Topic hub
Cyber research
Definition
Cyber threat research — is the systematic investigation of adversary tooling, infrastructure and behaviour — malware analysis, campaign attribution and technique documentation — carried out to make the resulting knowledge usable in defence.
We publish what we find. The analysts on a retainer are the same team that tracks state-sponsored actors and ships the open-source tooling, and what we see in the field shapes the hunts we run for clients — often before the technique is widely documented.
What we research
Our published work covers state-sponsored actors and the campaigns they run, wiper malware — including the campaign we track as Operation HANDALA — and the reverse engineering of specific tooling encountered in live intrusions. We write up the intrusions themselves as case studies where the client permits it, because a technique explained against a real timeline is far more useful than one described in the abstract.
Why a response firm publishes research
Research and response are the same work seen from two directions. A campaign taken apart in the lab produces the detection logic and hunting hypotheses used on the next engagement; an intrusion worked in the field produces the samples and infrastructure that become the next piece of research. Separating the two, as larger firms tend to, means the people who know the actor best are not the people on your call.
Where we present it
We present at GISEC Global, GPEC and HackExpo, brief international delegations on our wiper malware research, and sit in the Israel National Cyber Directorate MIRROR Forum alongside fourteen other Israeli incident response companies. Everything we publish is free to read and free to use, with no registration gate.
Everything we have published on cyber research
18 pieces of research, tooling and case-study work.
Common questions
What is cyber threat research?
Cyber threat research is the systematic investigation of adversary tooling, infrastructure and behaviour — reverse engineering malware, mapping command and control infrastructure, attributing campaigns to actors, and documenting techniques. Its purpose is to convert what an adversary does into detection logic and hunting hypotheses defenders can use.
What is an APT?
An APT, or advanced persistent threat, is a well-resourced adversary — usually state-sponsored or state-aligned — that targets a specific organization and maintains access over an extended period rather than seeking immediate financial gain. The defining characteristics are persistence, operational discipline, and a willingness to spend months on a single target.
What is wiper malware?
Wiper malware is designed to destroy data irrecoverably rather than to encrypt it for ransom. It is often disguised as ransomware — presenting a ransom note for data that no longer exists — because the disguise buys time and confuses the initial response. Recovery depends entirely on backups that were isolated from the affected environment.
What is Operation HANDALA?
Operation HANDALA is the name IONSEC uses for a wiper malware campaign it has tracked and published research on, and which it has briefed to international delegations including a Czech delegation hosted in Israel. The research is published in full on the IONSEC resources section.
Is IONSEC research free to read?
Yes. All IONSEC threat research and all six of its DFIR tools are published without a registration gate, paywall or lead-capture form.
Related topics
Incident response
Incident response is the structured process an organization follows to detect, contain, eradicate and recover from a cyber attack, and to establish how the attacker got in and what they accessed.
Digital forensics (DFIR)
Digital forensics and incident response (DFIR) is the combined discipline of collecting and analysing digital evidence to establish what happened during a cyber attack, and managing that attack end to end.
AI security
AI security is the practice of securing artificial intelligence systems — models, agent runtimes and the tooling they invoke — against attack, and of investigating incidents in which those systems are the target or the means.
Talk to the team that does the work
The people who publish the research above are the people who take your escalations.