A Failed Lookup Is Not a Clean Verdict
The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.
We build IntelStack — a threat intelligence platform that tells you which provider contributed each point of a verdict, and says unknown when it does not know. Alongside it we do threat research and security engineering for teams who need something built properly.
Our flagship Cyber Threat Intelligence platform connecting graph databases, multi-feed IOC ingestion, and AI triage.
Engineering defensive utilities, parsers, and automated threat collectors accessible to security analysts worldwide.
In-depth adversary campaign tracking, infrastructure teardowns, and actionable indicator disclosures.
Custom threat pipeline integrations, architectural reviews, and automated detection rule engineering.
Two People, One Product, and the Work That Funds It
GuardianVigil is a small cybersecurity company. Not a lab, not a collective — two people who got tired of threat intelligence tooling that was either priced for a bank or built as a spreadsheet with a login page.
Most of what we do is build IntelStack, a threat intelligence platform for teams who need to know whether an indicator is worth acting on and how confident that answer really is. It is in pre-release. We fund the build with threat research and security engineering work, which is the second thing we do and the reason the first thing has no investors attached to it.
We publish our scoring weights, our architecture, and the defects we shipped and had to remove. That is not modesty. A threat intelligence product that cannot show you why it reached a verdict is asking you to trust a number, and there is no good reason to do that.
The Same Twelve Indicators, Stored Two Ways
Six rows, no relationships. An analyst who blocks the first address learns nothing about the other five, and cannot tell whether this is one campaign or six unrelated hits.
The same six, with the relationships that were actually observed between them. Blocking the centre node is now a decision about a cluster, not a row — and the two samples at the left are visibly the same operation.
This is the entire argument for the product. Indicators are cheap and nobody is short of them; what a SOC is short of is the context that says which ones matter together. The catch is that a graph is only worth trusting if its edges are real — which is why ours are written from observation and never inferred from a verdict.
Cyber Threat Intelligence Platform — Pre-Release
IntelStack scans an indicator against twenty threat intelligence providers at once and shows you which provider contributed each point of the verdict. It detonates files and URLs in an isolated worker, and records what it observes as a graph the next analyst can pivot through. The one rule it will not break: a lookup that failed is reported as unknown, never as clean.
One indicator, twenty providers in parallel, and a distinct state for every kind of non-answer.
Six of these eight states are not findings. Unlisted means the provider answered and holds no record; Unconfigured means we have no key and never asked; Error means we asked and learned nothing. They stay grey and orange because none of them is evidence. Most scanners collapse all three into green.
Threat Research, Tooling and Security Engineering
Cutting-edge offensive and defensive research into emerging cyber threats, adversary campaigns, and evasive malware architectures.
Engineering high-performance, open-source security utilities and platforms designed to democratize cyber threat intelligence for security teams worldwide.
Fostering an open ecosystem of security researchers, incident responders, and engineers to share indicators, research briefs, and defense playbooks.
End-to-end security architecture design, custom threat intelligence pipeline integrations, and validation testing for resilient digital infrastructure.
Four Steps, No Discovery Phase That Bills for Itself
What you have, what is missing, and whether we are the right people for it.
The data flows and integration points, agreed before anything is built.
Tested, containerised, and running in your environment rather than a demo.
Documentation and a walkthrough, so it survives us leaving.
Original Threat Research & Campaign Attributions
The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.
Most multi-source scanners count votes. But a MalwareBazaar hit means somebody submitted the actual binary, and a GreyNoise hit means the address scans the internet. Treating those as equal votes produces confident nonsense.
Interface decisions in a security console are not aesthetic. A monospace font prevents an l/1 confusion in an indicator, and a colour choice decides what an analyst believes before they have read a word.
Leadership & Principal Security Researchers
Founder & Lead Security Researcher
Passionate cybersecurity researcher, threat intelligence specialist, and creator of IntelStack. Dedicated to building open-source defensive security tools and empowering the global security community.
Head of UI/UX & Product Design
Product designer crafting modern, high-density cyber interfaces and developer tools. Lead designer behind GuardianVigil and the IntelStack SaaS design system.
Project Briefs, Beta Access and Anything Else
For engagements, beta access, or a question about how something in IntelStack works. Both of us read it. Expect a reply within two business days — if you do not get one, the form failed and email is the reliable path.
Found a vulnerability in one of our tools or in IntelStack? Send the details to the address above and we will acknowledge it within two business days. We will not pursue action against good-faith research, and we will credit you unless you ask us not to.