A suspicious Word attachment. Deobfuscate four VBA layers (Chr, StrReverse, XOR, Base64), extract the C2, and write a YARA rule.
A Linux ext4 image from an alleged data theft. Build a mactime timeline, recover deleted files by metadata and by carving, and separate facts from hypotheses.
A Tor Onion service and a clearnet profile publish the same project. Attribute them to one operator via PGP fingerprint, PDF metadata, SHA-256 asset matching and idiolect.
The ORION capstone. Spot a metadata discordance, uncover JavaScript that pdfinfo misses, decode FlateDecode and ASCIIHex+Flate streams, and tie all four labs together.
A weaponised SVG attachment. Find the embedded script, peel back two obfuscation layers, and recover the phishing redirect and the base64-embedded victim tracker.
Triage a StealC-style stealer log: inventory stolen credentials, spot password reuse, find the session cookies that bypass MFA, and drive a prioritised incident response.
Reconstruct a ClickFix (fake-CAPTCHA) incident from Windows logs: read RunMRU, decode the PowerShell -EncodedCommand, follow the fileless cradle in Script Block Logging.
Work a packet capture: find the C2, prove the 30-second beacon, export the downloaded payload, and catch the data-exfiltration POST leaving the host.
Recover a deleted record from a Chrome-style History database: read the live history, carve the free space, and reveal the entry the user tried to erase.
SOC triage over a Windows event export: trace the brute force and account takeover, the persistence and privilege escalation, and the lateral movement, then contain.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.