Back to the investigation

Training mode

This walkthrough gives the answer away on purpose. Read it once to learn how the evidence works, then play a fresh case for real.

The Silent AirframeGhost in the BidTelemetry DriftThe Quiet RotationChange Order EchoSigning Key Shadow

Signing Key Shadow

Vantage Control Systems, an industrial software firm

Source code and code-signing material for a flight-control component left the network.

The cast

Clue by clue

CLUE 1

A crash dump with high entropy and no stack frames

How you surface it: Have forensics inspect the dump rather than trusting its extension.

Why it points at the insider: File type is a claim, not a fact. Entropy analysis exposes disguised archives.

CLUE 2

Vendor-portal upload from a workstation with no open ticket

How you surface it: Correlate outbound uploads with the ticketing system.

Why it points at the insider: Legitimate channels used without legitimate context are the insider's favourite cover.

CLUE 3

Secrets pulled from the vault into a local file

How you surface it: Review secret-vault access logs for bulk reads.

Why it points at the insider: Vault reads are the earliest possible warning for key theft — alert on volume, not just failure.

CLUE 4

Resignation timed to the upload window

How you surface it: Cross-reference HR events against the incident timeline.

Why it points at the insider: The 30 days around a resignation are the highest-risk window in insider risk. Monitor accordingly.

Innocent explanations you must rule out

The answer

Ori Ben-Ami is the insider. Motive: A signed competitor offer with a delivery expectation attached. Method: An encrypted archive disguised as a crash dump, uploaded through a vendor support portal.

Timeline: Day -35 offer signed; Day -28 pulls secrets into a local runbook; Day -21 creates the fake crash dump; Day -20 uploads via the support portal; Day -14 resigns; Day 0 signed binaries appear from an unknown publisher.

Lessons to carry into the game

Play a fresh casePlay this case