Welcome to my dimension
First entry. Let’s get the introductions out of the way.
By day I ship web applications. By night I’m usually elbow-deep in breach data, ransomware group genealogies, or a packet capture that raised more questions than it answered. I also came up through a journalism program before any of that, which turns out to matter more than it sounds — more on why below. This post is about what you’re actually here for.
Why this exists
The global threat landscape is bigger than the slice of it that gets written about. Coverage clusters around a handful of well-resourced regions and a handful of headline-grabbing incidents, while a lot of significant breaches elsewhere go undocumented, unattributed, or flattened into a single misreported paragraph. The public record is thinner than most people assume.
This site is one small attempt to close a bit of that gap — primary-source documentation instead of another summary filtered through a vendor selling something.
What you’ll find here
- Breach documentation and attribution — structured cataloguing of dark web disclosures and confirmed incidents, with attribution grounded in evidence. If a claim can’t be traced to a leak site posting, a disclosure, or corroborating data, it doesn’t make the record.
- Threat-actor evolution tracking — following ransomware groups through law-enforcement disruptions, rebrands, and reformations. Groups don’t die; they refactor.
- Breach aftermath analysis — what happens after the headline fades: the long tail of mass-exploitation campaigns, secondary redistribution of stolen data, and “dark data” scenarios where leaked records resurface years later in new contexts.
- Myth-busting bad statistics — disputed cyber-attack figures get repeated until they harden into fact. Widely-cited numbers get dismantled here by grounding the argument in verifiable incidents instead of recycled claims.
- OSINT and information-environment monitoring — open-source intelligence work spanning multilingual NLP, sentiment analysis, and disinformation detection.
Expect CTF writeups and tooling notes in the mix too, whenever something’s worth writing down.
The journalism part
Security research and journalism turn out to be the same discipline wearing different clothes: source verification, evidence chains, attribution standards, and the obligation to publish what you can prove rather than what makes the better headline. That editorial training is why every writeup here treats sourcing as non-negotiable — “a guy on a forum said so” doesn’t qualify as confirmation, no matter how good the story would be if it were true.
Ground rules
A few things this blog runs on, stated up front so there’s no ambiguity later:
- Evidence over vibes. Every claim traces back to something verifiable — a leak site, a disclosure, a capture, a reproducible test.
- Attribution with humility. Threat-actor attribution is stated with confidence levels, not certainty theater.
- Defang everything. No live links to hostile infrastructure. Ever.
- Authorized targets only. Techniques documented here are for authorized engagements, CTFs, defensive research, and education. Nothing here is an invitation, an instruction manual for crime, or legal advice.
- Write it down. Undocumented research might as well not have happened.
More soon.