The Lab
Interactive simulations built to accompany each article. Dark web markets, IRC sessions, hardware tools, ransomware screens, phishing emails, social engineering calls - run them in your browser and read the analyst notes alongside.
Nine artifacts - PGP source, a t-shirt with RSA on it, a 40-bit key. Guess which ones were arms trafficking to export under 1990s law. You will get some wrong, which is the point.
Pick an adversary - opportunist, stalker, police, nation-state - and watch which privacy measures actually matter versus which are theatre. 'Secure' means nothing without 'against whom'.
A real CVSS 3.1 calculator loaded with CVE-2025-25249, where NVD says 9.8 and Fortinet says 8.1. Flip attack complexity and watch the severity band cross the line that decides your patch SLA.
The same CRM theft by three routes - stolen password, stolen cookie, stolen OAuth token - against eight controls. The OAuth route walks past almost all of them, because none of them watch a token that never signs in.
Step through the ShinyHunters PeopleSoft campaign - MeshCentral dressed as an Azure service, an SSH-spraying bash script, zstd exfiltration - with the detection opportunity at each stage.
An npm worm and a macOS infostealer, side by side, with the control that should have caught each stage and why it did not - including valid Sigstore provenance for malicious code.
TukTuk's C2 ran over ClickHouse, Supabase, Ably, Dropbox and GitHub Issues. Block each channel and watch it fall through to the next - because every destination is a product your company might pay for.
Fifteen stages from a poisoned search result to encryption, with the actual command run at each step, the MITRE technique, and the detection chance that existed at that moment. Living-off-the-land stages marked.
How CVE-2025-32711 chained four separate defences into a zero-click data exfiltration against M365 Copilot. Each defeated control, in order.
A HASSH fingerprint published for the mdrfckr botnet in 2022, tested against 632 implants in a 2026 honeypot corpus - where it matches zero. Explore how the fingerprint drifted and why.
1,976 login attempts from five coordinated addresses hunting this honeypot's own usernames, drawn straight from the raw Cowrie logs. Original data that exists nowhere else.
Interactive recreation of the WannaCry ransom note. Countdown timer, BTC payment address, decryptor UI. Built from documented samples.
Browse the Silk Road marketplace circa 2013. Listings, vendor ratings, escrow system, Tor hidden service aesthetic.
Live IRC session in the #antisec channel. Sabu, Topiary, tFlow, Kayla - type commands and get responses. Classic Windows gray UI.
Navigate the original carding forum that invented modern cybercrime. Browse categories, read threads, see the vendor reputation system.
The largest dark web market at its peak. Browse listings, vendor ratings, BTC prices. Seizure banner included.
Inside a COM threat actor Telegram group. SIM swap coordination, social engineering tips, target sharing.
Recreation of the Ryan Collins phishing email. Toggle analyst mode to highlight every indicator - sender domain, fake urgency, malicious link.
Click-through evidence board for Sabu, DPR, Alpha02, Pompompurin, IntelBroker, Brett Johnson. The mistake, the context, the consequence.
A real SIM swap social engineering call, exchange by exchange. Toggle analyst notes to see what each step exploits and where the data came from.
Full Flipper Zero OLED interface simulation. Sub-GHz scanning, NFC reading, BadUSB payload execution, IR learning. With analyst panel.
Animated waterfall spectrum across FM, 433 MHz ISM, ADS-B aircraft, pager networks, and GSM. Click signals to see what's being broadcast.
Plug the Ducky into a simulated target. Watch DuckyScript execute keystroke by keystroke. Three payloads: WiFi dump, reverse shell, persistence.
Watch the AI hunt WPA2 networks, send deauth frames, and capture handshakes. Pixelated face changes mood. Live console log.
Full WiFi Pineapple attack workflow: scan for APs, clone a target SSID, deauth clients, deploy captive portal, harvest credentials.
Deploy Stuxnet against Natanz enrichment facility. Watch centrifuge RPMs go haywire while SCADA shows nominal readings. Compare real vs spoofed feeds.
Watch Mirai scan IPv4 space for default-credential IoT cameras and routers, build a botnet, then launch a DDoS attack against real targets.
Step through the NotPetya attack: MEDoc supply chain infection, EternalBlue propagation, Mimikatz credential theft, MBR overwrite, and the fake ransom screen.
Fire JNDI injection payloads at a vulnerable Log4j server. Watch the DNS callback, LDAP referral, class loading, and RCE play out step by step.
Network map showing DarkSide's spread through Colonial's IT network. Ransom note, the $4.4M Bitcoin negotiation, and the aftermath timeline.
Step through the SUNBURST supply chain attack: build system injection, 18,000-org distribution, 9-month dormancy, Golden SAML pivot to cloud, and detection by FireEye.
A USB-C cable with an embedded ESP8266 WiFi chip. Operator connects remotely, selects a DuckyScript payload, and triggers HID injection over WiFi. Target sees a normal cable.
Scan real RFID/NFC card types - HID Prox, EM410x, MIFARE Classic, iCLASS. Watch the CRYPTO1 attack crack sectors, clone the card, then emulate against a reader.
Browse simulated Shodan search results: exposed Siemens S7 PLCs, hospital HL7 interfaces, IP cameras with default creds, and RDP with BlueKeep. Click any result to see the banner and CVEs.
Browse the BreachForums interface circa 2024. Databases, combolists, exploits, malware source code, and services. Simulated posts from real threat actor patterns. Toggle analyst mode for context on each category.
The dark web negotiation portal ransomware victims are directed to. Choose your response: ask the price, request an extension, or refuse to pay. Each path shows the operator's counter and analyst notes on the negotiation tactics being used.
Step-through visualization of a classic stack buffer overflow. Watch input spill past a 32-byte buffer, overwrite saved EBP and return address, and redirect EIP into attacker shellcode. Step or auto-play through all 6 phases.
Interactive SQL injection playground. Five payload types: auth bypass, comment truncation, UNION data exfiltration, boolean blind probe, and stacked DROP (blocked). Watch queries execute and see exactly what the database returns.
Watch malware exfiltrate data through DNS queries that blend with legitimate traffic. Base32-encoded data hidden in subdomain labels, commands received in TXT responses. Toggle analyst mode to see why this evades most firewalls.
Three active beacons calling home to a Cobalt Strike team server. Run real commands (whoami, hashdump, lateral movement), watch the C2 traffic, and toggle analyst mode for JARM fingerprinting and detection signatures.
Annotated replay of a Scattered Spider-style IT helpdesk vishing call. Seven distinct social engineering techniques, from pretexting to complicity anchoring.
Interactive terminal simulator across six operating systems: Kali Linux, Windows CMD, PowerShell, macOS, Busybox, and Cisco IOS. Real command behaviour, realistic output.
Malware Family Database
Documented malware families - tracked, analyzed, and catalogued from public threat intelligence and independent analysis.
| Family | Type | Platform | Severity | Status | Last Seen | Tags | |
|---|---|---|---|---|---|---|---|
| > | Lumma | Stealer | Windows | Critical | Active | 2025-06 | #maas#credential-theft#crypto+1 |
| > | RedLine | Stealer | Windows | High | Active | 2025-05 | #stealer#credential-theft#underground |
| > | AsyncRAT | RAT | Windows | High | Active | 2025-06 | #rat#open-source#.net+1 |
| > | DarkGate | Loader | Windows | Critical | Active | 2025-06 | #loader#rat#persistence+1 |
| > | AgentTesla | Stealer / Keylogger | Windows, Linux | Medium | Monitored | 2025-04 | #.net#keylogger#stealer+1 |
| > | njRAT | RAT | Windows | High | Active | 2025-05 | #rat#keylogger#persistence |
| > | Remcos | RAT | Windows | High | Active | 2025-05 | #rat#commercial#espionage+1 |
| > | StealC | Stealer | Windows | High | Active | 2025-06 | #stealer#c-based#crypto+1 |
| > | MetaStealer | Stealer | macOS, Windows | Medium | Monitored | 2025-03 | #stealer#macos#cross-platform+1 |
| > | XWorm | RAT | Windows | High | Active | 2025-05 | #rat#hvnc#ransomware+1 |
| > | Vidar | Stealer | Windows | High | Monitored | 2025-02 | #stealer#maas#telegram+1 |
| > | RaccoonStealer | Stealer | Windows | Medium | Inactive | 2024-10 | #stealer#maas#c+++1 |