Research

Publications

Technical notes, methods, and research artifacts. Updates are published when research is complete.

Top tags

Threat Intelligence (3)Infrastructure Hunting (3)Methodology (3)Threat Hunting (1)Research Programs (1)AI Research Agents (1)NSO Group (1)Pegasus (1)Certificate Transparency (1)WHOIS History (1)Era Translation (1)Censys (1)
Introducing Mintaka — A Threat-Hunt Research Program

A sustained research program at Orion Labs producing two outputs together: a corpus of adversary-infrastructure analysis — roughly seventy signal bearers accumulated to date across compound fingerprints, technique classes, OPSEC patterns, cluster-shape signatures, and era-corrected attribution data — and the methodology, tooling, and analytical backend that makes the corpus possible. Current state human-led with AI assistance. Direction of travel a refined multi-agent system operating under the methodology as its discipline. The first dispatch in a new series.

From Disclosure to Reproduction: Hunting NSO Pegasus V1 Infrastructure — Part 2

Reproducing Citizen Lab and Lookout's 2016 Million Dollar Dissident infrastructure analysis with the 2026 connector stack: era-bound tool substitution, three previously-undisclosed NSO-attributed domains, and a V1 deployment 15 months earlier than the original disclosure documented.

Hunting Nation-State Spyware Infrastructure with Censys — Part 1

A technical orientation to the Censys Platform as a threat intelligence primitive: scanning architecture, data model, historical data, the Threat Hunting Module, ASM, and CenQL.

Research Notes: Scope and Publication Model

How Orion Labs structures research work and what we publish (and what we don't).