Test your SOC·Free · no signup · nothing to install·A new technique every week·13 written · 1 live now
Live this week

An intruder erases the record of everything they typed.Does your SOC say a word?

Copy one line. Run it on a machine you own. Then open your alerts and find out something true about your coverage — in about a minute, with nobody watching but you.

Defense evasionT1070.003Windows endpointHardCriticalSeen in Medusa
The whole testT1070.003
Remove-Item (Get-PSReadlineOption).HistorySavePath
01Run it on a box you own~60 sec
02Open your alerts and look~2 min
03Nothing fired? Take the detection ruleon the page
Run this test →
After you run it — did your SOC alert?
One bit, no account, and today it goes no further than this browser: there is nothing behind this page to send it to.
You needA box you own
You getA rule to hand your team
We seeNone of your data

13 techniques, written the same way.

One publishes every week · 1 live now · the rest are written and queued
13 of 13 techniques
Defense evasionT1070.003
Live now

Can your SOC see an erased trail?

Indicator Removal: Clear Command History · seen in Medusa

Delete your own PowerShell history file, then check your alerts

Critical impactHardWindows endpointAbout 60 seconds
Run the test
DiscoveryT1087

Can your SOC see who is asking who lives here?

Account Discovery · seen in Scattered Spider
Medium impactEasyWindows endpoint
Written · queued
DiscoveryT1018

Can your SOC see someone counting the doors?

Remote System Discovery · seen in Conti
Medium impactEasyWindows endpoint
Written · queued
PersistenceT1053.005

Can your SOC see a task quietly schedule itself?

Scheduled Task/Job: Scheduled Task · seen in APT29
High impactModerateWindows endpoint
Written · queued
DiscoveryT1082

Can your SOC see the machine being sized up?

System Information Discovery · seen in Black Basta
Medium impactEasyWindows endpoint
Written · queued
DiscoveryT1057

Can your SOC see someone checking what is running?

Process Discovery · seen in Akira
Medium impactEasyWindows endpoint
Written · queued
DiscoveryT1049

Can your SOC see someone asking where this box is already connected?

System Network Connections Discovery · seen in Volt Typhoon
Medium impactEasyWindows endpoint
Written · queued
DiscoveryT1016

Can your SOC see someone drawing the map?

System Network Configuration Discovery · seen in Lazarus Group
Medium impactEasyWindows endpoint
Written · queued
DiscoveryT1518.001

Can your SOC see someone checking what is watching them?

Software Discovery: Security Software Discovery · seen in MuddyWater
Medium impactEasyWindows endpoint
Written · queued
Defense evasionT1112

Can your SOC see one value quietly written?

Modify Registry · seen in APT41
High impactModerateWindows endpoint
Written · queued
Defense evasionT1027

Can your SOC see a payload wrapped up to look like nothing?

Obfuscated Files or Information · seen in Kimsuky
High impactModerateWindows endpoint
Written · queued
ExecutionT1059.001

Can your SOC see a command that arrives unreadable?

Command and Scripting Interpreter: PowerShell · seen in Turla
High impactEasyWindows endpoint
Written · queued
Credential accessT1552.001

Can your SOC see someone reading what you typed last week?

Unsecured Credentials: Credentials In Files · seen in Fox Kitten
High impactEasyWindows endpoint
Written · queued
What these pages are

Every technique here is public, documented tradecraft — MITRE ATT&CK and the public advisories name it long before we do. Every detection is expressed in Sigma, the open, vendor-neutral format, so your team can translate it into whatever you run.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
Detection logic on these pages is Sigma, and the rules come from the SigmaHQ rule set, used under the Detection Rule License 1.1 — https://github.com/SigmaHQ/Detection-Rule-License
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI