24/7 INCIDENT RESPONSE
(877) 259-0509

CYBER CENTAURS TOPICS

Understand the Evidence.
Understand the Investigation.

Focused reference material covering digital forensics, incident response, cyber investigations, threat hunting, and penetration testing.

FOUNDATIONAL TOPICS

Start With the Core Concepts.

A compact index of the initial migrated reference topics most useful for understanding digital evidence and cyber investigations.

Digital Forensics

What Is Digital Forensics?

Digital forensics is a branch of forensic science focused on the recovery and investigation of material found in digital devices, often associated with computer crime. The discipline involves the collection, preservation, analysis, and presentation of digital evidence. As technology evolves, so does the complexity of the digital crimes and the.

Read Topic →

Digital Forensics

What Is a Chain of Custody?

The concept of a chain of custody is crucial in both legal and forensic contexts. It refers to the documented process that tracks the possession, handling, and storage of evidence from its collection point to its presentation in court. This documentation is critical for ensuring the integrity and security of.

Read Topic →

Incident Response

What Is a Data Breach?

A data breach is a security incident in which sensitive, protected, or confidential data is accessed or disclosed without authorization. Such breaches can have devastating effects, ranging from the loss of customer trust to financial penalties and regulatory consequences. They occur in various sectors, impacting businesses, governments, and individuals across.

Read Topic →

Incident Response

What Is Ransomware?

Ransomware is a type of malicious software that encrypts the victim ’ s files, making them inaccessible, and demands a ransom payment to decrypt them. This form of cyberattack can affect individuals, businesses, and even government agencies, leading to significant data loss, financial damage, and disruption of services.

Read Topic →

Threat Hunting & Adversary Behavior

What Is a Command and Control (C2) Framework?

In cybersecurity, a Command and Control (C2) framework is the system attackers use to communicate with and control compromised devices inside a victim’s environment. Once an attacker gains access, they need a reliable way to issue commands, move laterally, steal data, or install additional tools. The C2 infrastructure provides that.

Read Topic →

Threat Hunting & Adversary Behavior

What Is Cobalt Strike?

Cobalt Strike is one of the most well-known Command and Control (C2) frameworks in cybersecurity. Originally developed as a legitimate red-team tool, it provides security professionals with a powerful platform to simulate advanced attacks, test defenses, and measure how organizations respond under real-world conditions. However, its wide adoption has also.

Read Topic →

BROWSE BY DISCIPLINE

Topics by Investigation Area.

Browse reference material by the Cyber Centaurs discipline most closely connected to the question or investigation.

Digital Forensics

Reference topics covering evidence preservation, forensic artifacts, analysis methods, chain of custody, and digital evidence interpretation.

Digital Forensics

Can Deleted Data Be Recovered?

Deleted data may be recoverable in some circumstances, but storage type, encryption, TRIM, mobile security, and cloud records all affect what remains.

Read Topic →

Digital Forensics

What Is a Chain of Custody?

The concept of a chain of custody is crucial in both legal and forensic contexts. It refers to the documented process that tracks the possession, handling, and storage of evidence from its collection point to its presentation in court. This documentation is critical for ensuring the integrity and security of.

Read Topic →

Digital Forensics

What Is an Artifact in Digital Forensics?

In the realm of digital forensics, an artifact is any piece of information stored on a digital device that provides insights into the usage and activities performed on that device. Artifacts are not merely files or documents; they encompass a broader range of data including system logs, browser histories, hidden.

Read Topic →

Digital Forensics

What Is Digital Forensics?

Digital forensics is a branch of forensic science focused on the recovery and investigation of material found in digital devices, often associated with computer crime. The discipline involves the collection, preservation, analysis, and presentation of digital evidence. As technology evolves, so does the complexity of the digital crimes and the.

Read Topic →

Digital Forensics

What Is eDiscovery?

Electronic Discovery, commonly referred to as eDiscovery, is an integral part of the legal process in the digital age. It involves the identification, collection, preservation, analysis, and presentation of electronic data for use in legal cases. As the volume of electronically stored information (ESI) continues to expand exponentially, eDiscovery has.

Read Topic →

Digital Forensics

What Is Forensic Imaging?

Forensic imaging is the controlled acquisition of digital evidence so investigators can examine reliable copies while preserving the original source.

Read Topic →
View All Digital Forensics →

Incident Response

Reference topics covering data breaches, ransomware, containment, recovery, and incident investigation concepts.

Incident Response

What Is a Data Breach?

A data breach is a security incident in which sensitive, protected, or confidential data is accessed or disclosed without authorization. Such breaches can have devastating effects, ranging from the loss of customer trust to financial penalties and regulatory consequences. They occur in various sectors, impacting businesses, governments, and individuals across.

Read Topic →

Incident Response

What Is Business Email Compromise?

Business email compromise is a fraud and account-abuse pattern involving trusted email identities, payment manipulation, impersonation, or mailbox control.

Read Topic →

Incident Response

What Is Data Exfiltration?

Data exfiltration is unauthorized data transfer out of an environment or account, often requiring careful correlation across endpoint, cloud, and network evidence.

Read Topic →

Incident Response

What Is Initial Access?

Initial Access is the MITRE ATT&CK tactic describing how an adversary first gains entry into a network, account, cloud tenant, or system.

Read Topic →

Incident Response

What Is Ransomware?

Ransomware is a type of malicious software that encrypts the victim ’ s files, making them inaccessible, and demands a ransom payment to decrypt them. This form of cyberattack can affect individuals, businesses, and even government agencies, leading to significant data loss, financial damage, and disruption of services.

Read Topic →
View All Incident Response →

Insider & Corporate Investigations

Reference topics covering insider risk, employee data movement, authorized access, and corporate investigative evidence.

What Is an Insider Threat?

An insider threat involves risk from authorized access, including malicious insiders, negligent behavior, or compromised accounts used in harmful ways.

Read Topic →

What Is Data Staging?

Data staging is the collection or preparation of data before another action, such as review, compression, transfer, or possible exfiltration.

Read Topic →

What Is Employee Data Theft?

Employee data theft refers to suspected unauthorized copying, transfer, or retention of company data by an employee or former employee.

Read Topic →
View All Insider & Corporate Investigations →

Cloud & Identity Investigations

Reference topics covering Microsoft 365, identity activity, session abuse, authentication, and cloud investigation records.

What Is MFA Fatigue?

MFA fatigue is a social-engineering pattern where attackers generate repeated authentication prompts until a user approves one.

Read Topic →

What Is Microsoft 365 Forensics?

Microsoft 365 forensics examines identity, audit, mailbox, SharePoint, OneDrive, OAuth, and administrative records to investigate cloud activity.

Read Topic →

What Is Session Hijacking?

Session hijacking occurs when an attacker obtains or reuses a valid session token, cookie, or similar credential to act as an authenticated user.

Read Topic →
View All Cloud & Identity Investigations →

Threat Hunting & Adversary Behavior

Reference topics covering adversary infrastructure, command and control frameworks, tooling, and behavior used in threat investigations.

Threat Hunting & Adversary Behavior

What Is a Command and Control (C2) Framework?

In cybersecurity, a Command and Control (C2) framework is the system attackers use to communicate with and control compromised devices inside a victim’s environment. Once an attacker gains access, they need a reliable way to issue commands, move laterally, steal data, or install additional tools. The C2 infrastructure provides that.

Read Topic →

Threat Hunting & Adversary Behavior

What Is Cobalt Strike?

Cobalt Strike is one of the most well-known Command and Control (C2) frameworks in cybersecurity. Originally developed as a legitimate red-team tool, it provides security professionals with a powerful platform to simulate advanced attacks, test defenses, and measure how organizations respond under real-world conditions. However, its wide adoption has also.

Read Topic →

Threat Hunting & Adversary Behavior

What Is Mythic?

Mythic is a modern, open-source Command and Control (C2) framework widely used by security professionals and, unfortunately, by adversaries as well. Designed to be modular, flexible, and highly customizable, Mythic provides a powerful platform for controlling compromised systems during red-team exercises and penetration tests.

Read Topic →

Threat Hunting & Adversary Behavior

What Is Sliver?

Sliver is a modern, open-source Command and Control (C2) framework developed by the security company Bishop Fox. Originally built as a legitimate tool for penetration testers and red teams, Sliver has gained popularity for its flexibility, scalability, and ease of use. Unfortunately, like many C2 frameworks, it has also been.

Read Topic →
View All Threat Hunting & Adversary Behavior →

Penetration Testing & Offensive Security

Reference topics covering authorized security testing, exploit validation, privilege escalation, and attack-path analysis.

What Is an Attack Path?

An attack path is a sequence of relationships, permissions, weaknesses, or configurations that could allow movement toward a target objective.

Read Topic →

What Is Privilege Escalation?

Privilege escalation is gaining a higher or different level of access than initially held, either vertically or horizontally.

Read Topic →

What Is the Metasploit Framework?

The Metasploit Framework is a security testing platform used to validate vulnerabilities and simulate exploit behavior in authorized assessments.

Read Topic →
View All Penetration Testing & Offensive Security →