Real breach investigations, written start to finish.

Each report rebuilds the full attack, from how the intruder got in to everything they did next, backed by a complete timeline and MITRE ATT&CK mapping. Investigated by Forge members in our hands-on SOC Simulator, CTF labs, and real phishing samples that hit our inbox.

fodhelper to .akira: A Full-Chain Ransomware Investigation at Kerning City Dental

by: David GilmorePublished on: 31/07/2026

David Gilmore traces a full-chain Akira ransomware attack at Kerning City Dental: CEO phishing to .akira encryption in 3 hours, with 1,184 MEGA POSTs of exfiltrated data along the way.

reports
fodhelper to .akira: A Full-Chain Ransomware Investigation at Kerning City Dental

Want to write reports like these?

Forge members investigate real attacks live in the SOC Simulator, CTF labs, and real phishing samples that land at MYDFIR, then publish their work here. Every report you read is the analyst's own investigation.