Reference

What to open mid-case

Four things, and each answers a different question. If you are working something right now, the second one is probably where to start.

“What does this artifact actually prove?”

Artifact reference

Where 14 Windows artifacts live, what each one establishes, and what it does not. That second half is the reason it exists: most references stop at what an artifact shows, which is how “Shimcache proves execution” became the most repeated mistake in the field.

6 categories, from execution to anti-forensics. 4 free to read.

“What should I collect, and what is expiring?”

Evidence-gap checker

Pick what you are trying to establish and get the sources that would establish it, in collection order, with the volatile ones first. Each one also names the trap: the source people reach for that does not settle the question.

8 hypotheses, free to use

“What is this timestamp, and is this link safe?”

Analyst tools

Timestamp conversion, defanging, and link checks. Everything runs in your browser and nothing is sent anywhere, which is the point: the paste-it-into-a-website tools you reach for during an incident are the ones you should not paste evidence into.

Free, no account

“Where do I get tools, feeds and practice data?”

Library

Advisories worth reading as they publish, the tooling to have installed before you need it, and public datasets to practise on. Other people’s work, collected because it is good, not because we made it.

Free, no account

for teams

The Threat Wire is also available as an API, in JSON, CSV or STIX 2.1, for pulling into a SOAR playbook or a dashboard. The documentation is public, including the rate limits and the error codes, so you can plan a pipeline before buying anything.

not sure which?

If you have a host in front of you and a question about it, start with the evidence-gap checker: it will hand you a collection list and link into the reference for each item. If you have already collected and want to know what a finding means, go straight to the artifact reference.

Learning rather than working? Start here instead.