labs
  • ATT&CK index
  • Library
  • Community
  • Members Archive
  • Subscriptions

Masthead

  • Masthead
  • Write for us
  • About & contact
  • Community guidelines
  • RSS feed
  • Terms
  • Privacy

Security Artifacts. Digital forensics, incident response, and threat intelligence. © 2026 Maysoon Ammar. All rights reserved. No analytics, no trackers. The only third-party script is the sign-in bot check, loaded on the login page alone.