Independent Cybersecurity Research
Hackerman Crew Services
A cyber research platform built to present threat intelligence, AI security, and future systems with command-grade clarity.
Hacking Just Feels Right.
Threat Intel • Field Notes • OSINT • AI Security • Disclosure
Independent cybersecurity research focused on threat intelligence, AI security, field notes, adversary tradecraft, and defensive experimentation.
Research Interface
Research is the command layer, not a supporting page.
The front page should feel like an active defensive environment: visible lanes, classified thinking, deliberate publication rules, and enough visual authority to support deeper systems later.
Research principles
Threat research
Investigations that feel active, not archived on arrival
Campaign notes, infrastructure analysis, and telemetry-backed observations should read like live operator thinking instead of reheated marketing prose.
AI security
Automation boundaries made visible
The interface should quietly communicate that authority, tooling, and agent trust boundaries matter as much as raw model capability.
Fenrir path
A stage worthy of future flagship systems
The visual system is being tightened so future showcases like Fenrir can land as first-class artifacts rather than awkward add-ons.
Featured Research
Current publications and research notes
Formal research stays structured and citable, but the surrounding presentation should carry more signal, more weight, and more future-facing presence.
Agent Trust Boundaries in Security Workflows
A defensive review structure for deciding what an AI-assisted security workflow should never be trusted to do autonomously.
Signals That Separate Disposable Phishing Infrastructure from Legitimate Brand Traffic
A practical set of technical and behavioral signals defenders can use to triage suspicious domains and impersonation sites.
Telemetry Baselines for Small IoT Segments
How small device enclaves can be monitored for suspicious communication without turning the network into a full-time forensics project.
Research Intelligence Feed
A defensive-intelligence wire, not a social feed.
The intelligence draft stays curated, review-gated, and intentionally limited. Automated ingestion, webhooks, and source activation remain off until explicit future approval.
Agent Trust Boundaries in Security Workflows
CONFIRMED
Internal research priority remains AI security controls that fail closed before an agent quietly expands authority.
Defending SaaS-based applications against ShinyHunters OAuth abuse
CONFIRMED
Useful current research for identity-first defenders: Microsoft ties overlapping ShinyHunters tradecraft to OAuth abuse, vishing, guest access misuse, and supply-chain pressure against SaaS environments.
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
CONFIRMED
Storm-1747 remains relevant because it shows how phishing-as-a-service normalizes MFA bypass at industrial scale. This is a strong fit for the research lane and the site's identity-attack coverage.
The Attack Cycle is Accelerating: Rapid7 2026 Global Threat Landscape Report
CONFIRMED
A strong anchor item for the page because it frames speed, identity abuse, ransomware economics, and AI as an accelerant instead of a separate category of magic.
Load more intelligence
Field Notes
A lighter format for observations that still matter.
Field Notes create room for shorter analysis without inflating every useful idea into a 4,000-word paper.
Field Notes
Conference signal worth keeping
Short-form observations have a home here so interesting infrastructure, social-engineering patterns, or AI-security experiments do not need to pretend they are full whitepapers.
Analysis
Evidence before narrative
Research starts from telemetry, artifacts, methods, and reproducible checks before it earns stronger claims or more polished storytelling.
Archived
Living work, dated on purpose
Notes and publications stay attributable, dated, and revisable so public work can evolve without losing its original context.
Research Areas
Organized around practical defender questions
Each research track supports future filters, deeper technical writing, and more attributable publication work.
Threat Intel
Threat Intelligence
Campaign tracking, infrastructure analysis, OSINT correlation, and intelligence workflows that help defenders reduce uncertainty.
AI Security
AI Security
Agent trust boundaries, prompt injection, tool abuse, context leakage, and defensive ways to use AI in security operations.
Phishing
Phishing
Brand impersonation, delivery infrastructure, detection signals, awareness gaps, and responder playbooks for modern phishing.
Malware
Malware
Malware behavior, persistence patterns, command-and-control telemetry, and practical defensive observations for analysts.
Network
Network Security
Segmentation, telemetry, IoT isolation, zero-trust controls, and evidence-driven approaches to unexpected network behavior.
Identity
Cloud & Identity
Suspicious authentication, exposed cloud services, identity controls, and investigation patterns for modern enterprise environments.
OSINT
OSINT
Research methods for finding, validating, and correlating public information into useful security intelligence.
Privacy
Privacy & Data Brokerage
Commercial data collection, brokered datasets, external exposure, and the security implications of privacy erosion.
Vulnerabilities
Vulnerability Research
Configuration flaws, product weaknesses, remediation patterns, and defensive lessons learned from vulnerability analysis.
Foundations
Grounded in current security frameworks and public guidance.
The public-facing research themes on this site track current guidance from NIST, CISA, and OWASP so the baseline assumptions stay inspectable.
NIST AI Risk Management Framework
Risk framing for trustworthy and governable AI use.
Review source (External)NIST AI RMF Generative AI Profile (NIST-AI-600-1)
Applied guidance for generative AI risk management.
Review source (External)OWASP GenAI LLM Top 10 2026
Current community-driven list of common GenAI application risks.
Review source (External)NIST SP 800-207 Zero Trust Architecture
Identity- and resource-centric architecture guidance.
Review source (External)The Lab
Public methods where useful. Private boundaries where necessary.
The lab is intentionally structured around active experiments, released work, methods, and clearly restricted areas rather than performative secrecy.
Some things belong on GitHub. Some belong in a research paper. Some stay in the lab.Enter The Lab
Future Flagship
Fenrir needs a stage that already feels powerful before it arrives.
This visual language is being shaped so larger systems, named programs, and deeper showcases can be revealed without needing the entire site to be reinvented later.
Read the background