READ WHAT THE OPERATION LEFT
This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them.
What you get
platform.
Raw artifacts
Each item carries the command that collected it and the time it ran.
Ground truth
The operation ledger already holds every command Cracken ran.
Retention gaps
Where a host kept nothing, you find out from an attack you authorized.
Host artifact sources
Covers $MFT, registry hives, event logs, Prefetch, Amcache, Shimcache, shell history, auth logs, journald.
Where it stops
It reads the host side of operations Cracken itself ran, under the authorization that covered them.
It does not investigate a real breach
There is no unknown adversary here — the operation is one you commissioned.
It does not perform live response. No isolation, no containment, no eradication, no recovery
It does not produce court-admissible evidence
No chain of custody, no forensic imaging, no expert testimony.
It does not attribute activity to a threat actor
It does not do memory forensics or full-disk imaging
Who this is for
Start testingRed Team Lead
You want to know what your own operation left behind on the host, so the next one leaves less of it.
Detection Engineer
You need to know which of your rules fired during a run you authorised, and which stayed silent while the technique executed.
Security Engineer
You are tuning host logging and want a run whose actions you already know, to check what the telemetry actually recorded.
Questions
Is this DFIR? Are you competing with incident response vendors?
The Digital Forensics playbook is not incident response. Incident response begins with an unknown intrusion and a containment decision; this playbook begins with an engagement you commissioned and a ledger of every command in it. Cracken validates exposure and does not remediate.
Can I point it at a host that was actually compromised?
No. The Digital Forensics playbook is scoped to hosts inside an authorized Cracken operation. A machine touched by a real intruder needs an incident response team and an evidence-handling process Cracken does not provide.
How is this different from just reading the operation report?
The operation report is Cracken's account of what Cracken did. Host artifact analysis is the machine's account of the same events. The value sits in the difference between the two, because what a host failed to retain does not appear in the report at all.
Start the command record with your first run.
Run an authorized engagement now. The Digital Forensics playbook reads what the hosts recorded of it.





