About

Threat intelligence is an input to active defense: emulate what the reporting describes, validate detections, and retest after the patch. This site is that public practice, not a finished consultancy.

Projects are case studies of that loop. Planned work is labeled until the lab is actually run. First looks and practitioner takes live on /imho (IMHO).

What this site does not publish

No employer or client internals, no live malware, no TLP other than CLEAR, and no invented lab results. When a case study is still a plan, it says so. There is no AI news wire here.

Contact

Email: [email protected]
Resume: luke.cyberresearch.us