SCARP research
Security research that follows the evidence.
Field notes on attack paths, confidence, and the work required to call an exposure closed.
Read the notesResearch notes
Working from the path, not the queue.
Editorial notes from the SCARP team. They describe our methodology and evidence model; they are not peer-reviewed research.
Why the fix at the shared hop beats the worst finding
A severity-sorted queue and a path-sorted queue rarely agree on what to fix first. Here's the arithmetic for why the second one is usually right.
Read the noteObserved, inferred, validated, verified: how SCARP grades its own evidence
Every claim in a SCARP report carries a grade for how it was obtained. Here's why that grading exists and what each grade actually means.
A path is closed when the retest says so
A deploy is not a closure. Why SCARP only credits a fix after the original attack path is retested, and why a partial result beats a clean one.
Reading desk
What we return to.
Security writing we use as a check on vendor narratives and a reminder to stay close to ground truth.
- 01Krebs on SecurityIndependent investigative reporting on breaches and the criminal infrastructure behind them, often before the affected companies say anything publicly.
- 02Schneier on SecurityLong-running, skeptical commentary on security and policy from one of the field's most consistent voices on how incentives shape outcomes.
- 03Google Project ZeroDetailed, technical vulnerability research from a team that publishes the how, not just the headline.
- 04PortSwigger ResearchWeb-application security research from the team behind Burp Suite, usually with working technique write-ups rather than summaries.
- 05SANS Internet Storm CenterA daily diary of what practitioners are actually seeing on the internet, useful as a ground-truth check against vendor narratives.
- 06Verizon Data Breach Investigations ReportThe closest thing the industry has to an annual, dataset-backed census of how breaches actually happen.
- 07CISA Known Exploited Vulnerabilities CatalogA running, government-maintained record of which vulnerabilities are confirmed under active exploitation, not just theoretically severe.