CTI research & analysis

Expert threat intelligence, in the open.

In-depth analysis, IOC reports, and actor tracking from the Chawkr research team — the same infrastructure intelligence that powers ClusterHawk, written up for the practitioners who act on it.

Latest research

Fresh from the oven.

Deep dives, cluster reports, and IOC breakdowns — free to read, with premium analysis for teams.

Browse all reports

This content requires premium access. Subscribe for full threat intelligence reports and analysis.

Premium
Premium content

SILENTLOOM: A Reused Device Pool Behind a Quiet Microsoft 365 Password Attack

Premium access required

Free
doctrinemethodologyinfrastructure-analysis+6

Find the House, Not the Doormat: A Doctrine for Reading Infrastructure Metadata After the Attack

The single-indicator pivot dies against a tier-separated operator, stopping at the access surface. This doctrine proposes four moves for reading metadata after: seed from a behavioral cohort, mine persistent fingerprints, separate attack signature from residue, confirm with an independent source.

CR

Chawkr Reports

18/06/2026

Free
eviltokensphishingdevice-code+7

EvilTokens: Device Code Phishing Goes Industrial

We fed 95 EvilTokens campaign IPs into ClusterHawk and mapped a four-tier architecture. It spans a Cloudflare CDN frontend, DocuSign/Exim backend hosting, a bridge cluster on Google Trust Services certs, Cobalt Strike C2 via domain fronting, and an unreported IoT layer of Hikvision/Dahua cameras.

CR

Chawkr Reports

09/04/2026

Why Chawkr

Intelligence you can act on, not just read.

Expert-led analysis

Every report is written by practitioners who tracked the threat, not aggregated from feeds.

Emerging trends early

We surface infrastructure shifts before they show up on the public blocklists.

IOC & analysis reports

Structured indicators and detection logic you can drop straight into your stack.

A practitioner community

Discuss findings in threaded comments with analysts working the same problems.

The research becomes tooling

Run the same analysis on your own data.

The clustering and fingerprinting behind these reports is a product. ClusterHawk turns your IOC lists into the operation behind them — on GPU, in minutes.

Explore ClusterHawk

Start free

Start with the free intel feed.

Free reports every month. Upgrade to premium for the deep analysis, full IOC sets, and detection logic.

Read the free feed