Technical Case Notes

Investigation scenarios and lessons

These notes describe common investigation patterns and lessons. Hypothetical scenarios sit alongside verified anonymised cases. Identifying details are removed. They are not customer case studies.

Incident ResponseVerified anonymised case

Ransomware After Exposed Remote Access

Ransomware encrypted a workstation after attackers brute-forced an internet-exposed remote desktop and a shared administrative account. A line-of-business server was planted with the same malware but never restarted, so encryption never ran there. Backups, not antivirus, prevented operational collapse.

Read the case note
Web SecurityHypothetical scenario

Compromised Web Application

A web application began serving unexpected content. Investigation revealed a web shell, credential theft, and lateral movement to internal systems — not merely a defacement.

Identity & AccessHypothetical scenario

Credential Abuse Investigation

Unusual login patterns from multiple geographic locations suggested account compromise. Timeline reconstruction connected the activity to a phishing campaign weeks earlier.

MalwareHypothetical scenario

Malware Persistence Investigation

Endpoint alerts flagged suspicious executables. Analysis revealed scheduled task persistence, command-and-control communication, and evidence of data staging.

Incident ResponseHypothetical scenario

Suspicious Administrative Access

Administrative actions on cloud infrastructure did not match normal operational patterns. Investigation traced access to a compromised service account with excessive permissions.

Data SecurityHypothetical scenario

Sensitive Data Exposure Investigation

A misconfigured cloud storage bucket exposed internal documents. Scope assessment determined what data was accessible, for how long, and whether unauthorized access occurred.

Insider ThreatsHypothetical scenario

Insider Threat Investigation

Unusual data access patterns preceded an employee's departure. Log correlation revealed systematic access to sensitive repositories outside normal role requirements.