Insights · Archive

All posts

Tactical blueprints, real-world DFIR case studies, and practical security lessons learned from the field.

Start here

ICS / OT 15 Jun 2026

A cyber-physical testbed for smart-grid and digital-substation security research

A case study on designing and building a realistic, closed-loop smart-grid cybersecurity testbed for a research institute — the requirement, the design approach, what was delivered, and why it matters for the people who keep the grid running. Implementation specifics are deliberately withheld.

By Cyberange Phygital Labs

Adversary emulation 27 May 2026

Inside a 90-day red team op against a tier-1 Indian airport operator

A redacted case study mapping a 13-week journey from an external foothold to full Active Directory compromise. Discover how the operator adapted tactics on the fly and what forensic artifacts survived a rigorous CERT-In post-incident review.

By Cyberange Adaptive Red Team

ICS / OT 26 May 2026

Why we ship real PLCs, not software emulators

A short practice note on the difference between a simulator and a range, and why the difference compounds in operator training, regulator-grade demonstrations, and live red-team engagements.

By Cyberange Phygital Labs

DFIR 14 Sep 2024

One letter off: how a look-alike domain and a stolen signature ran a 30-day invoice fraud

A new analyst, a trusted client, and an email that arrived at 5:45 on a Monday morning. The story of a business email compromise that turned on a single swapped character — and the forensic trail that survived a year of silence and a lawyer's denial.

By Cyberange DFIR Team

DFIR 14 May 2024

Anatomy of a ransomware breach: from one exposed RDP port to domain-wide encryption in 72 hours

A sanitized DFIR debrief of a ransomware intrusion at a large Indian manufacturer. We reconstruct the timeline from a misconfigured firewall rule and a brute-forced RDP login through Mimikatz, AV removal, PsExec lateral movement, and full-estate encryption — and the anti-forensics that nearly erased the trail.

By Cyberange DFIR Team

DFIR 14 Apr 2022

Just a marketing website: how a neglected WordPress site became a path to Domain Admin

It came in as a spam complaint. It ended at a forgotten brochure website wired into the company's domain controller, with the Domain Admin password sitting in a script on someone's desktop. A story about the assets nobody thinks are worth attacking.

By Cyberange DFIR Team

DFIR 26 May 2026

The CERT-In six-hour window: what your DFIR runbook needs to say

CERT-In Direction 70B (April 2022) requires reporting of certain cyber incidents within six hours of detection. A practical breakdown of what the clock actually measures, what your runbook needs to include, and where most organisations get the timeline wrong.

By Cyberange DFIR Consulting

Threat intelligence 17 Apr 2026

Browser-based initial access in 2026

The fastest-growing initial-access surface in the engagement data is the browser session, not the credential. Reverse-proxy phishing kits, OAuth consent abuse, extension supply-chain hijacks, and infostealer-fed cookie marketplaces — what changed, why MFA and password rotation no longer cover the dominant case, and which controls actually move the curve.

By Cyberange Threat Intel