SOCFRAME / THRONE Journal
socframe.io →

Adversary intelligence · From the lab

We don't claim detection.
We prove it.

We drive real adversary playbooks — nation-state espionage, ransomware, e-crime — at THRONE and publish exactly what it caught. Real incidents, real process trees, nothing staged. This is the work behind a more capable SOC.

Latest

Published as each operation completes
Scenario 07 · Live operationLive now

We stopped scripting.
We drove a live adversary.

We handed the wheel to a real Caldera C2 and let it fight: an autonomous, fact-chained APT29 operation. THRONE caught the whole kill chain in real time — credential theft, discovery, defense evasion — ONYX auto-triaged it, and every incident rebuilt as a process tree. Full technical detail, real IPs and incident IDs, HD evidence.

APT29 · Cozy Bear Autonomous C2 CRITICAL: LSASS dump caught 85 decisions
Read the operation report

The campaign

Six playbooks, emulated end to end