Real breach investigations, written start to finish.

Each report rebuilds the full attack, from how the intruder got in to everything they did next, backed by a complete timeline and MITRE ATT&CK mapping. Investigated by Forge members in our hands-on SOC Simulator, CTF labs, and real phishing samples that hit our inbox.

A Multi-Host Python C2 Investigation at Kerning City Dental

by: Nigel DeanPublished on: 31/07/2026

Nigel Dean traces a py.exe C2 beacon alert on KCD-Web that IOC scoping surfaced as a two-host compromise, with identical Drivers_EveryMinute persistence on both hosts.

reports
A Multi-Host Python C2 Investigation at Kerning City Dental

0/91 VirusTotal Detections, Still Phishing: The Structural Indicators Every Email Analyst Should Look For

by: Graham McKeanPublished on: 31/07/2026

Graham McKean analyzes a real Shure Media YouTube partnership phishing email received at MYDFIR: 0/91 VirusTotal detections, SPF and DKIM passed, but structural indicators reveal Likely Phishing.

reports
0/91 VirusTotal Detections, Still Phishing: The Structural Indicators Every Email Analyst Should Look For

fodhelper to .akira: A Full-Chain Ransomware Investigation at Kerning City Dental

by: David GilmorePublished on: 31/07/2026

David Gilmore traces a full-chain Akira ransomware attack at Kerning City Dental: CEO phishing to .akira encryption in 3 hours, with 1,184 MEGA POSTs of exfiltrated data along the way.

reports
fodhelper to .akira: A Full-Chain Ransomware Investigation at Kerning City Dental

Path Traversal to Persistence in 100 Minutes: A Meridian Health Systems Patient Portal Compromise

by: Jane UbaPublished on: 12/07/2026

Jane U. traces 100 minutes of an attacker's path through a healthcare patient portal: 18,454 Gobuster requests, LFI via config_viewer.php, and a systemd service named 60.

reports
Path Traversal to Persistence in 100 Minutes: A Meridian Health Systems Patient Portal Compromise

Want to write reports like these?

Forge members investigate real attacks live in the SOC Simulator, CTF labs, and real phishing samples that land at MYDFIR, then publish their work here. Every report you read is the analyst's own investigation.