Skip to content
Security ArtifactsDFIR Intelligence
SearchSign inSubscribe
  • Latest
  • Threat Wire
  • Research
  • Learn
    • Start here
    • Labs
    • Case studies
    • ATT&CK index
  • Reference
    • Artifact reference
    • Evidence-gap checker
    • Analyst tools
    • Library
  • Community
  • About

Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to vm.

All1beginnercarvingfilesystemlabseries-foundationssleuthkitvmamsiatomic-red-teamattackbecci-cd
59 more tags
cisacloudcode-injectioncommand-injectioncredential-accessdetection-engineeringdfirdfir-reportdnseolevtxfundamentalsgitgiteahomelabidentityincident-responseintermediatekevlateral-movementlockbitlogsm365mailmethodologymitreno-vmoauthpatch-managementpcappersistencephishingplasopowershellpre-authprivilege-escalationproxmoxransomwareregistryrule-packscheduled-tasksseries-cloudseries-persistenceseries-reportsservicessigmastatisticssupply-chainsuricatasysmontimelinetunnellingvelociraptorvulnerability-managementwindowswmiyarazeekzimbra
Guided Lab

Guided lab: build a disk image, then take it apart

The first lab for a machine of your own. You create the evidence yourself, delete a file from it, and then recover the file you deleted, which is the only way to be certain the recovery worked.

1 Sept 2026about 20 minutes of workT1070.004labvmsleuthkitfilesystem

Follow by feed

New articles in your reader, with no email address and nothing that records whether you read them.

How to subscribe

Browse by technique

The same archive arranged by the ATT&CK technique each piece exercises, in kill-chain order, with the gaps shown.

ATT&CK index

Practise it

Reading about a technique and recognising one are different skills. The labs make you generate the artifact yourself.

Guided labs

The Artifact Briefing

One email a week: what actually moved on the wire, and anything new from the lab. Double opt-in, one-click unsubscribe, no tracking pixel.

Sections

  • Start here
  • Research
  • Threat Wire
  • Corrections
  • Labs
  • ATT&CK index
  • Library
  • Community
  • Members Archive
  • Subscriptions

Masthead

  • Masthead
  • Write for us
  • About & contact
  • Community guidelines
  • RSS feed
  • Terms
  • Privacy

Security Artifacts. Digital forensics, incident response, and threat intelligence. © 2026 Maysoon Ammar. All rights reserved. No analytics, no trackers. The only third-party script is the sign-in bot check, loaded on the login page alone.