NULL DRAGON // RESEARCH LAB

Threat Intelligence

Threat actors, campaigns, infrastructure, indicators, malware, and toolkits—with context.

Researching the adversary.

I am expanding this section to cover threat actor profiles, campaign timelines, infrastructure analysis, malware and operator toolkits, and indicators of compromise. Reports will distinguish observed facts from assessment and will include collection dates, sources, and confidence where appropriate.

PROFILES

Threat Actors

Motivation, targeting, tradecraft, aliases, relationships, and observed operational patterns.

OPERATIONS

Campaigns

Timelines, victimology, infrastructure, delivery methods, and changes in tactics over time.

CAPABILITIES

Malware & Toolkits

Custom malware, commodity tools, living-off-the-land techniques, and operator workflows.

EVIDENCE

IOCs & Infrastructure

Indicators presented with provenance, context, confidence, and an explicit warning when data may be stale.

Threat intelligence reports are in the research pipeline.

I am building the format and source discipline first so the reports are useful, transparent, and maintainable rather than rushed collections of indicators.