READ WHAT THE OPERATION LEFT

This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them.

What you get

Explore the
platform.
  • Raw artifacts

    Each item carries the command that collected it and the time it ran.

  • Ground truth

    The operation ledger already holds every command Cracken ran.

  • Retention gaps

    Where a host kept nothing, you find out from an attack you authorized.

  • Host artifact sources

    Covers $MFT, registry hives, event logs, Prefetch, Amcache, Shimcache, shell history, auth logs, journald.

Where it stops

It reads the host side of operations Cracken itself ran, under the authorization that covered them.

  • It does not investigate a real breach

    There is no unknown adversary here the operation is one you commissioned.

  • It does not perform live response. No isolation, no containment, no eradication, no recovery

  • It does not produce court-admissible evidence

    No chain of custody, no forensic imaging, no expert testimony.

  • It does not attribute activity to a threat actor

  • It does not do memory forensics or full-disk imaging

Who this is for

Start testing
  • Red Team Lead

    You want to know what your own operation left behind on the host, so the next one leaves less of it.

  • Detection Engineer

    You need to know which of your rules fired during a run you authorised, and which stayed silent while the technique executed.

  • Security Engineer

    You are tuning host logging and want a run whose actions you already know, to check what the telemetry actually recorded.

Questions

Is this DFIR? Are you competing with incident response vendors?

The Digital Forensics playbook is not incident response. Incident response begins with an unknown intrusion and a containment decision; this playbook begins with an engagement you commissioned and a ledger of every command in it. Cracken validates exposure and does not remediate.

Can I point it at a host that was actually compromised?

No. The Digital Forensics playbook is scoped to hosts inside an authorized Cracken operation. A machine touched by a real intruder needs an incident response team and an evidence-handling process Cracken does not provide.

How is this different from just reading the operation report?

The operation report is Cracken's account of what Cracken did. Host artifact analysis is the machine's account of the same events. The value sits in the difference between the two, because what a host failed to retain does not appear in the report at all.

Start the command record with your first run.

Run an authorized engagement now. The Digital Forensics playbook reads what the hosts recorded of it.