About

Security Artifacts

Incident teardowns, detection engineering and adversary emulation, plus an automated wire of active exploitation and vulnerability disclosure.

Security Artifacts publishes incident teardowns, detection engineering notes and adversary emulation work, plus an automated wire of active exploitation and vulnerability disclosure.

Everything here is lab work or a public case reconstructed from public evidence. No client data, no employer's telemetry, no exceptions — and that constraint is a feature, because it means every artifact can be published in full rather than sanitised into uselessness.

What is free and what is not

The Threat Wire is free and stays free. It aggregates other people's public reporting and CISA and NIST open data; charging for a link to that would be both wrong and pointless.

What members pay for is the work on top: complete IOC lists rather than a redacted sample, detection rules with tuning notes and a measured false-positive budget, downloadable artifacts, and the analyst assessment attached to wire entries.

Licensing

Posts are CC BY 4.0. Detection rules, queries and IOC lists are CC0 — public domain, no attribution needed, even for members-only content once you have it. A rule with a licence attached is a rule nobody deploys.

Colophon

Next.js on Vercel, PostgreSQL and authentication on Supabase, billing through Stripe. No analytics, no tracking pixels, no third-party scripts. The only outbound request a page makes is to the database it is reading from.