Sequenxa[ Research / Methodology ]

How we do the research

Sequenxa Corporation publishes defensive research under a fixed set of methods, evidence standards, and boundaries. This page states them plainly so our work can be judged on its rigor.

01/Method

From question to finding

  • 01

    Scope and hypothesis

    Each study begins with a defensive question — how a decoy or engagement improves detection or understanding — and a clearly bounded environment we own and control.

  • 02

    Controlled instrumentation

    Decoys, breadcrumbs, and telemetry are built on infrastructure under our sole control. Observation is limited to interactions an attacker initiates against those owned assets.

  • 03

    Evidence collection

    We record technique-level behavior and system telemetry, not the identities of third parties. Findings are reproducible within the lab from the recorded conditions.

  • 04

    Analysis and review

    Observations are interpreted against established frameworks (for example, MITRE Engage) and reviewed internally before any external characterization.

02/Evidence & provenance

Publication and evidence standards

  • 01Claims are tied to observed telemetry from owned infrastructure, not speculation.
  • 02We distinguish research notes, prototypes, and validated findings, and we say which is which.
  • 03We do not publish personas, venue details, anti-detection methods, or operational playbooks.
  • 04Sources and frameworks we rely on are named so readers can trace the reasoning.

03/Boundaries

What we will not do

  • 01Defensive purpose only — no retaliation, hack-back, or out-of-band interference.
  • 02No unsolicited targeting of third-party systems or individuals.
  • 03Capture and observation limited to infrastructure we own and control.
  • 04Responsible disclosure and lawful coordination when findings affect others.

Read the research overview at Sequenxa Research, or browse published explainers and analysis under Sequenxa Intelligence.