Active defense research
I turn threat intelligence into controlled emulation, detection validation, and measurable defensive improvement. Public TLP:CLEAR notes: what happened, how it is reached, what to patch or hunt.
View projects · About this lab
Focus
-
Adversary emulation
Controlled tests mapped to ATT&CK techniques and realistic attacker behavior, in a lab I control.
-
Detection validation
Measuring whether behavior is prevented, logged, alerted, missed, or improved after retest.
-
Threat-informed defense
Turning public reporting into hunts, detections, and defensive engineering work — not a generic CTI blog.
Projects
-
Detection Validation Campaign
Planned public lab that scores a small ATT&CK subset as prevented, logged, alerted, or missed, then ships a detection and retests. No results yet.
About
cyberresearch.us is Luke Johnson’s active-defense research lab. Threat intelligence is an input: emulate what the reporting describes, validate detections, and retest.