Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

DFIR Case Studies

A structured library of synthetic DFIR incident reports built for analytical framework development, methodology practice, and incident response reasoning.

Reports follow a strict three-layer evidentiary framework:

  • [OBS] — Directly observed event from log or artifact
  • [INF] — Inferred mechanism with stated basis and rejected alternatives
  • [INT] — Assumed attacker intent, explicitly flagged as behavioral inference

Cases

Case ID Classification Severity Status
AD-2024-0891 Tier-0 Active Directory Compromise Critical Complete — v2.0

What This Repository Is

These are synthetic training scenarios built on fictional evidence packages. They are not documentation of real incidents. They exist to develop and stress-test DFIR analytical reasoning, evidentiary discipline, and incident command decision-making.


Topics Covered

  • Active Directory compromise analysis
  • Credential theft and lateral movement (Mimikatz, DCSync, PtH, Overpass-the-Hash)
  • Kerberos abuse (Golden Ticket, RC4 downgrade)
  • Authentication event analysis (Event IDs 4624, 4662, 4672, 4768, 4769)
  • Competing hypothesis analysis
  • Blast radius assessment
  • KRBTGT rotation methodology
  • Containment, eradication, and recovery sequencing

Methodology Reference

Each report separates:

  1. What happened (observed facts)
  2. What probably happened (inferences with confidence levels)
  3. What cannot be proven (explicitly documented unknowns)
  4. What evidence would resolve competing hypotheses

Author

Michael Oscar Digital Forensics Investigator | Pentesting | Bug Bounty | Red Team

About

Synthetic DFIR incident reports and adversary emulation scenarios for analytical framework development

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors