Skip to content
Obfuscation Hub

OBFH Labs

Practice the work before the work finds you

Reading about incident response is not the same as sequencing a messy timeline at 4 p.m. on a Thursday. These case exercises put realistic — and entirely fictional — evidence in front of you and make you decide, document, and deliver.

Lab Foundation

Build an Incident Timeline from Mixed Evidence

Reconstruct a business-email-compromise attempt from five messy, contradictory evidence sources — the core analyst skill of sequencing what actually happened, in what order, in one timezone.

60–90 minutes Evidence normalization · Timeline construction
Lab Foundation

Conduct a SaaS Administrative Access Review

Review the administrative access of a realistic 60-person company across four SaaS platforms. Decide who keeps what, justify every privileged retention, and produce audit-grade evidence.

45–75 minutes Least-privilege analysis · Access decision documentation
Lab Intermediate

Respond to a Compromised Vendor Account

A tabletop exercise: your managed service provider reports that one of their technician accounts — with admin rights in your environment — was compromised. Work the first four hours, decision by decision.

60–90 minutes (solo) · 90–120 minutes (team tabletop) Containment decision-making · Third-party incident coordination