Current Research Focus
This is the working research agenda behind HECAVEX. It shows where I am currently spending attention, not a list of services or a promise to publish on a fixed deadline.
Current lines of inquiry
- Web and advertising supply-chain compromise. Malicious JavaScript, third-party delivery paths, browser-side manipulation and the evidence needed to distinguish exposure from confirmed impact.
- Fraud and phishing infrastructure. Redirect chains, cloaking, related domains, hosting patterns and the operational systems that sit behind a single visible scam page.
- Identity-centred intrusion. Session theft, MFA bypass, social engineering and the point where a technically valid control stops being a complete security strategy.
- Information operations. The infrastructure, amplification mechanisms and increasingly AI-assisted workflows supporting influence activity around Lithuania and Europe.
- Threat-actor knowledge. Source-specific actor, campaign, malware and technique records maintained through APT Notes.
Publishing rhythm
HECAVEX publishes substantial investigations when the evidence is ready. Signal Briefs provide shorter prioritised updates, while APT Notes records structured changes to threat-actor knowledge. This page is reviewed as the research agenda changes.
For a curated introduction, visit the Research index. Journalists and event organisers can use the Speaking and media page.