Guardian Labs research library

Whitepapers and threat reports for people who have to make the decision

Primary research from the analysts, reverse engineers and detection engineers behind Guardian Sentinel. Every paper is built on first-party telemetry from 4.2 trillion weekly security events and 6,800 production deployments — not on vendor surveys.

The library

Ten papers, all peer-reviewed inside Guardian Labs

Each asset is gated behind a single short form. Fill it once and every paper below unlocks for the rest of your session, plus a PDF copy in your inbox.

Filter All papers 10 Threat research Architecture SOC operations Compliance Cloud Sorted by newest
Threat research58 pagesPDF

Ransomware Playbooks 2026: Anatomy of Nine Active Affiliate Programmes

A technical teardown of nine ransomware-as-a-service operations, from initial access brokerage through negotiation. Includes affiliate tooling inventories, encryption routines, data-staging patterns and the exact detection logic Guardian ships for each family.

Gated Published Jun 2026
Unlock this paper
Architecture64 pagesPDF

Zero Trust Reference Design for Hybrid Enterprises

A buildable architecture, not a philosophy deck. Covers policy decision and enforcement point placement, device trust signals, segmentation of legacy east-west traffic, and a phased 18-month migration plan with rollback criteria at every gate.

Gated Published May 2026
Unlock this paper
Identity46 pagesPDF

Identity Is the Perimeter: Defending Against Token Theft and Session Hijack

Adversary-in-the-middle phishing kits now defeat most push-based MFA in under 90 seconds. This paper documents the theft-to-replay chain across major identity providers and specifies the conditional access, token binding and detection controls that actually break it.

Gated Published May 2026
Unlock this paper
Cloud41 pagesPDF

Cloud Detection Engineering: Runtime Coverage for Kubernetes

Container escape, privileged sidecar abuse and malicious admission webhooks rarely appear in cloud posture scans. We map 34 runtime attack techniques to observable kernel and audit-log signals, then publish the eBPF-derived detections and their measured false-positive rates.

Gated Published Apr 2026
Unlock this paper
SOC operations28 pagesPDF

The SOC Automation Maturity Model

Five levels, from manual triage to closed-loop autonomous response, with objective entry and exit criteria for each. Includes the staffing ratios, mean-time-to-contain targets and guardrail design patterns observed across 412 Guardian-operated security operations centres.

Gated Published Apr 2026
Unlock this paper
Executive32 pagesPDF

The Economics of Autonomous Response: Cost per Incident

A cost model board members can interrogate. We decompose the fully loaded cost of an incident across analyst hours, business downtime, regulatory exposure and cyber-insurance retention, then quantify what each minute of reduced containment time is worth in each of six industries.

Gated Published Mar 2026
Unlock this paper
Compliance44 pagesPDF

DORA and NIS2 Readiness: A Control-by-Control Implementation Guide

Both regimes demand evidence, not intent. This guide maps every operational-resilience and incident-reporting obligation to a concrete technical control, names the artefact an auditor will ask for, and flags the seven requirements most organisations discover too late.

Gated Published Mar 2026
Unlock this paper
Detection engineering39 pagesPDF

Measuring Real Detection Coverage Against MITRE ATT&CK

Coverage heat maps flatter every vendor. We propose a weighted scoring method that accounts for technique prevalence, telemetry fidelity and analytic robustness, then apply it honestly to Guardian Sentinel — including the sub-techniques where we score poorly and why.

Gated Published Feb 2026
Unlock this paper
Emerging technology36 pagesPDF

AI Model Supply Chain Risk: Threats to MLOps Pipelines

Model registries, notebook infrastructure and vector stores are now production systems with production blast radius. We catalogue serialisation attacks, training-data poisoning and retrieval injection, and define the minimum viable controls for teams shipping models weekly.

Gated Published Feb 2026
Unlock this paper
Industry52 pagesPDF

Securing Operational Technology: IEC 62443 Mapped to Sentinel Controls

Written for plant engineers and security teams who have to agree. Covers passive asset discovery on Purdue levels 0–3, safe protocol parsing for Modbus, DNP3 and OPC UA, and change-window-aware response that never trips a safety instrumented system.

Gated Published Jan 2026
Unlock this paper

Methodology

How a Guardian Labs paper is made

Nothing is published because it makes a good headline. Every claim in these papers traces back to observed telemetry, casework or a reproducible lab result, and every draft survives an internal red-team review before it leaves the building.

Telemetry 4.2T weekly events, 142 countries Casework 2,100+ incident response engagements Lab reproduction Detonation range, 9 OS baselines Adversarial review Internal red team argues the opposite Publication Paper, detections and IOC package ship together

Evidence before narrative

Analysts start from a telemetry question, not a conclusion. A hypothesis that cannot be tested against at least 90 days of observed data is not published, and sample sizes appear next to every statistic in the paper.

Reproduce in the range

Every technique described is detonated in an isolated range across Windows, macOS, Linux, Kubernetes and cloud control-plane baselines so the observable signals we claim are the signals a customer will actually see.

Argue against it

A separate red team reviews each draft with a mandate to disprove it. Findings that survive are marked high confidence; findings that partially survive are published with the caveat attached, not quietly removed.

Ship the defence with the research

No paper is released before the corresponding detections, hunt queries and indicator packages are live in Guardian Sentinel for every customer. Research that only tells you a problem exists is marketing, not security.

Customer data never leaves the aggregate All statistics are computed on de-identified, aggregated telemetry. No customer, environment or individual is identifiable in any published paper, and case material is used only with written consent. Read our trust and security commitments.

Where to start

Reading paths by role

Eighty-four pages is a lot of evening. Pick the track that matches the decision in front of you and read three papers instead of ten.

Read first

2026 Global Threat Landscape Report

The executive summary and chapter 2 give you the board-ready version of what changed this year, with the numbers sourced.

Then

The Economics of Autonomous Response

Turns containment time into currency so budget conversations stop being about tooling and start being about exposure.

Then

The SOC Automation Maturity Model

Gives you a defensible current-state rating and a twelve-month roadmap you can present without hand-waving.

Read first

Measuring Real Detection Coverage

Rebuild your coverage model with weighting that reflects technique prevalence and telemetry fidelity, not raw technique counts.

Then

Ransomware Playbooks 2026

Nine affiliate programmes broken down to tooling and timing, with the detection logic and hunt queries included.

Then

Identity Is the Perimeter

The theft-to-replay chain for session tokens, plus the analytics that catch replay from an unexpected network position.

Read first

Cloud Detection Engineering for Kubernetes

Thirty-four runtime techniques mapped to kernel and audit signals, with measured false-positive rates for each detection.

Then

Zero Trust Reference Design

Where to put policy decision and enforcement points when half the estate is still a datacentre you cannot re-architect.

Then

AI Model Supply Chain Risk

Minimum viable controls for model registries, notebooks and vector stores that are already in production.

Read first

DORA and NIS2 Readiness

Every obligation mapped to a control and the exact evidence artefact an examiner will request during a review.

Then

IEC 62443 Mapped to Sentinel Controls

Essential if any part of your regulated estate touches operational technology or safety instrumented systems.

Then

The Economics of Autonomous Response

Gives risk committees a quantified basis for residual-risk acceptance and cyber-insurance retention decisions.

See the complete resource library

Archive

Nine editions of the Global Threat Landscape Report

Every prior edition stays available so you can track how adversary economics moved, and check our earlier calls against what actually happened.

Global Threat Landscape Report, editions 2018–2026. All editions remain downloadable.
Edition Published Headline finding Pages Status
2026 — Edition 09 June 2026 Identity-based intrusion overtakes malware; breakout time falls to 41 minutes 84 Current
2025 — Edition 08 June 2025 Extortion without encryption becomes the majority ransomware model 78 Archived
2024 — Edition 07 May 2024 Cloud control-plane abuse emerges as a primary initial access vector 72 Archived
2023 — Edition 06 May 2023 Initial access brokerage industrialises; median listing price falls 38% 66 Archived
2022 — Edition 05 April 2022 Living-off-the-land tradecraft becomes standard across criminal operations 61 Archived
2021 — Edition 04 April 2021 Software supply chain compromise moves from theory to routine 58 Archived

Scroll the table sideways to see every column.

Editions 01–03 (2018–2020) are available on request through Guardian sales or your customer success manager.

One form, whole library

Unlock every paper

Complete the form once. You will get an immediate download link for the 2026 Global Threat Landscape Report and access to all ten papers in the library, plus the accompanying detection and indicator packages.

  • Instant download — no waiting for approval or a sales call first.
  • PDF and EPUB formats, plus a print-optimised executive summary.
  • Machine-readable IOC package in STIX 2.1 and a MISP-compatible feed.
  • Optional Thursday threat briefing. Unsubscribe in one click, no dark patterns.
What we do with your details We use them to deliver the papers and, if you opt in, to send research updates. We do not sell or rent contact data. See the Privacy Policy.
Your details

Free mailbox providers are not accepted for gated research.

Context

Keep going

Related resources

Customer case studies

Measured before-and-after results from named deployments across banking, healthcare, manufacturing and public sector, with the metrics that moved.

Read the case studies

Webinars & events

Guardian Labs analysts walk through the reports live every quarter, including the findings that were too sensitive to print.

See upcoming sessions

Datasheets & documentation

Module specifications, agent footprints, sizing guidance and deployment guides for teams moving from evaluation to rollout.

Open the datasheets

Looking for a term you do not recognise in one of the papers? The security glossary defines every acronym we use, and the Guardian Labs blog publishes shorter research between editions.

Research is useful. Coverage is better.

Every detection described in these papers is already live for Guardian customers. See what Sentinel finds in your environment during a 30-day evaluation.