By invitation

Cerebro

Threat intelligence desk and offensive services. Member firms report incidents in confidence. The desk removes identifying detail, verifies the technique in lab, and redistributes it as a hunt the rest of the membership can run against their own environments.

FunctionThreat intelligence desk. Offensive security services.
AccessBy invitation. Three tiers: Signal, Circle, the Ring.There is no self-service signup. Every member is admitted by a person.
CoverageNetwork, endpoint, cloud, identity, OT, supply chain, hypervisor.Any layer where an attack method can be reused against someone else.
OutputVerified hunt packages with a runnable query per platform.
ExportSigma STIX/TAXII MISP and SIEM-native query formats.
Hard constraintVictim identity and raw customer data do not leave the desk.

The problem

A firm gets compromised. Counsel advises against disclosure. Eleven months later a filing appears with the technical detail removed. In the interval the same method works on other firms, because none of them knew to look for it.

The obstacle is exposure, not unwillingness. Security leaders will discuss an incident in detail in a room where it cannot be traced back to them, and will say nothing at all anywhere else. Most intelligence products work around this by dealing in indicators that are already public by the time they ship.

Cerebro is built to be that room. The desk sits between the firm that was hit and the members who need the technique, and identity does not cross it.

The desk

Four stages, run by operators. The interval from a member reporting an incident to the rest of the membership having a hunt for it is usually under a day.

1 · IntakeA member submits an incident in whatever form exists: a timeline, a console export, partial IR notes written mid-response. No template, no portal, no minimum quality bar.
2 · SanitizeAn operator removes identity, customer data, hostnames, address ranges, timestamps precise enough to correlate, and anything else that fingerprints the source. The event is restated as technique: what was attacked, at which layer, in what order, and how it presented to the defender.
3 · VerifyThe technique is reproduced in lab and the hunt is tested against representative telemetry. A hunt that returns nothing on a real estate does not get published; it trains analysts to ignore the feed.
4 · PublishSharp packet to the Ring, sanitized packet to the wider membership, in the query language the member already runs. Each package states the technique class, the layer attacked, what to hunt for, and which benign patterns will produce false positives.
Typical intervalUnder 24 hours, intake to first distribution.

What a member receives

A hunt package is written to be executed the day it arrives, by an analyst who was not involved in the original incident.

QueryOne runnable query per supported platform, written against the telemetry the member already collects.
Required telemetryThe specific log sources and fields the query depends on, stated up front so a gap is visible before the hunt is run.
Expected resultWhat a true positive looks like in the output, and the known benign patterns that will also match.
Technique detailLayer attacked, order of operations, and the preconditions the method needs. Enough to judge whether it applies to your estate.
Two-packet splitEvery event produces a sanitized packet for wide distribution and a sharp packet with full tradecraft detail that stays inside the Ring.
SanitizationPerformed by an operator who has run the offensive side of comparable engagements. It is a rewrite, and it happens before distribution rather than after.

Membership

Access widens as trust is established. Trust is established by contributing. Admission at every tier is a decision made by a person at the desk.

Tier one

Signal

For teams that want the hunts without joining an operator community.

  • Sanitized hunt packages as they publish
  • Runnable queries for your platform
  • Weekly tradecraft brief
  • Sigma, STIX/TAXII and MISP export
Tier two

Circle

For teams that will report as well as receive. Admission requires a named operator contact.

  • Everything in Signal
  • Submit incidents to the desk in confidence
  • Full technique detail on published packets
  • Request a hunt against your own stack
  • Quarterly operator sessions
Tier three · By nomination

The Ring

The Allied Tradecraft Ring. A small core of operators who see raw tradecraft ahead of distribution.

  • Everything in Circle
  • Sharp packets ahead of wide distribution
  • Direct line to the desk during an incident
  • Co-authored hunt packages
  • Entry is nominated by existing members

Offensive services

Penetration testing and adversary emulation, delivered by the same operators who write the hunts.

Running offensive work inside the intelligence company closes a loop. What our operators prove works in one environment becomes a sanitized hunt for the membership, and the tradecraft the desk collects informs the next engagement.

Your report stays yours. Nothing identifying leaves under any circumstance. What travels is the method, stripped of you, and only after the sanitization stage above.

Charter

A sharing community works for exactly as long as the first firm to report does not regret it. These five are not negotiable and are not tier-dependent.

The victim is never namedNot to members, not to the Ring, not in any packet, not verbally
ABSOLUTE
Raw customer data never leaves the deskSanitization happens before distribution
ABSOLUTE
Nothing publishes unverifiedIf the desk cannot reproduce it, it does not ship as a hunt
ABSOLUTE
Reporting is never a condition of receivingA firm mid-incident owes the desk nothing
ABSOLUTE
Entry to the Ring is nominatedMembers put names forward; the desk does not sell entry
ABSOLUTE

Request an invitation

Tell us what you run, what you have seen, and what you would be willing to share. We will tell you which tier fits and what admission would involve.