Test your SOC·Free · no signup · nothing to install·A new technique every week·13 written · 13 live now
Live this week

An intruder erases the record of everything they typed.Does your SOC say a word?

Copy one line. Run it on a machine you own. Then open your alerts and find out something true about your coverage — in about a minute, with nobody watching but you.

Defense evasionT1070.003Windows endpointHardCriticalSeen in Medusa
The whole testT1070.003
Remove-Item (Get-PSReadlineOption).HistorySavePath
01Run it on a box you own~60 sec
02Open your alerts and look~2 min
03Nothing fired? Take the detection ruleon the page
Run this test →
After you run it — did your SOC alert?
One bit, no account, and today it goes no further than this browser: there is nothing behind this page to send it to.
You needA box you own
You getA rule to hand your team
We seeNone of your data

13 techniques, written the same way.

One publishes every week · 13 live now · every one written is live
13 of 13 techniques
Defense evasionT1070.003
Live now

Can your SOC see an erased trail?

Indicator Removal: Clear Command History · seen in Medusa

Delete your own PowerShell history file, then check your alerts

Critical impactHardWindows endpointAbout 60 seconds
Run the test
DiscoveryT1087
Live now

Can your SOC see who is asking who lives here?

Account Discovery · seen in Scattered Spider

Run net user and whoami /all to list local accounts

Medium impactEasyWindows endpointAbout a minute
Run the test
DiscoveryT1018
Live now

Can your SOC see someone counting the doors?

Remote System Discovery · seen in Conti

Run net view to enumerate reachable shares and sessions

Medium impactEasyWindows endpointAbout a minute
Run the test
PersistenceT1053.005
Live now

Can your SOC see a task quietly schedule itself?

Scheduled Task/Job: Scheduled Task · seen in APT29

Create a harmless scheduled task with schtasks, then delete it

High impactModerateWindows endpointAbout a minute
Run the test
DiscoveryT1082
Live now

Can your SOC see the machine being sized up?

System Information Discovery · seen in Black Basta

Run systeminfo to read the machine's full specification

Medium impactEasyWindows endpointAbout a minute
Run the test
DiscoveryT1057
Live now

Can your SOC see someone checking what is running?

Process Discovery · seen in Akira

Pipe tasklist into findstr to filter the running process list

Medium impactEasyWindows endpointAbout a minute
Run the test
DiscoveryT1049
Live now

Can your SOC see someone asking where this box is already connected?

System Network Connections Discovery · seen in Volt Typhoon

Run net use to list connections this machine already holds

Medium impactEasyWindows endpointAbout a minute
Run the test
DiscoveryT1016
Live now

Can your SOC see someone drawing the map?

System Network Configuration Discovery · seen in Lazarus Group

Run ipconfig /all, arp -a and route print

Medium impactEasyWindows endpointAbout a minute
Run the test
DiscoveryT1518.001
Live now

Can your SOC see someone checking what is watching them?

Software Discovery: Security Software Discovery · seen in MuddyWater

Filter the process list for the name of a security product

Medium impactEasyWindows endpointAbout a minute
Run the test
Defense evasionT1112
Live now

Can your SOC see one value quietly written?

Modify Registry · seen in APT41

Import a one-value registry file with reg import, then delete it

High impactModerateWindows endpointAbout a minute
Run the test
Defense evasionT1027
Live now

Can your SOC see a payload wrapped up to look like nothing?

Obfuscated Files or Information · seen in Kimsuky

Encode a harmless file to base64 with certutil, then delete both

High impactModerateWindows endpointAbout a minute
Run the test
ExecutionT1059.001
Live now

Can your SOC see a command that arrives unreadable?

Command and Scripting Interpreter: PowerShell · seen in Turla

Run a PowerShell command line that decodes its own base64 string

High impactEasyWindows endpointAbout a minute
Run the test
Credential accessT1552.001
Live now

Can your SOC see someone reading what you typed last week?

Unsecured Credentials: Credentials In Files · seen in Fox Kitten

Read the last lines of your own PowerShell console history

High impactEasyWindows endpointAbout a minute
Run the test
What these pages are

Every technique here is public, documented tradecraft — MITRE ATT&CK and the public advisories name it long before we do. Every detection is expressed in Sigma, the open, vendor-neutral format, so your team can translate it into whatever you run.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
Detection logic on these pages is Sigma, and the rules come from the SigmaHQ rule set, used under the Detection Rule License 1.1 — https://github.com/SigmaHQ/Detection-Rule-License
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI