Threat Research

Research that ends in a rule

Long-form analysis of campaigns we think detection teams should be hunting for. Every report closes with ATT&CK-mapped behaviours you can take straight into a backlog, not a list of hashes that expired last quarter.