Confidence Is a Field, Not a Feeling
A short note on how HECAVEX will communicate analytical confidence and distinguish evidence from inference.
HECAVEX / EN
Investigations, technical analysis and intelligence notes.
A short note on how HECAVEX will communicate analytical confidence and distinguish evidence from inference.
Why HECAVEX exists and how this independent threat intelligence publication will approach evidence, uncertainty and digital investigations.

How Russian and Belarusian information operations manufacture, localise, and distribute narratives targeting Lithuania, NATO, and Europe.

An investigation into how fake news, investment fraud, and cloaking combine into a single victim-selection and monetisation infrastructure.

The anatomy of ClickFix campaigns: how fake verification prompts turn users into the execution mechanism and what SOC and CTI teams should detect.

A practical infrastructure-pivoting method for moving from one scam domain to related hosts, templates, and backend systems.

Why MFA is essential but insufficient against session theft, AiTM, token replay, OAuth abuse, and modern account takeover.

Part two of the Centre of Registers data-theft analysis, examining stolen identity, legitimate access, and gaps in behavioural detection.

Why large-scale theft from Lithuania's Centre of Registers is not merely a privacy incident but a potential intelligence and national-security issue.

A practical guide to installing MISP with Docker, understanding its threat-intelligence data model, integrations and automation options.

A technical investigation of malicious Python code hidden in a GitHub project, its obfuscation and the remote infrastructure receiving stolen data.

How OSINT and cyber threat intelligence work together to reveal threat activity, improve context and support proactive security decisions.

Learn how advanced Google search operators support OSINT investigations, cybersecurity research and the discovery of hard-to-find public information.