Evidence Lab
Security Cases
Practical investigations that show what was tested, how the attack works, what defenders can observe, and where the evidence still needs improvement. Research candidates identify the next Cases awaiting authorized reproduction.
Case workflow
- 01
Reproduce
Run the attack in an authorized environment.
- 02
Detect
Identify telemetry and portable detections.
- 03
Fix
Apply a patch or defensive control.
- 04
Verify
Prove the control stops the documented attack.
All cases
5cases published

