Analytical positions on cyber operations, deception, and adversary tradecraft.
Briefs examine the operational assumptions that shape cyber conflict, defensive doctrine, and autonomous systems. They present an argument grounded in field experience — not a campaign report or an indicator feed.
Crimeware Has an Attack Surface. We Catalogue It.
Standard threat-intelligence indexes malware by hash and family. Our Cyber Arsenal indexes the other thing — the vulnerabilities of the malware itself: the pre-auth RCE, the broken cookie validation, and the backdoors that the tools' own distributors wired into them. Over 40% of the commodity webshells and grabbers we catalogued are harvesting the operators who deploy them.
4 min readFortiBleed Credential-Validation Spray: Detection Brief
SOC-ready companion to FortiBleed from the Target Side. The highest-signal detections for the credential-validation phase: off-allowlist admin auth, one source testing many usernames at a steady 24/7 cadence, a single success after a run of failures, and FortiGate service/cloud accounts appearing at the login prompt. TLP:CLEAR.
IOC 4 min readThe AI Security Narrative Has Two Halves. We're Mostly Looking at One.
The vulnpocalypse framing assumes defense is static while offense gets new tools. Looking at the actual research and product landscape, that misses what's happening on the defensive side at the same time.
12 min readDeterrence by Cognitive Compromise
You can't deter a machine. But you can deter the operator behind it - by making the machine a liability. When intention itself becomes retrievable, the offensive economics of agentic operations changes shape.
3 min readBaseline Conditions
OHIIHO works on systemic cyber risk and digital sovereignty - how digital infrastructures behave when core security assumptions fail. Compromise, degradation, and uncertainty as default conditions, not edge cases.
1 min read