CASE-001SOC analysis
Cases
Follow the investigation.
Reviewed work
Explore cases
Open an entry to follow its evidence, reasoning, and limits.
Cases Cases CASE-002ClickFix Prompt Leads to Remote Access
A compromised website led to Run-dialog execution, remote HTA retrieval, silent MSI installation, persistence, and a remote-access foothold.Cases CASE-003Trusted SharePoint Link Leads to Session Hijack and BEC
A trusted SharePoint lure led to AiTM session theft, mailbox concealment, and follow-on phishing from the compromised identity.Cases CASE-004OAuth Consent Grant Gives a Third-Party App Persistent Access
A legitimate Microsoft consent screen was abused to authorize an unverified third-party application, creating persistent cloud access that password-only remediation would not remove.Cases CASE-005High-Risk User Reveals Device Code Phishing
A User Risk alert led to a successful device-code authentication that matched Microsoft's 2026 phishing tradecraft, shifting the investigation from password theft to attacker-controlled OAuth token acquisition.Cases CASE-006SSPR Abuse Turns a Cloud Identity into an Azure Breach
Social-engineered SSPR let an attacker replace MFA methods, take over a cloud identity, enumerate Microsoft Graph, attempt service-principal persistence, and expand into Azure.Cases CASE-007Teams Helpdesk Impersonation Leads to Remote Access
An external Teams helpdesk persona convinced a user to launch Quick Assist, leading to shell execution, WinRM lateral movement, alternate RMM, and Rclone exfiltration.Cases CASE-008Photo ZIP Lure Leads to Persistent Node JS Access
A hospitality phishing lure delivered a fake image shortcut that launched PowerShell, staged a user-space Node JS implant, altered Defender exclusions, and established dual registry persistence.