Investigation Portfolio

Threat Investigations

Structured cyber threat investigations worked end to end in realistic training environments. Each report documents analytical methodology, evidence collection, pivoting, and findings. Investigations are grouped by the platform they originated from. That source determines the kind of evidence available and the tradecraft the investigation demonstrates. These are scenario-based investigations, not real-world client engagements.

View KC7 Profile → View Darkroom Profile →

KC7 Cyber Investigation

Inside Encryptodera: An Insider Threat Scenario

A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to a domain-wide Active Directory...

Insider Threat · Active Directory Ransomware

ATT&CK · 8 9 min read

KC7 Cyber Investigation

Solvi Systems: A tale of Supply Chains and ICS

Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code exfiltration using raw web...

Critical Infrastructure · Supply Chain

ATT&CK · 8 11 min read

KC7 Cyber Investigation

Valdoria Votes: Advanced Persistent Threat Analysis

Part 1 of a two-part, scenario-based investigation into a multi-stage social-engineering campaign against The Valdorian Times. Reconstructs weaponized recruitment lures, scheduled-task persistence, automated plink.exe reverse-SSH tunneling, 7-Zip data archival and...

APT Campaign · Infrastructure Tracking

ATT&CK · 7 8 min read Part 1 Published