Independent Cybersecurity Research

Operational publication laneCurated intelligence, controlled lab work, and flagship-ready showcase space.

Hackerman Crew Services

A cyber research platform built to present threat intelligence, AI security, and future systems with command-grade clarity.

Hacking Just Feels Right.

Threat Intel • Field Notes • OSINT • AI Security • Disclosure

Independent cybersecurity research focused on threat intelligence, AI security, field notes, adversary tradecraft, and defensive experimentation.

Operating stateManual publication path
Verification modelSource-first, review-gated
Showcase postureFenrir-ready visual system
Hackerman Crew Services identity mark
ResearchField NotesRestricted by design
Publication postureHuman-approved output only
Showcase trackFenrir-ready interface layer
Active tracks04
Field notes queued07
Public methods05
Pending disclosures02

Research Interface

Research is the command layer, not a supporting page.

The front page should feel like an active defensive environment: visible lanes, classified thinking, deliberate publication rules, and enough visual authority to support deeper systems later.

Classification language

ResearchAnalysisDefensiveOSINTAI SecurityArchived

Research principles

Evidence-drivenDefensive by defaultPrivacy-consciousReproducible where practical

Threat research

Investigations that feel active, not archived on arrival

Campaign notes, infrastructure analysis, and telemetry-backed observations should read like live operator thinking instead of reheated marketing prose.

AI security

Automation boundaries made visible

The interface should quietly communicate that authority, tooling, and agent trust boundaries matter as much as raw model capability.

Fenrir path

A stage worthy of future flagship systems

The visual system is being tightened so future showcases like Fenrir can land as first-class artifacts rather than awkward add-ons.

Featured Research

Current publications and research notes

Formal research stays structured and citable, but the surrounding presentation should carry more signal, more weight, and more future-facing presence.

Research Intelligence Feed

A defensive-intelligence wire, not a social feed.

The intelligence draft stays curated, review-gated, and intentionally limited. Automated ingestion, webhooks, and source activation remain off until explicit future approval.

ORIGINAL RESEARCHHackerman Crew ServicesAugust 17, 2026

Agent Trust Boundaries in Security Workflows

CONFIRMED

Internal research priority remains AI security controls that fail closed before an agent quietly expands authority.

EXTERNAL RESEARCHMicrosoft SecurityJuly 12, 2026

Defending SaaS-based applications against ShinyHunters OAuth abuse

CONFIRMED

Useful current research for identity-first defenders: Microsoft ties overlapping ShinyHunters tradecraft to OAuth abuse, vishing, guest access misuse, and supply-chain pressure against SaaS environments.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYMicrosoft SecurityMarch 3, 2026

Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

CONFIRMED

Storm-1747 remains relevant because it shows how phishing-as-a-service normalizes MFA bypass at industrial scale. This is a strong fit for the research lane and the site's identity-attack coverage.

APPROVED — OFFICIAL SOURCE

EXTERNAL RESEARCHRapid7 LabsMarch 17, 2026

The Attack Cycle is Accelerating: Rapid7 2026 Global Threat Landscape Report

CONFIRMED

A strong anchor item for the page because it frames speed, identity abuse, ransomware economics, and AI as an accelerant instead of a separate category of magic.

APPROVED — OFFICIAL SOURCE

Load more intelligence
EXTERNAL RESEARCHRapid7 LabsMarch 25, 2026

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

CONFIRMED

This is one of the better examples of why the site should privilege verified research writeups over recycled takes. It is threat-intel heavy, high signal, and still defensively framed.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYRapid7 LabsJune 17, 2026

Rapid7 Detection Coverage for Iran-Linked Cyber Activity

CONFIRMED

Useful when defenders need a compact, current reference point for monitoring, detection coverage, and campaign follow-through during regional conflict-driven activity.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYBitdefenderAugust 11, 2026

Bitdefender Threat Debrief | August 2026

CORRELATED

A current ransomware snapshot with strong disclosure language about the limits of leak-site claims. Good fit for a research feed that wants to stay analytical instead of sensational.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYBitdefender LabsAugust 2, 2026

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

CONFIRMED

This one belongs because it connects gamer-focused lures, Discord distribution, and hands-on-keyboard malware tradecraft without requiring us to republish the underlying technical body.

APPROVED — OFFICIAL SOURCE

CONFERENCE NOTEHalcyonAugust 5, 2026

Black Hat's AI Blind Spot

CORRELATED

A useful conference-side commentary item because it asks whether the industry is matching attacker use of AI with equally serious defensive analysis, rather than just expo-floor enthusiasm.

APPROVED — OFFICIAL SOURCE

EXTERNAL RESEARCHHalcyonAugust 11, 2026

When Ransomware Hits, Are Board Members Personally Liable?

CORRELATED

Included because governance belongs in the threat conversation. The piece is less about malware mechanics and more about accountability, proportional action, and board-level oversight.

APPROVED — OFFICIAL SOURCE

Field Notes

A lighter format for observations that still matter.

Field Notes create room for shorter analysis without inflating every useful idea into a 4,000-word paper.

Field Notes

Conference signal worth keeping

Short-form observations have a home here so interesting infrastructure, social-engineering patterns, or AI-security experiments do not need to pretend they are full whitepapers.

Analysis

Evidence before narrative

Research starts from telemetry, artifacts, methods, and reproducible checks before it earns stronger claims or more polished storytelling.

Archived

Living work, dated on purpose

Notes and publications stay attributable, dated, and revisable so public work can evolve without losing its original context.

Research Areas

Organized around practical defender questions

Each research track supports future filters, deeper technical writing, and more attributable publication work.

Threat IntelAI SecurityPhishingMalwareNetworkIdentityOSINTPrivacyVulnerabilities

Threat Intel

Threat Intelligence

Campaign tracking, infrastructure analysis, OSINT correlation, and intelligence workflows that help defenders reduce uncertainty.

AI Security

AI Security

Agent trust boundaries, prompt injection, tool abuse, context leakage, and defensive ways to use AI in security operations.

Phishing

Phishing

Brand impersonation, delivery infrastructure, detection signals, awareness gaps, and responder playbooks for modern phishing.

Malware

Malware

Malware behavior, persistence patterns, command-and-control telemetry, and practical defensive observations for analysts.

Network

Network Security

Segmentation, telemetry, IoT isolation, zero-trust controls, and evidence-driven approaches to unexpected network behavior.

Identity

Cloud & Identity

Suspicious authentication, exposed cloud services, identity controls, and investigation patterns for modern enterprise environments.

OSINT

OSINT

Research methods for finding, validating, and correlating public information into useful security intelligence.

Privacy

Privacy & Data Brokerage

Commercial data collection, brokered datasets, external exposure, and the security implications of privacy erosion.

Vulnerabilities

Vulnerability Research

Configuration flaws, product weaknesses, remediation patterns, and defensive lessons learned from vulnerability analysis.

Foundations

Grounded in current security frameworks and public guidance.

The public-facing research themes on this site track current guidance from NIST, CISA, and OWASP so the baseline assumptions stay inspectable.

NIST AI RMF Generative AI Profile (NIST-AI-600-1)

Applied guidance for generative AI risk management.

Review source (External)

The Lab

Public methods where useful. Private boundaries where necessary.

The lab is intentionally structured around active experiments, released work, methods, and clearly restricted areas rather than performative secrecy.

Some things belong on GitHub. Some belong in a research paper. Some stay in the lab.
Enter The Lab

Future Flagship

Fenrir needs a stage that already feels powerful before it arrives.

This visual language is being shaped so larger systems, named programs, and deeper showcases can be revealed without needing the entire site to be reinvented later.

Read the background