Follow the signal. See the whole attack.
Real-world security investigations reconstructed by TandemTrace AI agents—from the first alert to the final verdict.
Explore the evidence, attack path, competing hypotheses, scope, and response decisions behind every confirmed incident.
Controlled simulations test how the autonomous SOC reasons.
Observed incidents show how evidence changes a real investigation.
Open the case files.
Coordinated SSPR reconnaissance
A distributed probe across password-reset infrastructure: the alert pattern, infrastructure overlap, evidence boundaries, risk assessment, and recommended response.
Endpoint malware followed by credential dumping
An unsigned execution chain establishes persistence, accesses LSASS memory, stages credential material, and begins command-and-control beaconing.
PowerShell download chain confirmed malicious
A document launches encoded PowerShell, retrieves a second-stage script, executes in memory, and creates scheduled-task persistence.
ClickFix attack through a fake CAPTCHA
A compromised portal seeds a clipboard command, guides the user through the Run dialog, and launches a staged information-stealing chain.
AWS access-key compromise and IAM escalation
A stolen CI access key crosses its workload boundary, assumes a production role, grants wildcard privileges, and creates persistent credentials.
Linux web compromise, persistence, and credential theft
A crafted upload request leads to shell execution, a persistent systemd service, secret collection, and a confirmed outbound transfer.
Every conclusion traces back to evidence captured during the investigation.
Confirmed facts, analytical judgments, and unknowns are kept separate.
Each report closes with risk, investigation delta, and prioritized action.