Evidence-first incident response: what we put in every report
A finding without a timestamp and a source is a rumor. This is the exact record skeleton we use on every engagement — and why we refuse to ship anything less.
The Journal
Engineering, tradecraft, and governance notes from the team. Evidence first, ready for a second pair of eyes.
A finding without a timestamp and a source is a rumor. This is the exact record skeleton we use on every engagement — and why we refuse to ship anything less.
The authorization checklist every engagement starts with
Scope, owner, exclusions, stop conditions, and data-handling rules — signed before any operator touches a system. Here is the full checklist and why each line matters.
Black-box models are a liability in a reviewable workflow. How we designed Bolt so every assertion can be traced back to attached evidence.
Uganda's Computer Misuse Act and what 'authorized' really means
A working reading of the 2011 Act, NITA-U guidance, and why a signed scope matters even for the most well-intentioned penetration test.
Threat model first, tooling second
Teams adopt detection platforms before they can describe the adversary. We walk through the five questions we ask every client before we touch a single rule.
Field reports
A tricky triage, an authorization edge case, a detection that held up. No client identities.