foyl SecIntel
foyl Reports
The report IS the deliverable: after every real incident, an analyst writes the document that executives, legal, and the next shift act on. Build one yourself, section by section, scored against the incident record.
Write the report
RPT-2026-0087 · INV-2024-0087 Critical Builder · Scored
Operation IRON CHIMNEY - Write the Incident Report
You have seen this incident across the consoles, the Range, and the labs. Now write it up: classify the incident, build the executive summary, reconstruct the timeline, file the IOC inventory, map the ATT&CK techniques, and choose recommendations you could defend in the executive briefing. Every choice is checked against the incident record, and you print your finished report at the end.
report writing executive summary timeline reconstruction ioc inventory att&ck mapping
6 scored sections
Printable finished report
~20 minutes
Start writing
RPT-2026-BEC-001 · THREAT-002 High Builder · Scored
BEC-001 - Write the CEO Wire Fraud Report
MailGuard blocked a $47,500 CEO impersonation before it reached the CFO. Classify a fully blocked fraud attempt, build the executive summary the impersonated CEO will read, reconstruct the out-of-band verification chain, map the techniques, and close with your own written assessment of what happens the day the classifier misses.
bec out-of-band verification executive summary analyst assessment
6 scored sections + free-write
Printable finished report
~20 minutes
Start writing
RPT-2026-VF-001 · THREAT-003 High Builder · Scored
VF-001 - Write the Vendor Fraud Report
One character separated the real vendor from the fraud: acme-industr1al.com carrying a $23,847 invoice with new bank details. Separate real fraud signals from noise, reconstruct registration-to-closure, choose verification that never touches the attacker's own contact details, and write your own closing judgment.
vendor-fraud homoglyph fraud signals analyst assessment
6 scored sections + free-write
Printable finished report
~20 minutes
Start writing
RPT-2026-ATO-002 · INV-2024-0086 High Builder · Scored
ATO-002 - Write the MFA Fatigue Report
The automation locked the account in 107 seconds - and the attacker's session lived another 22 minutes. Reconstruct the push-bombing takeover minute by minute, write the honest after-action review that credits the playbook and documents its gap, and tell the SOC lead which change you make first.
mfa-fatigue soar automation response gaps analyst assessment
6 scored sections + free-write
Printable finished report
~20 minutes
Start writing
RPT-2026-INS-001 · DLP-012 Critical Builder · Scored
INSIDER-001 - Write the Source Code Theft Report
No exploit, no stolen password - a trusted engineer pushed 1.8 GB of IRONMAN source to a personal repo behind a VPN, Tor, and an unmanaged device. Write the investigation report HR, Legal, and maybe a court will read: claims that survive scrutiny, evidence handling by the book, and controls that end at the corporate boundary.
insider threat evidence handling dlp correlation analyst assessment
6 scored sections + free-write
Printable finished report
~25 minutes
Start writing
RPT-2026-SUP-001 · CAM-003 Elevated Builder · Scored
SUPPLY-001 - Write the Supply-Chain Threat Assessment
Nothing has been breached - and that is the moment to write. A state-nexus APT is staging a lookalike partner portal against SecIntel. Practice a different genre: confidence language, IOC decisions where one observable must NOT be blocked, a proactive hunt plan, and justifying spend on an incident that will never happen.
threat assessment supply chain confidence language intel-led hunting
6 scored sections + free-write
Printable finished assessment
~25 minutes
Start writing

Every scenario now has a builder. Scored sections check your choices against the incident record; the Analyst Assessment sections are your own words, filed as written. Completing a builder counts toward your progress like a lab, with your best score kept.

Model reports - instructor material
INV-2024-0087 · CASE-2024-0267 Critical Active - Contain
Operation IRON CHIMNEY - Ransomware & Double Extortion
An invoice-themed AiTM lure stole Marcus Chen's session, which was replayed to create mailbox persistence. Credential dumping on FINANCE-WS-01 preceded lateral movement through SI-DC-01 to RESEARCH-STATION-01, where 547 MB left over the campaign C2 channel before 847 research files were encrypted. Six native-tool alerts correlate into this one investigation; ATO-002 remains a separate case.
ransomware aitm-phishing double-extortion credential-dumping data-exfiltration iron-chimney
847 files encrypted
547 MB exfiltrated
3 SOAR playbooks triggered
TA-001 - Eastern Europe
May 27, 2026
BEC-001 · CASE-2024-0218 Critical Blocked
BEC-001 - CEO Wire Fraud Impersonation
Business email compromise targeting CFO j.whitfield. Attacker impersonated CEO Marcus Reynolds using a Gmail display-name spoof requesting an urgent $47,500 wire transfer to a fraudulent account. Detected and blocked by Foyl MailGuard. BEC confidence score 97%.
bec ceo-fraud wire-fraud social-engineering
$47,500 wire attempt
Zero financial loss
TA-002 - COBALT MANTIS
May 27, 2026
VF-001 · THREAT-003 High Quarantined
VF-001 - Vendor Fraud Homoglyph Domain Attack
Lookalike domain attack using acme-industr1al.com (digit "1" substituted for letter "l") impersonating legitimate vendor Acme Industrial Supplies. Fraudulent invoice for $23,847 directed AP to an alternate bank account. Detected by domain-age heuristics and SPF/DKIM failure chain.
vendor-fraud homoglyph invoice-redirect lookalike-domain
$23,847 invoice fraud
Intercepted - no payment
TA-002 - COBALT MANTIS
May 27, 2026
ATO-002 · INV-2024-0086 · CASE-2024-0142 High Contained
ATO-002 - MFA Fatigue Account Takeover
Push bombing against Michael Blake (Director of Research) from 203.0.113.88: three denials, then a fourth push approved at 14:17. SOAR PB-002 executed nine of ten nodes in 107 seconds, but its missing token-revocation action left the session usable after the 14:19 suspension until conditional access terminated it at 14:39. TIP attribution may relate the infrastructure to TA-001; the evidence remains in its own investigation.
mfa-fatigue push-bombing soar-automation session-revocation
20 minutes after suspension
PB-002 · 9/10 nodes in 1m 47s
Separate from INV-2024-0087
May 27, 2026
INSIDER-001 · DLP-012 · RISK-004/005 Critical Investigating
INSIDER-001 - Source Code Theft Investigation
Trusted engineer victor.zane pushed 214 files / 1.8 GB of IRONMAN R&D source to a personal GitHub repository using a NordVPN inspection bypass, Tor sign-ins, and an unmanaged device. No exploit, no stolen credential - an investigation report written to HR and Legal standards, with evidence handling documented.
insider-threat data-exfiltration evidence-handling dlp
1.8 GB IRONMAN source
4 evasion layers
HR + Legal engaged
May 28, 2026
SUPPLY-001 · TA-003 · CAM-003 Elevated Monitoring
SUPPLY-001 - Supply-Chain Staging Assessment
SAPPHIRE FORGE, a suspected state-nexus APT, staging against the SecIntel supply chain: lookalike partner portal secintel-partner-hub.io, quiet scanning, and a Go implant dropper circulating in sector intel. A threat assessment in key-judgment form - confidence language, IOC decisions, escalation indicators, and a proactive hunt plan.
threat-assessment supply-chain apt key-judgments
No confirmed compromise
4 key judgments
TA-003 · medium confidence
Apr 24, 2026
About foyl Reports

Report builders turn documentation into a hands-on, scored activity. The model reports are the finished worked examples - because they double as the builder's answer key, they are instructor material, like the scenarios. All data is fictional foyl SecIntel content drawn from the same incidents that thread through the consoles, labs, and the Range.