Research

Field notes from the other side

Everything here comes out of our own pipeline: measured, anonymized and written for people who operate, not for people who forward PDFs.

5 pieces · 3 formats · written by the analysts who ran the collection
LATESTData analysis2026-06-24 · 2 min read

Anatomy of a stealer log: from infection to sale in 31 hours

We followed a single log batch from the moment it hit a Telegram channel to the moment its credentials were tested against a corporate VPN. The window is smaller than you think.

READ THE PAPER

Format

Topic

5 of 5 pieces

2026-06-24
Data analysis
Sherlog · 2 min

Anatomy of a stealer log: from infection to sale in 31 hours

We followed a single log batch from the moment it hit a Telegram channel to the moment its credentials were tested against a corporate VPN. The window is smaller than you think.

InfostealersAccount takeover
2026-06-10
Data analysis
Sherlog · 1 min

Session cookies outlive password resets: measuring the window

Across a sample of stealer records, we measured how long stolen session cookies remained valid after the victim's password was changed. The median was not minutes.

InfostealersAccount takeover
2026-05-28
Research report
Cvekit · 2 min

EPSS + KEV + exploit maturity: a prioritization formula that survives contact

CVSS tells you what could hurt. Exploitation probability, confirmed exploitation and exploit maturity together tell you what is hurting, and they shrink the patch queue by an order of magnitude.

Vulnerabilities
2026-05-12
Field note
Jabbernaut · 2 min

Why the underground's real marketplace speaks XMPP

Forum posts are advertisements. The price, the sample, the escrow and the handover all happen over Jabber, a layer almost no monitoring product indexes.

Messaging networksDark webInitial access
2026-04-30
Research report
Dragnet · 2 min

Ransomware blogs as a data source: what leak-site behavior reveals

Victim announcements, countdown timers, proof packs and entries that quietly vanish. Leak-site behavior is a dataset, and it says more about the groups than their ransom notes do.

RansomwareDark web

Follow the desk

Papers are published here first. The wire runs alongside them and carries what the pipeline turns up between them. For the papers alone, in a reader, there is feed.xml.

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware