Resource center

Everything Guardian knows, written down

Adversary research, architecture guidance, measured customer outcomes, product specifications and plain-English definitions — 640 pieces of published material, all free, none of it gated behind a sales call.

Popular right now: 2026 Threat Landscape Report · Breakout time analysis · What is identity threat detection?

Browse by type

Six libraries, one index

Each collection is maintained by the team that owns the subject matter — Guardian Labs for research, the product organisation for specifications, and the services practices for the operational guidance.

Browse by topic

The library

Filter by subject to see everything Guardian has published on it, across all six content types.

WhitepaperCloud & containers

Kubernetes attack paths: from exposed dashboard to cluster admin

Eight documented escalation chains observed in production clusters, each with the RBAC change or admission policy that breaks it.

34 pages Read
ArticleIdentity security

Session token theft has overtaken password attacks

Why stolen cookies now beat MFA more often than credential stuffing does, and the four controls that make a token worthless off-device.

9 min read Read
Case studyManufacturing

Keeping 22 plants running through a supply chain compromise

A vendor update carried a loader into the IT estate. Containment held it out of the OT network, and no production line stopped.

7 min read Read
WebinarAutomation & AI

What an AI analyst actually does with an alert

A live walkthrough of the Sentinel reasoning chain: enrichment, hypothesis, evidence weighting, and where a human is still required to decide.

52 min Watch
GuideCompliance & risk

DORA resilience testing without breaking production

How threat-led penetration testing requirements map onto an existing offensive security programme, and what evidence supervisors expect.

18 pages Read
DatasheetEndpoint security

Sentinel endpoint agent: platforms, footprint and scale limits

Supported kernels, average CPU and memory consumption under load, offline behaviour and rollback semantics, with sizing tables to 500,000 endpoints.

Version 9.4 Open
ArticleIncident response

The first ninety minutes: a containment decision framework

Isolate, observe or rebuild — a structured way to make the call under pressure, with the evidence each option destroys or preserves.

11 min read Read
WhitepaperOT & critical infrastructure

Monitoring the IT/OT boundary without touching a controller

A passive-first reference architecture for Purdue levels 2 to 3.5, with protocol coverage and safety review guidance.

28 pages Read
GlossaryThreat detection

What is behavioural detection, and how does it differ from anomaly detection?

Two terms used interchangeably that describe different things, with worked examples of where each succeeds and each generates noise.

Definition Open

Guardian Labs

Research published on a schedule, not when marketing needs a launch

Guardian Labs is a 140-person research organisation with a standing publication commitment: weekly adversary tracking notes, monthly detection content releases, quarterly deep research and an annual landscape report. Nothing on this site is behind a form, and nothing is written by someone who has not done the work.

  • Every statistic cites its population, window and method
  • Detection logic in research posts is published as Sigma, free to reuse
  • Corrections are issued publicly with a dated change note
  • Vulnerability research follows a 90-day coordinated disclosure policy

Published output

Last eight quarters

Items published per quarter across all six libraries.

0 30 60 90 120 Q1 24 Q2 24 Q3 24 Q4 24 Q1 25 Q2 25 Q3 25 Q4 25 52 108 Articles Research Customer stories Video & events

Curated collections

Reading lists assembled for a job, not a topic

If you have ninety minutes and a specific problem, start with one of these sequences rather than the search box.

Evaluating an XDR platform

Seven items covering architecture questions to ask, how to design a proof of value, and the metrics that separate marketing claims from operational reality.

7 items · ~90 min Open

Building an incident response capability

From retainer decision to runbook library to the first tabletop, with templates for the incident record and the regulatory notification clock.

9 items · ~2 h Open

Securing a multi-cloud estate

Identity-first architecture, workload protection, IaC guardrails and the runtime signals that matter once the build pipeline has done its job.

8 items · ~2 h Open

Your first SOC 2 or ISO 27001

Scoping decisions that cost or save months, the control library approach, and what continuous evidence collection changes about audit season.

6 items · ~75 min Open

The Thursday briefing

New adversary tradecraft in your inbox every week

One email, every Thursday: what Guardian Labs observed that week, the detection logic to catch it, and a short note on anything that changed in the platform. Read by 94,000 security practitioners. No product spam, and one-click unsubscribe in every issue.

We use this address only to send the briefing.

Also send me

Issue 214 · 30 July 2026

In this issue: PALE MERIDIAN moves to OAuth consent phishing; three new Sigma rules for CI/CD token abuse; why your SSO logs are missing the field that matters.

Issue 213 · 23 July 2026

In this issue: A ransomware affiliate switching to ESXi first; measuring detection coverage honestly; the case against 90-day password rotation, again.

Back issues are published to the blog two weeks after they are sent.

Looking for something else?

Not everything lives in the library

Product documentation

Deployment guides, API reference and integration recipes live in the support portal alongside version-specific release notes.

Go to support

Trust and compliance artefacts

Our SOC 2 Type II report, ISO 27001 certificate, penetration test summary and subprocessor list are available on request through the trust center.

Open trust center

Press and analyst enquiries

Media kit, executive biographies, brand assets and the fastest route to a Guardian Labs researcher for comment.

Visit the newsroom

Read enough. Want to see it running?

A Guardian engineer will walk you through the console with your own use cases in the room — not a canned demo environment.