Researching the adversary.
I am expanding this section to cover threat actor profiles, campaign timelines, infrastructure analysis, malware and operator toolkits, and indicators of compromise. Reports will distinguish observed facts from assessment and will include collection dates, sources, and confidence where appropriate.
Threat Actors
Motivation, targeting, tradecraft, aliases, relationships, and observed operational patterns.
Campaigns
Timelines, victimology, infrastructure, delivery methods, and changes in tactics over time.
Malware & Toolkits
Custom malware, commodity tools, living-off-the-land techniques, and operator workflows.
IOCs & Infrastructure
Indicators presented with provenance, context, confidence, and an explicit warning when data may be stale.
I am building the format and source discipline first so the reports are useful, transparent, and maintainable rather than rushed collections of indicators.