Guardian Labs

Intelligence that ends as a deployed detection, not a PDF

Guardian Labs tracks 214 named adversaries using telemetry from 6,800 organisations in 142 countries. Every finding is converted into detection logic, tested, and pushed to every tenant — in a median of 41 minutes from first observation. Reports are a by-product, not the product.

4.2T Security events processed every week across the Guardian sensor network
214 Named adversary groups under active tracking by Guardian Labs
41min Median time from first observation to a detection live in every tenant
18.6M Indicators under management, with automatic ageing and confidence decay
142 Countries contributing telemetry, weighted to avoid regional blind spots

Global telemetry

Scale is only useful if it is diverse

A hundred thousand sensors in one industry and one region produce a confident model of a very small world. Guardian weights the sensor network across geography, industry and organisation size, and reports coverage honestly — including where it is thin.

Guardian Labs correlation core 6.9M events/s ENDPOINT CLOUD NETWORK IDENTITY 2.41M North America 1.9T events/wk 1.88M Europe 1.2T events/wk 1.32M Asia Pacific 760B events/wk 410k Latin America 190B events/wk 286k Middle East & Africa 174k Oceania · 84B events/wk Sensor counts are active endpoints, cloud accounts and network sensors reporting in the trailing 24 hours. All telemetry is pseudonymised before it reaches Labs.

Scroll horizontally to see the full visual on a small screen.

First-party first

Roughly 78% of Guardian intelligence originates in our own sensor network and incident response engagements. The remainder comes from honeypot infrastructure, dark-web collection, sinkholes, partner sharing and open sources — each labelled with its provenance.

Behaviour outlives infrastructure

A domain dies in days; a technique persists for years. Labs prioritises behavioural analytics over indicator lists, which is why Guardian detections routinely catch a group's next campaign without an update.

People, not just pipelines

84 researchers across reverse engineering, malware analysis, cryptography, geopolitics and linguistics. Machine collection scales; attribution and intent still require analysts who read the forum posts in the original language.

Adversary tracking

214 groups, each with a name, a profile and a set of detections

Guardian Labs assigns a two-word cryptonym: a constellation for the cluster, and a suffix for motivation — WOLF for financially motivated crime, HERON for state-directed espionage, ANVIL for destructive operations, MOTH for access brokerage and EMBER for ideologically motivated activity.

Active First seen 2019-04

CORVUS WOLF

Financially motivated · ransomware-as-a-service

Operates the Kryptline encryptor with 40–60 affiliates. Gains access through edge-device exploitation and callback phishing, dwells for a median of 4.2 days, and exfiltrates before encrypting. Notable for disabling backups through the hypervisor rather than the guest.

Primary targets
Manufacturing, healthcare, professional services in North America and Western Europe
Tracked techniques
73 ATT&CK techniques · 61 Guardian detections mapped
Confidence: high Latest research
Active First seen 2016-11

LYRA HERON

State-directed · long-dwell espionage

Targets telecommunications, government and semiconductor supply chains. Distinguished by patient operational security: living-off-the-land tooling only, no custom implants on tier-1 hosts, and command and control tunnelled through compromised legitimate infrastructure in the victim's own country.

Median dwell time
287 days before detection in pre-Guardian environments
Tracked techniques
91 ATT&CK techniques · 78 Guardian detections mapped
Confidence: high Read the profile
Resurgent First seen 2021-02

VELA ANVIL

State-aligned · destructive operations

Wiper deployment against energy, water and transport operators, frequently staged months in advance and triggered around geopolitical events. Uses legitimate OT engineering software and signed drivers, which is why signature-based controls consistently miss the final stage.

Primary targets
Critical national infrastructure, ICS and SCADA environments
Tracked techniques
54 ATT&CK techniques · 47 Guardian detections mapped
Confidence: moderate Sector guidance
Active First seen 2022-08

AQUILA MOTH

Initial access broker

Mass-exploits internet-facing VPN concentrators, file transfer appliances and mail gateways within hours of proof-of-concept publication, then sells validated access. Roughly a third of the ransomware intrusions Guardian investigated in 2025 began with an AQUILA MOTH foothold.

Time to exploit
Median 19 hours from public proof of concept to mass scanning
Tracked techniques
38 ATT&CK techniques · 44 Guardian detections mapped
Confidence: high Edge exposure
Episodic First seen 2023-05

DRACO EMBER

Ideologically motivated · disruption and leak

Combines volumetric denial of service with opportunistic data theft and public leak for narrative effect. Technically unsophisticated but fast, and increasingly willing to purchase access from brokers rather than obtain it directly — which raises the real impact considerably.

Primary targets
Government, media, financial services aligned with contested policy positions
Tracked techniques
26 ATT&CK techniques · 31 Guardian detections mapped
Confidence: moderate Public sector guidance
Emerging First seen 2025-09

CETUS WOLF

Financially motivated · extortion without encryption

Skips encryption entirely: bulk-exfiltrates from SaaS tenants using stolen OAuth grants and legitimate API calls, then extorts on the threat of publication. Generates almost no endpoint signal, which makes identity and data telemetry the only reliable detection surface.

Notable tradecraft
Consent phishing, refresh token replay, API-rate-shaped exfiltration
Tracked techniques
29 ATT&CK techniques · 36 Guardian detections mapped
Confidence: moderate Identity defences
On attribution Guardian Labs attributes activity to clusters of observed behaviour, not to governments. Where we assess state direction, we state the confidence level and the specific evidence classes supporting it. We publish when we are wrong, and the correction carries the same distribution as the original.

Technique coverage

Where the tracked groups actually operate

Aggregate technique usage across all 214 tracked adversaries, mapped to MITRE ATT&CK tactics. Darker cells indicate techniques observed in more campaigns during the trailing twelve months — and each one is backed by Guardian detection logic.

Recon Initial Execute Persist Privilege Evasion Credential Discover Lateral Collect Exfil 71% 58% 55% 49% 12% 40% 31% 35% 44% 38% 27% Most prevalent techniques, all tracked groups T1078 · Valid accounts71% of campaigns T1566 · Phishing64% T1003 · OS credential dumping58% T1562 · Impair defences55% T1567 · Exfiltration over web service49% Fastest growing, year on year T1528 · Steal application access token+118% T1621 · MFA request generation+96% T1557.003 · AiTM proxy+81% T1190 · Exploit public-facing app+64% T1648 · Serverless execution+57% Prevalence low → high · every cell maps to at least one shipped Guardian detection

Scroll horizontally to see the full heatmap on a small screen.

IOC and TTP feeds

Consume it however your stack expects it

Intelligence is delivered in the format your existing tooling already speaks, with honest confidence scoring and automatic ageing. Nothing in the Guardian feed sits at confidence 100 forever, because nothing in the real world does.

Feed catalogue. All feeds are included with the platform; standalone subscriptions are available for organisations that are not Guardian Sentinel customers.
Feed Content Formats Update cadence Typical volume Ageing policy
High-confidence indicators Hashes, domains, IPs, URLs and certificates seen in confirmed intrusions STIX 2.1, TAXII 2.1, MISP, CSV, JSON Streaming ~41k/day Confidence halves every 30 days
Adversary TTP profiles Per-group technique sets, tooling, infrastructure patterns and targeting STIX 2.1, ATT&CK Navigator JSON On change 214 profiles Reviewed quarterly, versioned
Detection content Guardian rules, plus Sigma and YARA equivalents for third-party tooling Sigma, YARA, Guardian DSL Continuous ~90/week Deprecated with 60-day notice
Exploited vulnerabilities CVEs with confirmed in-the-wild exploitation and observed exploitation volume JSON, CSV, CVE feed Hourly ~30/week Retained indefinitely with status
Compromised credentials Credentials for your domains observed in dumps, stealer logs and broker markets API, webhook, JSON Continuous Tenant-specific Retained until rotation confirmed
Brand and infrastructure exposure Lookalike domains, spoofed portals, leaked source and exposed services API, email digest, JSON Every 15 min Tenant-specific Closed on takedown confirmation

Scroll horizontally to see all columns.

Pull it over TAXII in three lines

Standard TAXII 2.1 collections, OAuth 2.0 client credentials, and cursor-based pagination that survives a restart.

curl -s https://intel.guardian.com/taxii2/collections/ \
     -H "Authorization: Bearer $GDN_TOKEN" \
     -H "Accept: application/taxii+json;version=2.1"

# → { "collections": [
#     { "id": "hi-conf-indicators",
#       "title": "High-confidence indicators",
#       "media_types": ["application/stix+json;version=2.1"] },
#     { "id": "adversary-ttp",
#       "title": "Adversary TTP profiles" } ] }

Confidence you can reason about

Every indicator carries a confidence value, an observation count, a first and last seen timestamp, the collection source class and an explicit ageing curve. You can filter to only what your tolerance for false positives allows, and the filter is a number rather than a vendor's adjective.

Tenant-relevant by default

Feeds can be scoped to your sectors, regions and technology stack, which typically removes 80% of volume with no loss of relevant coverage. Sentinel customers get this scoping automatically from their own asset inventory.

No re-distribution restrictions inside your organisation Share Guardian intelligence with subsidiaries, MSSP partners and your own downstream tooling. Commercial redistribution outside your organisation requires a partner agreement.

Intel-to-detection pipeline

41 minutes from a researcher's observation to your tenant

The value of intelligence decays faster than almost any other security asset. This is the industrialised path Guardian Labs uses to close the gap, and the median time spent at each stage.

01 02 03 04 Collect Analyse and cluster Engineer detection Deploy and verify sensors, IR, honeypots, sinkholes, dark web infrastructure, code reuse, analyst confirmation write logic, state FP hypothesis, backtest 90 days push to all tenants, monitor precision drift T+0 T+14 min T+33 min T+41 min median 14 min median 19 min median 8 min precision drift → revise or withdraw retroactive replay against up to 7 years of retained telemetry — 3,840 cases opened this way in 2025

Scroll horizontally to see the full timeline on a small screen.

  1. Collect

    Sensor telemetry, incident response engagements, honeypots, sinkholes, dark-web collection and partner sharing land in a normalised store. Deduplication and provenance labelling happen at ingest, not later.

    continuous
  2. Analyse

    Clustering links new activity to existing adversary profiles by infrastructure, tooling, code reuse and behavioural signature. Analysts confirm or reject the cluster and record the evidence classes that justify it.

    median 14 min
  3. Engineer

    Behaviour is converted into detection logic with an explicit false-positive hypothesis, then backtested against 90 days of aggregate telemetry to measure precision before anything is published.

    median 19 min
  4. Deploy and verify

    Content ships to every tenant, is replayed against retained telemetry to surface historical matches, and is monitored for precision drift. Detections that degrade are automatically flagged for revision.

    median 8 min

Retroactive by default

Every new detection is automatically replayed against your retained telemetry — 90 days on the standard plan, up to seven years on Enterprise. A technique published this afternoon surfaces the intrusion that used it last quarter, opening a normal case with its original timestamps preserved.

In 2025, retroactive hunting opened 3,840 cases across the customer base that no live detection had caught at the time. Eleven of those were confirmed state-directed intrusions with dwell times above 200 days.

3,840Cases opened retroactively in 2025
90/wkNew or revised detections shipped
0Customer action required to receive them
Emergency content path For actively exploited zero-days, Labs can ship a mitigating detection in under 15 minutes, ahead of the full analysis. The content is marked provisional and refined within 24 hours.
Precision is monitored, not assumed Every shipped detection reports its live precision across the fleet. Anything that drifts below its committed floor is revised or withdrawn within one release cycle.

See how intel triggers automated response

Research highlights

Recent work from Guardian Labs

Published research is free, ungated where it matters, and written for practitioners. Everything below shipped with detection content on the day of publication.

Whitepaper62 pagesJuly 2026

2026 Threat Landscape Report

Breakout time fell to 41 minutes, credential-based intrusion overtook malware for the second year, and extortion-without-encryption grew 118%. The full data set behind those numbers, by sector and region.

Download the report
Technical analysis18 min readJune 2026

Inside Kryptline 4: how CORVUS WOLF kills backups at the hypervisor

A full reverse-engineering walkthrough of the ESXi component, the credential path it depends on, and the four detection opportunities that exist before the encryptor ever runs.

Read the analysis
Technical analysis12 min readMay 2026

Consent phishing at scale: the CETUS WOLF playbook

How an adversary exfiltrated 2.4 TB from a SaaS tenant using nothing but legitimate OAuth grants and documented API calls, and why endpoint telemetry never saw a thing.

Read the analysis
Research note9 min readMay 2026

Nineteen hours: measuring the edge-device exploitation window

Twelve months of scanning telemetry against VPN concentrators and file transfer appliances, and what it means for a patch cycle that assumes you have a weekend.

Read the note
Whitepaper34 pagesApril 2026

Serverless persistence: seven techniques nobody is logging

Function-level persistence across three major cloud providers, the telemetry each one does and does not emit by default, and the configuration changes that make detection possible.

Download the paper
Webinar48 minMarch 2026

Attribution without hand-waving: how Labs assesses confidence

The evidence classes, the analytic standards and the cases where we got it wrong — presented by the Guardian Labs attribution team with unredacted worked examples.

Watch on demand

Questions

What intelligence teams ask us first

Is our telemetry used to produce intelligence for other customers?

Behavioural patterns and indicators of compromise are, after pseudonymisation and aggregation — that is what makes a 6,800-organisation sensor network valuable to every participant. Your content, filenames, user identities, hostnames and business data are never included, never leave your region, and never train a shared model. The full data handling specification is published in Trust and security, and participation in aggregate research can be disabled.

Can we use Guardian intelligence in a third-party SIEM?

Yes. Feeds are delivered over TAXII 2.1, MISP, REST and webhook, and detection content is published as Sigma and YARA alongside the native Guardian format. Prebuilt integrations exist for Splunk, Microsoft Sentinel, QRadar, Elastic and Google SecOps — see the integrations page.

How do you avoid drowning us in indicators?

Three ways. Confidence decays automatically, so a hash from an eight-month-old campaign no longer fires at full weight. Feeds are scoped to your sector, region and technology stack from your own asset inventory. And Sentinel matches on behaviour first, using indicators as corroboration rather than as the primary trigger — which is why indicator volume does not translate into alert volume.

Do you provide a dedicated intelligence analyst?

On the Enterprise plan and with Guardian MDR, yes: a named Labs liaison, a quarterly threat-landscape briefing tailored to your sector and geography, priority requests for information with a 24-hour response commitment, and direct access to the analysts who wrote the relevant research.

What happens when Labs attributes something incorrectly?

We publish the correction with the same distribution as the original assessment, restate the confidence level, and record what evidence changed. Cluster reassignments are versioned in the adversary profile feed so downstream tooling picks them up automatically. Our published analytic standards and confidence definitions are available to any customer on request.

Can we submit our own indicators and get them enriched?

Yes. Submit hashes, domains, IPs or full samples through the API or console for enrichment against the Guardian corpus, including sandbox detonation, cluster association and a prevalence figure across the sensor network. Submissions are private to your tenant by default; you can opt in to sharing where it helps the wider community.

Find out which adversaries are already targeting your sector

A Guardian Labs exposure briefing maps the groups active against your industry and geography, the techniques they favour, and the specific detection coverage you have against each one today.