READ WHAT THE OPERATION LEFT

This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them.

What you get

Explore the
platform.
  • Raw artifacts

    Each item carries the command that collected it and the time it ran.

  • Ground truth

    The operation ledger already holds every command Cracken ran.

  • Retention gaps

    Where a host kept nothing, you find out from an attack you authorized.

  • Host artifact sources

    Covers $MFT, registry hives, event logs, Prefetch, Amcache, Shimcache, shell history, auth logs, journald.

Who this is for

Start testing
  • Red Team Lead

    You want to know what your own operation left behind on the host, so the next one leaves less of it.

  • Detection Engineer

    You need to know which of your rules fired during a run you authorised, and which stayed silent while the technique executed.

  • Security Engineer

    You are tuning host logging and want a run whose actions you already know, to check what the telemetry actually recorded.

Questions

Is this DFIR? Are you competing with incident response vendors?

This playbook starts from an engagement you commissioned and a ledger of every command in it, then reads the host's own account of the same events. The value sits in the difference between the two: what the machine retained, against what actually ran.

Can I point it at a host that was actually compromised?

It reads hosts inside an authorized Cracken operation, where every command that ran is already on the ledger. That known baseline is what makes the host's account checkable — you can see exactly what the machine recorded against what happened.

How is this different from just reading the operation report?

The operation report is Cracken's account of what Cracken did. Host artifact analysis is the machine's account of the same events. The value sits in the difference between the two, because what a host failed to retain does not appear in the report at all.

Start the command record with your first run.

Run an authorized engagement now. The Digital Forensics playbook reads what the hosts recorded of it.