Editorial process
Methodology
How records are researched, corroborated and assessed, and the limits that apply to every analysis published here.
Methodology
How a record is built
The same four stages apply to every record, in this order. Nothing is published that has not completed all four.
- 01
Collect
Primary material only: incident reports, vendor advisories, telemetry samples and published research. Aggregator coverage is treated as a pointer, never as a source.
- 02
Corroborate
Each material claim is checked against a second independent source. Claims that survive only one source are marked as such or removed.
- 03
Reconstruct
Events are placed on a timeline with explicit gaps. Where sequence is inferred rather than evidenced, the record says so in plain language.
- 04
Assess
Every record closes with a confidence assessment and states what would change it. Analysis without a stated confidence level is opinion.
Editorial standards
Why this analysis can be relied on
These four commitments are the reason a record is worth reading. They are also the easiest things to check.
- No vendor influence
- No sponsored placements, no products named as remedies, no analysis shaped by a commercial relationship. Controls are described by capability.
- Sources are listed
- Every record links its primary sources. If a claim cannot be traced to something you can read yourself, it does not appear.
- Confidence is stated
- High, moderate or low — assessed explicitly, with the reasoning given. Uncertainty is reported rather than smoothed over.
- Corrections are visible
- Records carry an updated date and the change is described in the text. Silent edits defeat the point of a register.
Stated limits
What this analysis does not claim
- Reconstruction is not observation
- Records describe intrusions from evidence left behind. Where a step is inferred from its effects rather than observed directly, the record marks it as inference.
- Timing figures are indicative
- Durations such as dwell time and time to patch reflect the cases examined. They describe a pattern worth planning against, not a measurement that generalises to every estate.
- Detection efficacy varies by environment
- A detection that performs well in one estate can be unusable in another. Every playbook states the telemetry it depends on so the reader can judge fit before building.
- Attribution is generally out of scope
- Naming an actor rarely changes a defensive decision. Records focus on technique, signal and control, and say so when attribution is deliberately not assessed.