Resources
Research you can take to the stand-up.
Finished intelligence, working papers, and sessions for detection engineers and CTI leads. No vendor keynote energy.
Research
All research
2026-08-12 · 9 min
From IOC to behavior: retiring indicator-only detection
Most intel programs still measure themselves in indicators shipped. The programs that reduce incidents measure coverage that survives infrastructure turnover.

2026-07-02 · 12 min
Volt Typhoon’s living-off-the-land shift, 18 months on
The tradecraft did not disappear when the first round of advisories landed. It got quieter, closer to the identity plane, and harder to IOC.

2026-05-21 · 8 min
What FIN7’s latest toolkit means for payment processors
The loaders changed. The interest in card-present and orchestration platforms did not. A practical read for fraud and detection teams.

2026-04-08 · 7 min
TAXII 2.1 in practice: why most intel never reaches detection
The standard works. The operating model around it usually does not. A field note from programs that actually close the loop.
Whitepapers
All briefsQuestions
Common questions
- What is in the Attack Nemesis resource library?
- Research notes, whitepapers, and webinars for detection engineers and CTI leads. Each one is meant to change something at your next stand-up, not fill a reading list. Attack Nemesis publishes finished intelligence and working papers, not vendor keynotes.
- Who writes Attack Nemesis research?
- Practitioners: Elena Cho, head of intelligence; Julian Okoye, CTO and former national CSIRT and bank detection-engineering lead; Mira Shah, CEO; and the Attack Nemesis Research team. Attack Nemesis research is written by people who still read the raw collection.
- How do I get an Attack Nemesis whitepaper or webinar seat?
- Open the brief or session page and fill in the short form. Whitepapers go to the work email you provide, without a marketing sequence. Attack Nemesis gates briefs with one short form and nothing after it.
- Where should I start in the Attack Nemesis library?
- Small team: CTI for the understaffed SOC. Detection backlog: Detection engineering from threat intelligence. Board questions: Board-level threat metrics that matter. Each starts from a real operational problem. Attack Nemesis research is organized around the problem in front of you, not the product.
Next step
See the platform against your environment.
A forty-minute briefing: your sources, your stack, and the tickets that should already exist.