Structured investigation writeups from security incidents and threat research scenarios.
Each report covers:
- Timeline — chronological attacker actions
- IOCs — IPs, hashes, domains, user-agents
- MITRE ATT&CK chain — techniques observed
- Detection logic — what fired and why
- Remediation — response recommendations
| Date | Title | Techniques | Severity |
|---|---|---|---|
| 2026-07-11 | SSH Brute Force to Credential Access | T1110.001, T1078 | Medium |
YYYY-MM-DD-short-description.md