
Case library
Real scenarios, seeded and ready
Every case ships with headers, URLs, attachments, identity and endpoint evidence.
Lottery Scam Triage
A commodity scam email. Learn to separate noise from real threats fast.
Bank Security Alert
Brand impersonation with a convincing login portal.
CEO Wire Request (BEC)
No links, no malware — just pressure. Prove intent with headers alone.
Payroll Bonus Scam
admin@serbiagotcold[.]wiki impersonating Payroll Admin. SPF passes. Now what?
Credential Harvest + Session Theft
The user submitted credentials. Race the attacker to the session.
Malicious Macro Document
Inquiry 2026-50035 with a macro-enabled workbook. Detonate and decide.
HTML Smuggling Payload
The payload is built in the browser. Gateway saw nothing.
ISO + LNK Smuggling
Container files that bypass mark-of-the-web.
QR Phishing (Quishing)
The URL never appears in the email body. Extract it anyway.
OAuth Consent Phishing
No password stolen — but the attacker reads the mailbox anyway.
Callback Phishing (TOAD)
A phone number instead of a link. Same outcome.
Thread Hijack
A real conversation, a fake reply. Spot the pivot.
Fake SharePoint Share
Trusted brand, untrusted infrastructure.
Invoice Fraud — Bank Detail Swap
Six figures depend on your classification.
MFA Fatigue Follow-On
The push storm worked. Contain the session before exfil.
