Cerebro
Threat intelligence desk and offensive services. Member firms report incidents in confidence. The desk removes identifying detail, verifies the technique in lab, and redistributes it as a hunt the rest of the membership can run against their own environments.
Sigma STIX/TAXII MISP and SIEM-native query formats.The problem
A firm gets compromised. Counsel advises against disclosure. Eleven months later a filing appears with the technical detail removed. In the interval the same method works on other firms, because none of them knew to look for it.
The obstacle is exposure, not unwillingness. Security leaders will discuss an incident in detail in a room where it cannot be traced back to them, and will say nothing at all anywhere else. Most intelligence products work around this by dealing in indicators that are already public by the time they ship.
Cerebro is built to be that room. The desk sits between the firm that was hit and the members who need the technique, and identity does not cross it.
The desk
Four stages, run by operators. The interval from a member reporting an incident to the rest of the membership having a hunt for it is usually under a day.
What a member receives
A hunt package is written to be executed the day it arrives, by an analyst who was not involved in the original incident.
Membership
Access widens as trust is established. Trust is established by contributing. Admission at every tier is a decision made by a person at the desk.
Signal
For teams that want the hunts without joining an operator community.
- Sanitized hunt packages as they publish
- Runnable queries for your platform
- Weekly tradecraft brief
- Sigma, STIX/TAXII and MISP export
Circle
For teams that will report as well as receive. Admission requires a named operator contact.
- Everything in Signal
- Submit incidents to the desk in confidence
- Full technique detail on published packets
- Request a hunt against your own stack
- Quarterly operator sessions
The Ring
The Allied Tradecraft Ring. A small core of operators who see raw tradecraft ahead of distribution.
- Everything in Circle
- Sharp packets ahead of wide distribution
- Direct line to the desk during an incident
- Co-authored hunt packages
- Entry is nominated by existing members
Offensive services
Penetration testing and adversary emulation, delivered by the same operators who write the hunts.
Running offensive work inside the intelligence company closes a loop. What our operators prove works in one environment becomes a sanitized hunt for the membership, and the tradecraft the desk collects informs the next engagement.
Your report stays yours. Nothing identifying leaves under any circumstance. What travels is the method, stripped of you, and only after the sanitization stage above.
Charter
A sharing community works for exactly as long as the first firm to report does not regret it. These five are not negotiable and are not tier-dependent.
Request an invitation
Tell us what you run, what you have seen, and what you would be willing to share. We will tell you which tier fits and what admission would involve.