Research

Intelligence that starts with curiosity

Our research team studies adversary tradecraft, emerging attack surfaces, and defensive techniques — and feeds every finding back into our services.

Focus Areas

What we study

AI & LLM attack surfaces

Prompt injection, model manipulation, and the new failure modes of AI-integrated enterprise systems.

Cloud-native tradecraft

How adversaries abuse identity, misconfiguration, and managed services in modern cloud estates.

Adversary tracking

Tooling, infrastructure, and behavioral patterns of the threat actors most relevant to our clients' sectors.

Ransomware economics

The evolving business models of extortion groups, and what actually deters them.

Supply-chain risk

Dependency, vendor, and build-pipeline attack paths in software-driven organizations.

Detection engineering

Turning offensive findings into durable, low-noise detection logic.

Research Pipeline

From lab to defense

01

Observe

Telemetry from engagements and open sources surfaces new attacker behavior.

02

Reproduce

We rebuild the technique safely in the lab to understand its mechanics and limits.

03

Detect

Findings become detection rules, hunting hypotheses, and test-plan scenarios.

04

Publish

Advisories and write-ups share what defenders everywhere need to know.

Publications and advisories will appear here. For early access to our research, get in touch.