A structured library of synthetic DFIR incident reports built for analytical framework development, methodology practice, and incident response reasoning.
Reports follow a strict three-layer evidentiary framework:
- [OBS] — Directly observed event from log or artifact
- [INF] — Inferred mechanism with stated basis and rejected alternatives
- [INT] — Assumed attacker intent, explicitly flagged as behavioral inference
| Case ID | Classification | Severity | Status |
|---|---|---|---|
| AD-2024-0891 | Tier-0 Active Directory Compromise | Critical | Complete — v2.0 |
These are synthetic training scenarios built on fictional evidence packages. They are not documentation of real incidents. They exist to develop and stress-test DFIR analytical reasoning, evidentiary discipline, and incident command decision-making.
- Active Directory compromise analysis
- Credential theft and lateral movement (Mimikatz, DCSync, PtH, Overpass-the-Hash)
- Kerberos abuse (Golden Ticket, RC4 downgrade)
- Authentication event analysis (Event IDs 4624, 4662, 4672, 4768, 4769)
- Competing hypothesis analysis
- Blast radius assessment
- KRBTGT rotation methodology
- Containment, eradication, and recovery sequencing
Each report separates:
- What happened (observed facts)
- What probably happened (inferences with confidence levels)
- What cannot be proven (explicitly documented unknowns)
- What evidence would resolve competing hypotheses
Michael Oscar Digital Forensics Investigator | Pentesting | Bug Bounty | Red Team