Threat intelligence in the wild
How real intrusions are actually being run, right now.
Security advice ages badly. We track how intrusions are actually being carried out today — the tooling, the techniques, the shift toward AI-operated attacks — and turn it into briefings your team can act on, rather than a headline read months after the fact. Our MARLEYNODE series is where this work is published.

What you get
A deliverable, not a dashboard to babysit
Briefings and deeper research, some restricted to named recipients.
- Plain-English briefings on live attacker behaviour, written for decision-makers
- The MARLEYNODE series on AI-operated intrusion (offensive, detection, board, defence)
- Deeper technical write-ups for your security team where relevant
- New drops delivered to your portal, not lost in a newsletter
How it works
Four steps, and you stay in control of each
- 01
We track what is live
Real campaigns and techniques as they are being used, not textbook theory.
- 02
We separate the audiences
A board briefing and an engineer's write-up are different documents — you get the one you need.
- 03
We restrict what should be
The most sensitive material is shared with named people, under a distribution marking.
- 04
You act on it early
Understand the shift while there is still time to prepare for it.
Want this for your business?
Briefings and deeper research, some restricted to named recipients. Tell us a little about your setup and we'll come back with how it would work for you.