Security Labs

Research and publications.

Work from Security Labs is published here by type. We publish when something is finished and useful, not on a schedule.

01Library

Published work

Security Labs has not published yet.

The first research notes are in progress. Until they are released, the articles in Resources show how we think.

02Output types

What will be published here.

Research note
A technical write-up of one question: what was tested, how, what was found and what a defender can do with it. Written so that the work can be repeated.
Advisory
A short notice on a vulnerability or an active technique, with affected versions or conditions, detection guidance and mitigation. Vulnerability advisories are released under coordinated disclosure.
Tool
Source code for a utility built during research, such as a test harness, parser or collector, released with documentation when it is useful outside Onion.
Talk
A conference or community presentation of completed research, with slides and supporting material published afterward.
Detection content
Detection rules and queries with the test data, MITRE ATT&CK mapping and tuning notes needed to run them. The same content is used in our security operations service and in XDR development.

03Disclosure

Coordinated disclosure

When our research finds a vulnerability in someone else’s product, we report it to the vendor and coordinate publication. If you have found an issue in ours, the same policy tells you how to reach us.