Investigation Portfolio
Threat Investigations
Structured cyber threat investigations worked end to end in realistic training environments. Each report documents analytical methodology, evidence collection, pivoting, and findings. Investigations are grouped by the platform they originated from. That source determines the kind of evidence available and the tradecraft the investigation demonstrates. These are scenario-based investigations, not real-world client engagements.
View KC7 Profile →
View Darkroom Profile →
Flare Darkroom
·
Investigation
Following a simulated Initial Access Broker investigation in Flare Darkroom and tracing NovaCrest credential exposure back to a third-party compromise.
Cyber Threat Intelligence · Dark Web Intelligence · Initial Access Brokers
9 min read
Flare Darkroom
·
Investigation
Following the NovaCrest investigation through ransomware operations, credential stuffing, account resale, and the underground credential economy.
Ransomware · Ransomware-as-a-Service · Threat Actor Analysis
8 min read
Flare Darkroom
·
Investigation
Correlating an Initial Access Broker across underground forums and examining analyst tradecraft through Flare Darkroom's simulated threat-actor negotiation.
Threat Intelligence · Cross-Forum Intelligence · Threat Actor Analysis
14 min read
KC7 Cyber
·
Investigation
A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to a domain-wide Active Directory...
Insider Threat · Active Directory Ransomware
ATT&CK · 8
9 min read
KC7 Cyber
·
Investigation
Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code exfiltration using raw web...
Critical Infrastructure · Supply Chain
ATT&CK · 8
11 min read
KC7 Cyber
·
Investigation
Part 1 of a two-part, scenario-based investigation into a multi-stage social-engineering campaign against The Valdorian Times. Reconstructs weaponized recruitment lures, scheduled-task persistence, automated plink.exe reverse-SSH tunneling, 7-Zip data archival and...
APT Campaign · Infrastructure Tracking
ATT&CK · 7
8 min read
Part 1 Published
No investigations match your search.