Capture over contact
Our sensors record what attackers send to them. We never connect to attacker infrastructure outside the lab, never reuse harvested credentials or keys, and never scan or probe third-party hosts.
Offline, isolated analysis
Samples are analysed only in an isolated lab with no route to any production network. Its egress is fail-closed through an encrypted tunnel: if the tunnel drops, nothing leaves.
C2 contact only when necessary
A command-and-control (C2) server is contacted only when necessary to confirm it is live, for a short, time-boxed window, with only that single destination reachable and all other traffic blocked.
No binaries published
We never publish malware binaries. Samples are referenced by SHA-256 hash, and scripts are defanged before publication.
Vetted, deduplicated indicators
Indicators are checked against existing feeds before submission, so we report what is new rather than duplicating others. Confidence reflects how each indicator was observed.
Corrections welcome
'Not found publicly' is not the same as 'novel'. We say when we have simply not located prior reporting, and we correct our work when we get something wrong.