GUARDIANVIGIL

GUARDIANVIGIL // RESEARCH & ENGINEERING NOTES

ARTICLES: 3 PUBLISHED
TOPICS: CTI, DETECTION, DESIGN
Research & Engineering Notes

What We Learned Building It

Notes on threat intelligence scoring, detection engineering and interface design — written from the decisions and the mistakes behind IntelStack, not from a content calendar.

Open Source August 24, 2026

A Failed Lookup Is Not a Clean Verdict

The most dangerous line in a threat scanner is the catch block. We have found and removed the same defect twelve times in IntelStack: a provider call fails, and the scanner reports the indicator as clean.

#Detection Engineering#Data Integrity#Scoring#IntelStack
Dharrmin Suthar · 3 min readRead
Threat Intel August 12, 2026

Not Every Provider's "Malicious" Means the Same Thing

Most multi-source scanners count votes. But a MalwareBazaar hit means somebody submitted the actual binary, and a GreyNoise hit means the address scans the internet. Treating those as equal votes produces confident nonsense.

#Scoring#CTI#Provider Coverage#IntelStack
Dharrmin Suthar · 3 min readRead
Open Source July 28, 2026

Designing for Analysts Who Are Already Tired

Interface decisions in a security console are not aesthetic. A monospace font prevents an l/1 confusion in an indicator, and a colour choice decides what an analyst believes before they have read a word.

#Product Design#Design System#Security Operations
Dixit Kumar · 2 min readRead