Guardian Labs & engineering

The Guardian blog

Adversary research, detection engineering practice, incident post-mortems and product engineering notes — written by the researchers and responders who did the work. 312 articles, two to four new every week, none of them behind a form.

Latest articles

Threat research

PALE MERIDIAN pivots to OAuth consent phishing against SaaS tenants

4 August 202611 min read

The supply-chain actor we track as PALE MERIDIAN has stopped bothering with credentials. Its current campaign registers a plausible multi-tenant application, harvests delegated consent from a single administrator, and reads mail across the tenant without ever touching a password or an MFA prompt. Detection logic and a tenant hardening checklist included.

Read the research
Identity

Session token theft has overtaken password attacks

29 July 20269 min read

Across our 2026 casework, stolen session cookies were the initial access vector in 34% of identity-driven intrusions, against 21% for credential stuffing. Multi-factor authentication does not help once the token exists. We look at the four controls that make a stolen token worthless off the device it was issued to, and the telemetry that proves they are working.

Read the article
Detection engineering

Budget for false positives before you write the rule

24 July 202613 min read

Every detection has a cost measured in analyst minutes, and most teams discover that cost only after deployment. We describe the practice Guardian's detection engineers use: assign each rule an explicit noise budget per 10,000 events, test against a replayed month of production telemetry, and refuse to ship anything that exceeds it. Includes the test harness we open-sourced.

Read the article
Incident response

Reconstructing a 41-minute breakout, hop by hop

17 July 202615 min read

A redacted walkthrough of a 2026 engagement at a European logistics operator: an unpatched file transfer appliance at 09:14, a harvested service account at 09:31, and domain-wide privilege at 09:55. We publish the timeline alongside the six telemetry sources that would have caught it, and the three that actually did — twenty-two minutes too late.

Read the post-mortem
Cloud security

Admission control is not a security boundary — until you make it one

10 July 202612 min read

Most Kubernetes admission policies we assess fail open, exempt too many namespaces, or run in audit mode two years after someone promised to enforce them. We walk through eight escalation chains observed in production clusters and the specific policy, RBAC change or runtime control that breaks each one — with the manifests.

Read the article
Product

Sentinel 9.4: autonomous rollback, wider eBPF coverage, 62 new detections

3 July 20266 min read

The July release brings transactional rollback for ransomware-encrypted files on Linux hosts, eBPF-based runtime telemetry on four additional kernel families, and a rewritten identity risk engine that scores sessions rather than accounts. Full change log, upgrade notes and the deprecations landing in 9.6.

Read the release notes
Identity

Why your SSO logs are missing the one field that matters

26 June 20268 min read

Almost every identity provider records that authentication succeeded. Far fewer record which authentication method actually satisfied the policy, and fewer still expose it in the export you ship to your SIEM. Without that field you cannot distinguish a phishing-resistant login from a push-notification approval — and neither can your detections.

Read the article
Compliance

NIS2 is enforced. Here is what supervisors are actually asking for.

19 June 202610 min read

Eighteen months into national transposition, patterns are emerging in how competent authorities across seven member states are exercising supervision. The questions are consistently about incident reporting timelines, supply chain oversight and management body accountability — and rarely about the technical measures organisations spent their budget on.

Read the analysis
Detection engineering

The trouble with ATT&CK heat maps

12 June 202614 min read

A wall of green squares is the most reassuring and least informative artefact in security. Coverage of a technique is not binary, most maps count rules rather than validated detections, and nobody colours in the procedures their tooling cannot see. We propose a scoring model with four levels and show what it does to a real customer's map.

Read the article
Threat research

Ransomware affiliates hit ESXi first. Your recovery plan assumes otherwise.

5 June 202612 min read

In 58% of the ransomware engagements Guardian handled in the first half of 2026, the hypervisor was encrypted before a single Windows endpoint was touched. Backups stored as virtual disks on the same cluster went with it. We set out the access paths affiliates use to reach the management interface and the four architectural changes that survive the attack.

Read the research
AI & automation

What our AI analyst gets wrong, and why we publish the failures

29 May 20269 min read

Sentinel's reasoning engine closes 91% of tier-one alerts without a human. This article is about the other 9%. We describe the three failure modes we see most — over-trusting asset context, collapsing similar-looking campaigns, and under-weighting rare-but-benign behaviour — and the guardrails that route each one to a person instead.

Read the article
Critical infrastructure

OT network monitoring without injecting a single packet

22 May 202611 min read

Active scanning has knocked over more production processes than most adversaries have. This is a reference architecture for passive visibility across Purdue levels 2 to 3.5: tap placement, protocol parsing for Modbus, DNP3 and OPC UA, asset inventory built from observation alone, and the safety review that has to happen before any of it is installed.

Read the architecture

Showing 1–12 of 312 articles.

Recurring series

Four things you can rely on arriving

Most of the blog is written when there is something to say. These four run to a fixed calendar, so you can plan around them.

Tracking notes

A short, technical update on one adversary group: what changed in their tooling, infrastructure or targeting this week, with fresh indicators.

Weekly Thursdays

Detection drop

Every new detection shipped to the platform that month, published as Sigma with the telemetry it needs and the noise profile we measured.

Monthly First Tuesday

Anatomy of an intrusion

One redacted incident response engagement reconstructed end to end, with the timeline, the telemetry gaps and the decisions we would make differently.

Monthly Third Wednesday

By the numbers

A quantitative look at one question — dwell time, patch latency, MFA bypass rates — using platform telemetry, with the method published in full.

Quarterly Second month

Who writes this

Practitioners, not a content team

Every article carries the name of the person who did the work. Guardian has no ghostwriters and no agency byline — if a post analyses an intrusion, the responder who handled it wrote it.

Dr Elena Vasquez

Director, Threat Research

Leads adversary tracking at Guardian Labs. Writes the annual threat landscape analysis and the quarterly benchmark series.

47 articles

Tomas Andersson

Principal Detection Engineer

Owns detection content standards. Writes the monthly detection drop and most of what the blog publishes about rule quality.

38 articles

Priya Nandakumar

Head of Incident Response

Has led over 300 breach engagements. Writes the anatomy of an intrusion series and the containment guidance.

31 articles

Marcus Oyelaran

Principal Cloud Security Architect

Works on Kubernetes and multi-cloud reference architecture. Writes most of what appears here under cloud security.

26 articles

Guardian Labs is 140 researchers across four offices. See the wider team on the leadership page, or the roles we are hiring for in careers.

Editorial standards

What gets published, and what does not

The blog is written by researchers and responders, reviewed by researchers and responders, and published on a schedule that does not bend to product launches. Four rules govern it.

Every number cites its method

If we say 58% of ransomware engagements began at the hypervisor, the post states the population, the observation window, the inclusion criteria and the cases we excluded. Statistics without a denominator are marketing, and we mark them as such when we quote other people's.

Detection logic is published, not teased

Research posts include working Sigma rules or query logic under a permissive licence, whether or not you are a Guardian customer. A finding you cannot act on is an advertisement.

Customers are never identifiable without consent

Incident write-ups are redacted of names, addresses, asset identifiers and any detail that would allow attribution, and are reviewed by the affected organisation before publication. Where a customer is named, as in case studies, they approved the final text.

Corrections are public and dated

When we get something wrong we amend the post, add a dated correction note at the top, and say what changed. Eleven corrections have been issued since 2024; all remain visible on the original articles.

Published 2024 – 2026

312 articles by category

312 articles published since January 2024
  • Threat research 84
  • Detection engineering 61
  • Incident response 48
  • Cloud security 39
  • Identity 31
  • AI, compliance, OT & product 49

The Thursday briefing

Everything above, a week earlier

Subscribers receive new research the day it is written, plus the detection content that goes with it. One email a week, no product spam, one-click unsubscribe.

See the research running as product

Everything Guardian Labs publishes ships as detection content in Guardian Sentinel, usually within days. Let an engineer show you the pipeline end to end.