PRG-01
Adversary tracking
Longitudinal tracking of financially motivated and state-aligned clusters operating against GCC targets, with published TTP mappings.
QUARTERLY TEARDOWN
Peer-reviewed studies, longitudinal telemetry analysis and field research from the DeGooL research group. Every published figure is reproducible from the methodology appendix.
Two years of sensor data across 312 estates in nine countries: 4,180 confirmed incidents classified by initial access vector, dwell time, sector and containment outcome — with the full statistical method published alongside.

Four standing programmes, each with a published output cadence and named lead.
PRG-01
Longitudinal tracking of financially motivated and state-aligned clusters operating against GCC targets, with published TTP mappings.
QUARTERLY TEARDOWN
PRG-02
Measuring which detection logic actually survives production: precision, recall and decay rates across 1,780 maintained rules.
BIANNUAL STUDY
PRG-03
Controlled comparison of analyst-only, model-only and model-assisted triage on identical incident sets, including error taxonomy.
ANNUAL PAPER + DATASET
PRG-04
Field research on industrial protocol abuse in energy and water infrastructure, conducted on instrumented test rigs.
CONFERENCE TRACK
Analysts and a Claude-based reasoning layer were given identical incident sets under blind conditions. We report agreement rates, error taxonomies and the cases where model assistance degraded rather than improved the verdict.
DEGOOL RESEARCH GROUP · 34 PP · METHODOLOGY APPENDIX INCLUDED
Distribution of attacker dwell time across sectors and initial access vectors, with survival analysis showing where detection coverage changes the curve and where it does not.
DEGOOL RESEARCH GROUP · 52 PP · DATASET AVAILABLE UNDER NDA
Twelve attack primitives executed against a physical test rig, with the passive detection signatures each one produces and the false-positive cost of deploying them in production.
OT PRACTICE · 41 PP · SIGNATURES PUBLISHED
We tracked 1,780 detection rules over 24 months. Precision decays predictably with estate change; we identify the four drivers and the maintenance cadence that arrests them.
DETECTION ENGINEERING · 28 PP
Anonymous survey of security leaders in the GCC on team size, alert volume, triage capacity and the share of the queue that is never reviewed.
DEGOOL RESEARCH GROUP · 22 PP · RAW RESPONSES ANONYMISED
What a reasoning trace must contain to satisfy an ISO 27001 or SOC 2 auditor, derived from twelve real audit engagements where model-assisted decisions were in scope.
GOVERNANCE PRACTICE · 19 PP
| DATA SOURCE | SCOPE | VOLUME | METHOD |
|---|---|---|---|
| Client telemetry | 312 consenting estates, 9 countries | 41.6 B events/day | Aggregated, de-identified at collection |
| Honeynet sensors | GCC region, 14 sensor sites | 2.31 M probes/day | Full packet capture, manual classification |
| Dark web collection | Forums, paste sites, broker listings | 3.4 M credential records | Automated collection, human verification |
| Incident casework | DFIR engagements 2024–2026 | 4,180 confirmed incidents | Structured post-incident coding, dual reviewer |
| Purple-team exercises | Client estates, quarterly | 1,780 rules tested | Atomic test replay, precision/recall scored |
| Practitioner survey | 140 regional organisations | 140 responses | Anonymous, self-reported, weighted by size |
Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.