Observed arrival · 2026-08-31
Security Artifacts turns incident response into a notebook
A DFIR and threat-hunting archive combining incident teardowns, detection engineering, hands-on labs, ATT&CK explainers, and an automated threat wire.
Field notes
The guided labs use staged investigations rather than abstract checklists: readers plant or encounter persistence mechanisms, inspect them through multiple methods, and decide which evidence would survive production conditions. Visible examples include Run keys, scheduled tasks, services, and WMI event subscriptions, each paired with ATT&CK identifiers and Sysmon-oriented tags. A separate Threat Wire is described as aggregating CISA KEV, NIST NVD, and other reporting every six hours; some complete write-ups are reserved for members or subscribers.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue