Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

DFIR dossierlogo

IncidentDossier

Evidence-led DFIR and SOC case studies developed from hands-on investigations in controlled lab environments. These are educational simulations, not production incidents.

Each report separates observed evidence from analyst assessment and documents scope, investigative reasoning, technical findings, confidence, impact, response actions, and remaining limitations.

Featured Investigations

Case Why it is featured Skills demonstrated
Jinkies Reconstructs a Windows workstation compromise and likely intellectual-property theft across multiple artifact sources KAPE triage, Registry, $MFT, Windows events, Sysmon, browser history, credential analysis
Recollection Uses volatile evidence to reconstruct malicious PowerShell activity, malware execution, and an attempted file transfer Volatility, process relationships, console history, clipboard analysis, memory forensics
Unit42 Follows a masqueraded download through execution, MSI staging, timestomping, and cleanup Sysmon analysis, process chains, network telemetry, ATT&CK mapping, detection opportunities
PhantomRing Profiles a Linux implant while carefully separating embedded capability from observed execution ELF static analysis, io_uring, anti-eBPF behavior, C2 and detection engineering

Investigation Collection

Case Domain Focus
Brutus DFIR · Log Analysis Linux authentication and persistence
Campfire-1 SOC · Log Analysis Windows event logs, Prefetch, and Kerberoasting
Jinkies DFIR · Incident Response Windows endpoint compromise and data theft
LogJammer SOC · Threat Detection Windows logs, persistence, and defense evasion
PhantomRing Threat Analysis · Malware Static analysis of a Linux implant
Recollection DFIR · Memory Forensics Windows memory analysis and malicious PowerShell
ReliableThreat DFIR · Threat Analysis Windows memory, disk artifacts, and persistence
RogueOne DFIR · Memory Forensics Malicious process and C2 investigation
Tracer DFIR · Log Analysis Windows artifacts, PsExec, and lateral movement
Trojan DFIR · Malware Memory, disk, and network forensics
Unit42 SOC · Threat Detection Sysmon analysis and malicious execution

Reporting Standard

The investigations use a consistent professional structure:

  1. Define the scope, available artifacts, time standard, and evidence limitations.
  2. Distinguish facts observed in the evidence from hypotheses and external enrichment.
  3. Reconstruct the incident narrative and normalized UTC timeline.
  4. Record indicators, affected assets, confidence, impact, and ATT&CK mappings where supported.
  5. Recommend containment, eradication, recovery, and detection improvements.
  6. Link material findings back to their supporting artifacts.

New investigations should use the full investigation template. Short-form alert decisions will be added under SOC triage using the SOC triage template.

Evidence and Scenario Disclosure

  • The current cases are based on Hack The Box Sherlocks and other controlled lab material.
  • Report text, analysis, timelines, and conclusions are the portfolio work presented here.
  • Source-provided artifacts, screenshots, walkthrough material, and product names remain third-party material and are identified when used.
  • An external reputation result or walkthrough statement is treated as enrichment, not as independent host evidence.
  • A capability, attempted action, or suspicious indicator is not described as successful impact unless the available evidence supports that conclusion.

Spoiler notice: The reports contain findings and solutions for their respective simulated scenarios, including Hack The Box Sherlocks.

About

Evidence-led DFIR case studies with timelines, technical findings, IOCs, ATT&CK mapping, and response recommendations.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors