Publishing
One intelligence shop, three audiences: State of the Threat for the board, State of the Attack for the responders, State of the Defense for the teams closing the gaps.
State of the Threat publishes daily, with the long-form analysis on Sunday. State of the Attack and State of the Defense publish as material warrants, on no fixed schedule.
First-Party Observation
State of the Attack is written from a first-party sensor network. When it publishes, it is because we watched it happen, not because a vendor report said so. AI accelerates the collection and the first pass through it; the analysis and the call on what matters stay human. The briefs and the IOCs go out on the site and get pushed to the trackers other teams already watch: AlienVault OTX, Open Source Malware, and the abuse.ch trackers including URLhaus.
Essays
-
May 6, 2025
Implementing Zero Trust To Combat Fraud
Why the castle-and-moat security model fails against fraud, and how "never trust, always verify" can be made usable for the non-technical people it needs to protect.
-
April 22, 2025
The Cost of Neglect: A Personal Case for Robust Incident Response
A homelab password-vault scare that spiraled into hours of panic, and why a written, accessible incident response plan matters even at personal scale.