CASE-004SOC//LIFE
Security analysis, explained.
Real-world attack behavior turned into investigations, detections, and threat hunts.
Explore
Choose a path
Follow an investigation, see how its behavior can be detected, then search for the same activity elsewhere.
Recent work
Start with an analysis
Each entry connects the initial question to the evidence and conclusion.
Cases Cases CASE-005High-Risk User Reveals Device Code Phishing
A User Risk alert led to a successful device-code authentication that matched Microsoft's 2026 phishing tradecraft, shifting the investigation from password theft to attacker-controlled OAuth token acquisition.Cases CASE-006SSPR Abuse Turns a Cloud Identity into an Azure Breach
Social-engineered SSPR let an attacker replace MFA methods, take over a cloud identity, enumerate Microsoft Graph, attempt service-principal persistence, and expand into Azure.Cases CASE-007Teams Helpdesk Impersonation Leads to Remote Access
An external Teams helpdesk persona convinced a user to launch Quick Assist, leading to shell execution, WinRM lateral movement, alternate RMM, and Rclone exfiltration.