GUARDIANVIGIL

GUARDIANVIGIL // OPERATIONS & ENGAGEMENTS

CONSULTING: ACTIVE
OPEN-SOURCE R&D: ONGOING
Practice Areas

Security Engineering & Threat Intelligence Services

Building IntelStack is most of what we do. The rest is threat research, security tooling and pipeline architecture for teams who need a specific thing built properly.

Adversary Infrastructure and Campaign Analysis

Threat Research

Focused research on a threat you are actually facing, rather than a quarterly report about threats in general. We take a set of indicators, an incident, or a suspicion, and work out what is behind it and what else it touches.

Shape
Fixed-scope, 1–3 weeks
Starts When
You send indicators or an incident summary
What You Get
Infrastructure teardown — what an indicator connects to and why we believe it
Campaign timeline reconstructed from observed activity, with confidence stated per link
Indicator package in a format your tooling can ingest
A written analysis your team can act on without a follow-up call
Connectors, Parsers and Collection

Security Tool Development

The unglamorous plumbing between the tools you already run. Most teams do not need another platform; they need the feed they pay for to land in the system that consumes it, reliably, without somebody babysitting a cron job.

Shape
Fixed-scope or retained
Starts When
You describe the two systems that need to talk
What You Get
Connectors and normalisers between your feeds and your existing stack
Indicator extraction and deduplication that survives a provider changing its schema
Containerised, with a CI pipeline and a runbook for the day it breaks
Open-sourced by default unless the work is specific to your environment
Design Review and Build

Pipeline and Architecture Engineering

Design and review of threat intelligence ingestion, secret handling and the paths between your services. This is the same work that produced IntelStack's own architecture — where the trust boundary sits, and the decision that no client ever reaches an analysis service directly.

Shape
Review from 1 week; build scoped after
Starts When
You share an architecture diagram or a repository
What You Get
Architecture review with findings ranked by what is actually reachable
Ingestion pipeline design sized to your volume, not to a reference diagram
Secret management and key rotation that can be performed without downtime
Container and deployment hardening
Teaching the Thing Rather Than Selling It

Workshops and Knowledge Transfer

Sessions for analysts and engineers on graph-based threat modelling, provider scoring, and reading a detonation report critically. Run for teams, university groups and community events.

Shape
Half-day to two days
Starts When
You tell us the audience and their level
What You Get
Threat modelling and graph analysis workshops, run against your own data
Threat hunting playbooks written for your stack
Detection engineering review — what your rules do and do not cover
Mentoring for people moving into security engineering

What We Do Not Do

Cheaper to Read Now Than to Discover in Week Three

We are two people. The list below is work we will turn down, and we would rather you knew that before a call than after a proposal.

Offensive engagements

We do defensive work. For a red team or a pentest, you want a specialist firm.

24/7 monitoring or managed SOC

Two people cannot staff a rota, and pretending otherwise would fail you at 3am.

Compliance certification

We can build the technical controls; we cannot sign an audit.

Incident response retainers

We will help you understand an incident after the fact, but we are not an on-call IR team.

Our Collaboration Methodology

How We Work With Security Teams and Organizations

01. Discovery & Scope

Initial assessment of your current threat model, feed sources, and defensive requirements.

02. Technical Architecture

Agreeing the data flows and integration points before anything gets built.

03. Implementation & QA

Engineering tools with rigorous testing, CI/CD, and containerized deployment packages.

04. Knowledge Transfer

Detailed technical handover, playbooks, and ongoing advisory support.

Have a Project Brief or Custom Requirement?

Transmit your technical requirements to schedule an initial consultation with our lead researchers.

Send Project Brief