Methodology
Evidence first.
Conclusions with context.
A useful report lets another person understand what happened, reproduce the relevant observations where safe, and assess the basis for a concern.
From observation to a qualified report
Research starts with a specific concern, not a presumption of guilt. The depth of an investigation depends on the available evidence, the nature of the behavior and the recipient’s remit.
Manual review & scope
Record the domain, the reason for review and the questions to investigate. Distinguish a direct observation from a third-party signal.
Reproduce the user journey
Document entry points, navigation, redirects and material representations. Record UTC time, relevant browser context, location-dependent behavior and any reproduction limits.
Check the technical context
Examine relevant DNS, registration data, TLS, hosting and HTTP behavior. Avoid attributing control solely from a shared IP address or service provider.
Preserve evidence & integrity
Capture relevant pages and technical observations with timestamps, source references and cryptographic hashes where applicable. Preserve originals separately from annotated or redacted copies.
Qualify the concern
Connect each conclusion to an observation. Identify the applicable policy or suspected violation and clearly state alternative explanations, uncertainty and missing evidence.
Route & review
Identify the party responsible for the relevant service. Send a proportionate report through its published channel, track material corrections and reassess when new evidence is available.
What the recipient receives
A structured report designed for assessment, with sensitive material shared only through an appropriate channel.
Scope & identifiersRelevant domains, observation times and a concise summary.
Observed behaviorA reproducible sequence with cited evidence and technical context.
Assessment & limitationsThe basis for the concern, applicable policy and confidence limits.
Evidence inventoryArtifact references, integrity information and redaction notes.
Requested reviewA request within the recipient’s remit and a route for follow-up or correction.
Standards that make evidence useful
Traceability over volume
Every material conclusion should have a traceable basis. Repeated reputation signals are not treated as independent proof when they derive from the same source.
Integrity and clear handling
Keep original artifacts, acquisition context and integrity records together. Redacted copies must be identified as such. A hash helps check that an artifact has not changed; it does not by itself prove a claim.
Safe URL presentation
Potentially harmful URLs are presented as non-clickable, defanged text such as hxxps://example[.]invalid/path. Remove access tokens and personal identifiers when they are not necessary to understand the issue.
Boundaries of the work
No unauthorized access, bypassing of access controls, live card testing or interaction that creates harm is part of this research framework. Potential malware is handled only in an appropriate isolated environment.
Reports reflect observations at a particular time. Domains can change ownership or behavior. We do not promise a takedown, determine legal liability or replace a recipient’s independent review.
How to challenge a finding →A clear route to review
Have information
we should examine?
Share context, raise a concern, or request a correction. Start with a concise summary and safely formatted domains.
Contact the team