READ WHAT THE OPERATION LEFT
This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them.
What you get
platform.
Raw artifacts
Each item carries the command that collected it and the time it ran.
Ground truth
The operation ledger already holds every command Cracken ran.
Retention gaps
Where a host kept nothing, you find out from an attack you authorized.
Host artifact sources
Covers $MFT, registry hives, event logs, Prefetch, Amcache, Shimcache, shell history, auth logs, journald.
Who this is for
Start testingRed Team Lead
You want to know what your own operation left behind on the host, so the next one leaves less of it.
Detection Engineer
You need to know which of your rules fired during a run you authorised, and which stayed silent while the technique executed.
Security Engineer
You are tuning host logging and want a run whose actions you already know, to check what the telemetry actually recorded.
Questions
Is this DFIR? Are you competing with incident response vendors?
This playbook starts from an engagement you commissioned and a ledger of every command in it, then reads the host's own account of the same events. The value sits in the difference between the two: what the machine retained, against what actually ran.
Can I point it at a host that was actually compromised?
It reads hosts inside an authorized Cracken operation, where every command that ran is already on the ledger. That known baseline is what makes the host's account checkable — you can see exactly what the machine recorded against what happened.
How is this different from just reading the operation report?
The operation report is Cracken's account of what Cracken did. Host artifact analysis is the machine's account of the same events. The value sits in the difference between the two, because what a host failed to retain does not appear in the report at all.
Start the command record with your first run.
Run an authorized engagement now. The Digital Forensics playbook reads what the hosts recorded of it.





