FIELD NOTES · THREAT INTEL

Field notes.

Threat intelligence, NIS2 compliance, and deception security, written for practitioners.

8 posts
[ field visual · placeholder ]
NIS2

NIS2 Detection Compliance: What Your SIEM Won't Tell You

Article 23 creates a 24-hour early-warning duty after awareness of a significant incident. But many SIEM stacks still miss honeytoken-grade signals because nobody built a rule for the trap nobody planted.

12 May 2026 · 8 min read
Read →
Threat Intel

Hackers Hid Malware Inside Tools Your Developers Use Every Day, And Nobody Noticed for 20 Minutes

In May 2026, attackers secretly infected 42 popular developer tools used by thousands of companies worldwide. In six minutes, they stole AWS credentials, passwords, and private keys from every machine that had those tools installed. Here's what happened, why your security software missed it, and the one thing that would have stopped it cold.

14 May 2026 · 8 min read
Read →
[ field visual · placeholder ]
Threat Intel

Fingerprinting the autonomous attacker

Timing variance, path-optimality, and the things that give an LLM agent away when it walks into your bait.

04 May 2026 · 6 min read
Read →
[ field visual · placeholder ]
Product

Sub-60s IAM revocation, what we learned shipping it

Reversible by design. The engineering decisions behind containment that fires automatically and never paints you into a corner.

22 April 2026 · 5 min read
Read →
[ field visual · placeholder ]
Case Studies

How a Dutch fintech caught a credential-stuffing campaign before the first login

A single URL beacon planted in a wiki page surfaced an exfiltration chain that had been in motion for nine days.

08 April 2026 · 7 min read
Read →
[ field visual · placeholder ]
Threat Intel

MITRE ATT&CK and honeytokens: where the framework actually fits

We map every Vantuz trip back to ATT&CK in the dossier. Here's how we decided which techniques apply.

28 March 2026 · 6 min read
Read →
[ field visual · placeholder ]
Product

Why our entire data plane lives inside one EU region

GDPR by design isn't a clause in a DPA. It's where the bits actually move.

14 March 2026 · 4 min read
Read →
FILE № 09 · DEPLOY

Stop reading.
Start watching.

Deploy your first token Get in touch
EU core data plane · NIS2 incident-ready · No agent on your network