Skip to case studies

Blue Team ยท Case Studies

Read the incident.
Explain the defence.

Each study traces a real attack layer by layer, maps it to ATT&CK and the kill chain, then names the mitigations and devices that answer it. Written to rehearse the questions an analyst interview actually asks.

13 case studies

Incident breakdowns

Ordered by year. Each one is drill-ready for interview questions on layers, attacks and mitigations.

201020 min

Stuxnet

The first malware known to cause physical destruction, using multiple zero-days and stolen certificates to cross an air gap and sabotage Iranian nuclear centrifuges while reporting normal readings to operators.

  • Cyber-physical sabotage (ICS/OT)
  • Removable-media propagation
  • Zero-day exploitation
Read the case study
201316 min

Target 2013

Attackers phished an HVAC contractor, used its vendor-portal access to reach Target's flat internal network, and scraped 40 million card numbers from point-of-sale memory.

  • Third-party / supply-chain access
  • Phishing
  • Point-of-sale memory-scraping malware
Read the case study
201716 min

Equifax

Attackers exploited an unpatched Apache Struts flaw in a public web portal, found plaintext credentials, and quietly queried dozens of databases for months, stealing the personal data of about 147 million people.

  • Web-application RCE (unpatched CVE)
  • Web-shell persistence
  • Plaintext-credential exposure
Read the case study
201718 min

NotPetya

A destructive wiper disguised as ransomware that spread through a trojanised accounting-software update, then used a stolen NSA exploit and credential theft to cross flat networks in minutes.

  • Software supply-chain compromise
  • Destructive wiper
  • Pseudo-ransomware
Read the case study
201715 min

WannaCry

A ransomware worm that used the leaked EternalBlue SMB exploit to infect over 200,000 unpatched Windows systems in days, until an accidental kill-switch domain slowed it down.

  • Ransomware
  • Self-propagating worm
  • Remote exploitation
Read the case study
201918 min

Capital One

A misconfigured web application firewall let an attacker trick a cloud server into handing over its own IAM credentials, which were then used to copy more than 100 million customer records out of AWS S3.

  • Server-side request forgery (SSRF)
  • Cloud instance-metadata credential theft
  • Over-permissive IAM role abuse
Read the case study
202020 min

SolarWinds SUNBURST

A stealthy supply-chain compromise that inserted a backdoor into signed SolarWinds Orion updates, then used DNS beaconing and forged SAML tokens to move quietly into cloud environments over months.

  • Software supply-chain compromise
  • Stealth backdoor and C2
  • Identity/token forgery (Golden SAML)
Read the case study
202115 min

Colonial Pipeline

A single leaked VPN password with no multi-factor authentication let DarkSide ransomware into Colonial's IT network, and the precautionary shutdown that followed cut fuel to much of the US East Coast.

  • Ransomware (double extortion)
  • VPN and valid-account abuse
  • Data exfiltration
Read the case study
202117 min

Kaseya VSA / REvil

Attackers exploited zero-days in Kaseya's remote-management software and used its own trusted update channel to push REvil ransomware through managed service providers to roughly 1,500 downstream businesses at once.

  • Supply-chain ransomware (via RMM/MSP)
  • Authentication-bypass and SQL-injection zero-days
  • Trusted-tool abuse
Read the case study
202117 min

Log4Shell

A trivially exploitable remote-code-execution flaw in the ubiquitous Log4j logging library, where a single attacker-controlled string in any log message could make a server fetch and run malicious code.

  • Remote code execution (zero-day)
  • Injection (JNDI lookup)
  • Dependency / software-component risk
Read the case study
202215 min

Uber 2022

An attacker bought a contractor's password, wore down their multi-factor authentication with repeated push prompts and a fake IT message, then found hardcoded admin credentials in a script that unlocked Uber's internal systems.

  • MFA fatigue (push bombing)
  • Social engineering
  • Valid-account abuse
Read the case study
202317 min

MOVEit / Cl0p

A SQL-injection zero-day in the widely used MOVEit Transfer file-sharing product let the Cl0p group deploy a web shell and steal data from hundreds of organisations in a single mass-extortion campaign.

  • SQL injection (zero-day)
  • Web shell deployment
  • Mass data theft and extortion
Read the case study
202417 min

IOCONTROL

A modular, Linux-based backdoor built to compromise internet-exposed IoT and OT devices, used by an Iran-linked group to reach fuel-management systems over an MQTT command channel.

  • OT/IoT device compromise
  • MQTT-based command and control
  • Default and weak-credential abuse
Read the case study