Skip to content

Editorial process

Methodology

How records are researched, corroborated and assessed, and the limits that apply to every analysis published here.

Methodology

How a record is built

The same four stages apply to every record, in this order. Nothing is published that has not completed all four.

  1. 01

    Collect

    Primary material only: incident reports, vendor advisories, telemetry samples and published research. Aggregator coverage is treated as a pointer, never as a source.

  2. 02

    Corroborate

    Each material claim is checked against a second independent source. Claims that survive only one source are marked as such or removed.

  3. 03

    Reconstruct

    Events are placed on a timeline with explicit gaps. Where sequence is inferred rather than evidenced, the record says so in plain language.

  4. 04

    Assess

    Every record closes with a confidence assessment and states what would change it. Analysis without a stated confidence level is opinion.

Editorial standards

Why this analysis can be relied on

These four commitments are the reason a record is worth reading. They are also the easiest things to check.

No vendor influence
No sponsored placements, no products named as remedies, no analysis shaped by a commercial relationship. Controls are described by capability.
Sources are listed
Every record links its primary sources. If a claim cannot be traced to something you can read yourself, it does not appear.
Confidence is stated
High, moderate or low — assessed explicitly, with the reasoning given. Uncertainty is reported rather than smoothed over.
Corrections are visible
Records carry an updated date and the change is described in the text. Silent edits defeat the point of a register.

Stated limits

What this analysis does not claim

Reconstruction is not observation
Records describe intrusions from evidence left behind. Where a step is inferred from its effects rather than observed directly, the record marks it as inference.
Timing figures are indicative
Durations such as dwell time and time to patch reflect the cases examined. They describe a pattern worth planning against, not a measurement that generalises to every estate.
Detection efficacy varies by environment
A detection that performs well in one estate can be unusable in another. Every playbook states the telemetry it depends on so the reader can judge fit before building.
Attribution is generally out of scope
Naming an actor rarely changes a defensive decision. Records focus on technique, signal and control, and say so when attribution is deliberately not assessed.