Research & Field Notes
Technical research, lab observations and engineering notes produced while building, attacking, detecting, investigating and improving systems inside the BELISARIUS13 security lab.
Research from real lab activity
Articles should originate from experiments, investigations, engineering decisions or lessons learned rather than generic cybersecurity summaries.
Document the environment
Capture architecture decisions, tooling, configuration and reproducible deployment practices.
Generate evidence
Use controlled attack activity and lab experiments to produce observable security telemetry.
Explain what happened
Break down telemetry, detections, packet captures, artifacts and investigative findings.
Publish the lesson
Turn practical findings into concise technical write-ups that others can reproduce and evaluate.
Publication domains
Research is organized around the same technical disciplines used across the BELISARIUS13 campaigns.
Purple Team Research
Adversary emulation, security-control validation, ATT&CK coverage and lessons from attack-to-defense exercises.
Detection Notes
Detection hypotheses, telemetry requirements, rule development, false-positive analysis and tuning decisions.
Incident Response & DFIR
Investigation timelines, artifact analysis, root-cause findings, containment and remediation lessons.
Network Analysis
PCAP analysis, suspicious traffic patterns, protocol behavior and network-detection engineering.
Azure Security
Identity, posture, logging, workload security and control validation inside Microsoft Azure.
Engineering Build Logs
Implementation notes covering lab infrastructure, automation, GitOps, CI/CD and reproducible security tooling.
From experiment to article
Research follows a lightweight editorial workflow so notes are based on evidence and remain technically reproducible.
Planned research
The queue is intentionally tied to active and upcoming campaigns so the site grows alongside the engineering work.
Building BELISARIUS13: Secure Portfolio Infrastructure
Architecture, Git workflow, automated deployment, DNS, TLS and the security decisions behind Campaign-00.
Designing a Resource-Conscious Purple Team Lab
Building a staged lab environment for adversary emulation, endpoint telemetry and defensive analysis without requiring a large attack range.
From ATT&CK Technique to Detection Hypothesis
A practical workflow for translating controlled adversary behavior into telemetry requirements and testable detection logic.
Reconstructing a Controlled Windows Incident
Using endpoint telemetry and forensic artifacts to build a timeline, identify root cause and validate remediation.
Reading the Attack in the PCAP
Protocol analysis and network evidence from a controlled hostile-traffic scenario.
Building an Azure Purple Team Validation Workflow
Connecting identity, cloud activity, posture findings and defensive validation in a controlled Azure lab.
Research archive
The archive will only count completed technical articles after they have been reviewed and published.
Research framework established
The publication structure is ready. The first articles will be produced from Campaign-00 documentation and the build-out of Campaign-01.
Research connects back to the lab.
Articles should link directly to the campaigns, detections and lab components that produced the underlying evidence.