Skip to content

Intelligence register

Security incidents, taken apart and written down.

A working register of intrusions, techniques and exposures. Each record explains how the failure happened, which signals were available, and what would have changed the outcome.

Records
06
Categories
06
Vendor claims
00

Featured record

IA-0001Severity: critical

Build Pipeline Compromise: When the Artifact Is the Payload

An intrusion that never touched production directly. The attacker modified a build agent, and the organisation shipped the backdoor itself through its own signed release channel.

Incident Analysis4 min read

Key findings

  • A self-hosted build agent was reachable from a developer VLAN with no egress filtering and a shared local administrator password.
  • The attacker injected a post-compile step that appended loader code to the release artifact before signing, so every downstream integrity check passed.
  • Dwell time was 41 days. Detection came from a customer reporting anomalous outbound traffic, not from internal monitoring.

Latest intelligence

Recently published records

Each record is a self-contained analysis: what happened, how it worked, and which controls would have changed the outcome.

Browse by category

Lines of enquiry

Categories describe the kind of question a record answers, not the vendor or product involved.

IA1 record

Incident Analysis

Reconstructions of confirmed intrusions: entry point, dwell time, impact and the controls that would have changed the outcome.

AT1 record

Attack Techniques

How a single technique works in practice, where it shows up in telemetry, and what reliably detects it.

VR1 record

Vulnerability Research

Root-cause breakdowns of software weaknesses, exploitation conditions and realistic exposure windows.

CS1 record

Cloud Security

Identity, workload and storage failures specific to managed infrastructure and shared-responsibility gaps.

ID1 record

Identity & Access

Authentication bypasses, session abuse, privilege paths and the directory misconfigurations that enable them.

DP1 record

Defensive Playbooks

Detection logic, hardening sequences and response steps written to be implemented, not admired.

Methodology

How a record is built

The same four stages apply to every record, in this order. Nothing is published that has not completed all four.

  1. 01

    Collect

    Primary material only: incident reports, vendor advisories, telemetry samples and published research. Aggregator coverage is treated as a pointer, never as a source.

  2. 02

    Corroborate

    Each material claim is checked against a second independent source. Claims that survive only one source are marked as such or removed.

  3. 03

    Reconstruct

    Events are placed on a timeline with explicit gaps. Where sequence is inferred rather than evidenced, the record says so in plain language.

  4. 04

    Assess

    Every record closes with a confidence assessment and states what would change it. Analysis without a stated confidence level is opinion.

Editorial standards

Why this analysis can be relied on

These four commitments are the reason a record is worth reading. They are also the easiest things to check.

No vendor influence
No sponsored placements, no products named as remedies, no analysis shaped by a commercial relationship. Controls are described by capability.
Sources are listed
Every record links its primary sources. If a claim cannot be traced to something you can read yourself, it does not appear.
Confidence is stated
High, moderate or low — assessed explicitly, with the reasoning given. Uncertainty is reported rather than smoothed over.
Corrections are visible
Records carry an updated date and the change is described in the text. Silent edits defeat the point of a register.

Subscribe

New records, as they are published

One message per record. No newsletter digest, no product mail, and you can unsubscribe from any message.