About Services
Investigations Footprint Consulting Research Data Intelligence API Training VPN Digitization Disc Duplication Print Web & Mobile RF & Physical Lead Generation
Contact
Services / Research

Original Cybersecurity & OSINT Research

We find things other people miss, then publish the methodology. The VECERT exposé traced stolen ProtonMail and DarkEye tokens to a single operator running unauthorized scans of Venezuela's national election infrastructure, published 2026-02-22 with full attribution. The Albania AI Minister exposé surfaced an empty government frontend over a fully open OData API, recovered 32GB from public Azure Blob storage, and reached Albanian national news within 24 hours. Minnect and Valuetainment both silently patched disclosures that sat unanswered for 49 days before going public. Research is not a sideline. It is how we prove what the tools do. Press inquiries get a 72-hour answer or a clean no.

Active streams
NW-R01
Country-scale OSINT methodology

Full-stack intelligence operations against foreign government and commercial infrastructure. 18+ jurisdictions. Methodology from initial recon through deliverable.

Substack + Medium // bilingual EN/ES
NW-R02
Credential exposure ecosystems

Cross-referencing breach datasets against enterprise and government domains. 3,000+ domains mapped, 2.9M+ exposures tracked, 70 countries covered. Methodology, not raw data.

Database-backed // monthly refresh
NW-R03
Infrastructure-as-adversary

How adversary infrastructure reveals adversary intent. Topology mapping, ASN analysis, BGP route leaks, data-center inventories. Pairs with our 6,000+ global DC cartography.

Maps + writeups
NW-R04
Space domain awareness

TLE localization, commercial satellite tracking, and the US UDL vs peer-nation alternatives arms race. Explainers on SpaceMapper (Chinese UDL equivalent) and orbital regime analysis.

Technical deep-dives // bilingual
NW-R05
Defensive architecture for self-hosted services

Production-grade infrastructure without third-party clouds. Proxmox patterns, Cloudflare tunnel topologies, hardening checklists, secret-rotation discipline.

Open methodology // used by ODINT + allied nonprofits
NW-R06
Device fingerprinting & network identification

Building and maintaining device fingerprint databases (Fingerbank pipelines, DHCP fingerprinting, MAC vendor enrichment). Attribution work at the IP/device layer without overclaiming.

Published tooling on GitHub // Huginn-Muninn pipeline

Active CFP submissions across DEFCON, BSides, RSA Innovation Sandbox, and regional conferences. Press inquiries to [email protected] — 72-hour turnaround or we say no.

Read full details → Ask for current article links →
Selected work
PUB-2026-05
Albania AI Minister exposé
Empty Vue frontend over a wide-open parlament.al OData API. Recovered 32GB from public Azure Blob storage, surfaced AKSHI procurement history. Hit Albanian national news 2026-05-20. Inbound from journalists, opposition MPs, and whistleblowers within 48 hours.
Published May 2026
PUB-2026-04
SpaceMapper: the Chinese UDL equivalent
Deep-dive on Kaiyun United's TLE-localization platform, its API surface, and the implications for US Space Force's Unified Data Library program. Bilingual EN/ES.
Article series
PUB-2026-02
VECERT.io exposé
Stolen ProtonMail/DarkEye tokens in public GitHub commits + scans of Venezuela's CNE. Full infrastructure + operator attribution.
View →
Substack + Medium
CORPUS-CARMEN
Carmen Sandiego: 260-country OSINT corpus
5.5M domains across 260 countries, with credential exposure surfaces and infrastructure fingerprints. Powers the regional OSINT product and our country-scale consulting.
Internal dataset, licensed selectively
Get in touch

Ready when
you are.

[email protected]
Received. You'll hear back within 48 hours.
Something went wrong — email us at [email protected].