GUARDIANVIGIL

GUARDIANVIGIL // OVERVIEW

INTELSTACK: PRE-RELEASE
OPERATIONS: OPEN

What GuardianVigil Is

Two People, One Product, and the Work That Funds It

GuardianVigil is a small cybersecurity company. Not a lab, not a collective — two people who got tired of threat intelligence tooling that was either priced for a bank or built as a spreadsheet with a login page.

Most of what we do is build IntelStack, a threat intelligence platform for teams who need to know whether an indicator is worth acting on and how confident that answer really is. It is in pre-release. We fund the build with threat research and security engineering work, which is the second thing we do and the reason the first thing has no investors attached to it.

We publish our scoring weights, our architecture, and the defects we shipped and had to remove. That is not modesty. A threat intelligence product that cannot show you why it reached a verdict is asking you to trust a number, and there is no good reason to do that.

CompanyTwo people
ProductIntelStack — pre-release
FundingResearch and engineering work
InvestorsNone

Why We Build It as a Graph

The Same Twelve Indicators, Stored Two Ways

As a listwhat most feeds hand you
192.0.2.41
sha256:4f2a…c19b
update-service.invalid
192.0.2.87
sha256:9d10…772e
cdn-metrics.invalid

Six rows, no relationships. An analyst who blocks the first address learns nothing about the other five, and cannot tell whether this is one campaign or six unrelated hits.

As a graphwhat IntelStack stores

The same six, with the relationships that were actually observed between them. Blocking the centre node is now a decision about a cluster, not a row — and the two samples at the left are visibly the same operation.

This is the entire argument for the product. Indicators are cheap and nobody is short of them; what a SOC is short of is the context that says which ones matter together. The catch is that a graph is only worth trusting if its edges are real — which is why ours are written from observation and never inferred from a verdict.

Flagship Product: IntelStack

Cyber Threat Intelligence Platform — Pre-Release

In DevelopmentProduct Details

IntelStack scans an indicator against twenty threat intelligence providers at once and shows you which provider contributed each point of the verdict. It detonates files and URLs in an isolated worker, and records what it observes as a graph the next analyst can pivot through. The one rule it will not break: a lookup that failed is reported as unknown, never as clean.

Multi-Source ScanningIllustrative — not a live observation

One indicator, twenty providers in parallel, and a distinct state for every kind of non-answer.

VirusTotal · MaliciousAbuseIPDB · SuspiciousGreyNoise · CleanThreatFox · UnlistedPulsedive · Unconfiguredurlscan.io · ErrorIPinfo · InfoShodan · Info

Six of these eight states are not findings. Unlisted means the provider answered and holds no record; Unconfigured means we have no key and never asked; Error means we asked and learned nothing. They stay grey and orange because none of them is evidence. Most scanners collapse all three into green.

Operations

Threat Research, Tooling and Security Engineering

All Operations
In-depth Threat Landscape Analysis

Research Insights

Cutting-edge offensive and defensive research into emerging cyber threats, adversary campaigns, and evasive malware architectures.

APT tracking & attribution
Zero-day vulnerability disclosures
Campaign timeline reconstruction
Indicator packages your tooling can ingest
Community-Driven Defensive Engineering

Open Source Tools Development

Engineering high-performance, open-source security utilities and platforms designed to democratize cyber threat intelligence for security teams worldwide.

IntelStack CTI platform development
Automated indicator collection and normalisation
Connectors for the intelligence platforms you already run
Telemetry collection that scales with your volume
Collective Security Intelligence

Community Collaboration

Fostering an open ecosystem of security researchers, incident responders, and engineers to share indicators, research briefs, and defense playbooks.

Open threat feed sharing
Collaborative malware triage
Security workshops & tech talks
Student & community mentoring
Production-Grade Security Architectures

Solution Architecture & Engineering

End-to-end security architecture design, custom threat intelligence pipeline integrations, and validation testing for resilient digital infrastructure.

Threat pipeline architecture
Cloud-native container security
Secret management & Zero Trust setup
Automated compliance & verification

How an Engagement Runs

Four Steps, No Discovery Phase That Bills for Itself

All Operations
01
Scope

What you have, what is missing, and whether we are the right people for it.

02
Architecture

The data flows and integration points, agreed before anything is built.

03
Build

Tested, containerised, and running in your environment rather than a demo.

04
Handover

Documentation and a walkthrough, so it survives us leaving.

Research & Engineering Notes

Original Threat Research & Campaign Attributions

All Articles
Open Source August 24, 2026

A Failed Lookup Is Not a Clean Verdict

The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.

#Detection Engineering#Data Integrity#Scoring
By Dharrmin SutharRead Analysis
Threat Intel August 12, 2026

Not Every Provider's "Malicious" Means the Same Thing

Most multi-source scanners count votes. But a MalwareBazaar hit means somebody submitted the actual binary, and a GreyNoise hit means the address scans the internet. Treating those as equal votes produces confident nonsense.

#Scoring#CTI#Provider Coverage
By Dharrmin SutharRead Analysis
Open Source July 28, 2026

Designing for Analysts Who Are Already Tired

Interface decisions in a security console are not aesthetic. A monospace font prevents an l/1 confusion in an indicator, and a colour choice decides what an analyst believes before they have read a word.

#Product Design#Design System#Security Operations
By Dixit KumarRead Analysis

Who We Are

Leadership & Principal Security Researchers

DS

Dharrmin Suthar

Founder & Lead Security Researcher

Passionate cybersecurity researcher, threat intelligence specialist, and creator of IntelStack. Dedicated to building open-source defensive security tools and empowering the global security community.

DK

Dixit Kumar

Head of UI/UX & Product Design

Product designer crafting modern, high-density cyber interfaces and developer tools. Lead designer behind GuardianVigil and the IntelStack SaaS design system.

Get in Touch

Project Briefs, Beta Access and Anything Else

Email
contact@guardianvigil.io

For engagements, beta access, or a question about how something in IntelStack works. Both of us read it. Expect a reply within two business days — if you do not get one, the form failed and email is the reliable path.

Security Disclosures

Found a vulnerability in one of our tools or in IntelStack? Send the details to the address above and we will acknowledge it within two business days. We will not pursue action against good-faith research, and we will credit you unless you ask us not to.