Active defense research

I turn threat intelligence into controlled emulation, detection validation, and measurable defensive improvement. Public TLP:CLEAR notes: what happened, how it is reached, what to patch or hunt.

View projects · About this lab

Focus

  • Adversary emulation

    Controlled tests mapped to ATT&CK techniques and realistic attacker behavior, in a lab I control.

  • Detection validation

    Measuring whether behavior is prevented, logged, alerted, missed, or improved after retest.

  • Threat-informed defense

    Turning public reporting into hunts, detections, and defensive engineering work — not a generic CTI blog.

Projects

  • Detection Validation Campaign

    Planned public lab that scores a small ATT&CK subset as prevented, logged, alerted, or missed, then ships a detection and retests. No results yet.

All projects

About

cyberresearch.us is Luke Johnson’s active-defense research lab. Threat intelligence is an input: emulate what the reporting describes, validate detections, and retest.

About this lab