Each report rebuilds the full attack, from how the intruder got in to everything they did next, backed by a complete timeline and MITRE ATT&CK mapping. Investigated by Forge members in our hands-on SOC Simulator, CTF labs, and real phishing samples that hit our inbox.
Nigel Dean traces a py.exe C2 beacon alert on KCD-Web that IOC scoping surfaced as a two-host compromise, with identical Drivers_EveryMinute persistence on both hosts.
Forge members investigate real attacks live in the SOC Simulator, CTF labs, and real phishing samples that land at MYDFIR, then publish their work here. Every report you read is the analyst's own investigation.