Technical notes
Short write-ups from our analysts on detection, forensics and hardening. No forms, no registration, no gate — take what is useful.
- Read
7 min read
Detecting thread hijacking without reading anyone's mail
Header and graph signals that identify an injected reply, without content inspection or the privacy problems it brings.
- Detection
- BEC
- Read
6 min read
What we preserve first, and why the order matters
The evidence acquisition sequence our responders follow in the first hour, and the reasoning behind it.
- Incident response
- Forensics
- Read
5 min read
p=quarantine is not enforcement
Why a partial DMARC policy provides far less protection than the dashboard suggests, and what the percentage tag actually does.
- DMARC
- Hardening
Why these are free
Because gating them would be self-defeating. A note is the thing an engineer pastes into a team channel at 2am — that circulation is worth more to us than the email addresses a form would collect, and a form would destroy it.
They are written by the analysts who do the work, not by a content team, which is why they are irregular and occasionally very specific. We publish when we learn something worth passing on.
What we write about
- Detection engineering
- Signals that still work in a production estate, and the false positives they cost you.
- Incident response method
- How we sequence evidence acquisition, and the reasoning behind the order.
- Hardening
- Controls that are widely deployed but rarely finished — DMARC being the standing example.
- Fraud
- How the money actually moves, which is usually less technical than people expect.
Spotted an error, or want us to go deeper on one? Write to the CERT directly — corrections are welcome and we credit them.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.