Linux Web Service Intrusion
A public-safe replay that follows a Linux web-service intrusion through execution, discovery, collection, detection, and containment.
Open emulation →Curated security research that follows attacker behavior into the telemetry, evidence, detections, and defender decisions it produces. Use the catalog for direct access to a specific emulation, or browse the Scenario Library when you want to explore.
Foundations lead into techniques, detections, attack chains, and CVE studies. Search by subject or filter by platform and status to get to the right material quickly.
A public-safe replay that follows a Linux web-service intrusion through execution, discovery, collection, detection, and containment.
Open emulation →Use the library when you want to compare available scenarios before opening one.
CVE studies attach to reusable behaviors and evidence instead of becoming isolated one-off pages.
Core host, identity, file, DNS, process, and network behaviors that later content can reuse.
ATT&CK-aligned behavior studied independently of any one vulnerability.
Defender-focused material built around the telemetry needed to see and reason about behavior.
Multi-stage scenarios that combine earlier building blocks into a coherent sequence.
Curated vulnerability case studies that reuse the same behavior, telemetry, evidence, and detection model.
Paths guide newer users through the same catalog without forcing experienced practitioners into a fixed sequence.
Build from host and network visibility toward techniques, detections, attack chains, and CVE studies.
Learn Windows execution, identity, services, scheduled activity, and the detections built around them.
Work from required telemetry to observed evidence and practical detection reasoning.
Collections make it easier to follow a subject across multiple emulations without changing the underlying learning structure.
Content related to public-facing services, execution, discovery, network behavior, and defender visibility.
The Scenario Library remains the main browse experience. When you select a specific emulation from this catalog, M3HT4 takes you directly into that scenario instead of asking you to choose it again.
The working Platform Beta and dedicated scenario replay pages are not being moved or rewritten by this update.
Browse Scenario Library →Published material remains selected, sanitized, and separated from private operational details. M3HT4 research is limited to owned or explicitly authorized environments.