Research Publications

Selected security research publications with an explicit, human-reviewed publication workflow.

Publication policy

AI assists in drafting, expanding and validating research publications. An AI never auto-publishes: the published state is only set by a human editor after review.

Review workflow

  • Draft — Being written; no external claim yet.
  • Peer review — Reviewed by domain analysts.
  • Verified — Facts and citations checked; pending human decision.
  • Published — Set only by a human editor after review.

The published state is set only by a human editor. AI drafts, expands and validates, but never auto-publishes.

A Practitioner Ransomware Family Taxonomy

published OpenTrojan Research Notes · 2026

A structured taxonomy of notable ransomware families, their behavior and detection guidance, reviewed by domain analysts.

Sources: MITRE ATT&CK, NVD, Vendor advisories

Log4Shell: Exposure and Mitigation Brief

verified OpenTrojan Research Notes · 2026

A practical brief on Log4Shell exposure paths and mitigation priorities, validated against vendor guidance.

Sources: NVD, CISA, Apache advisories

Baseline Hardening Guidance for Edge Services

peer_review OpenTrojan Research Notes · 2026

Detection and hardening checklists for internet-facing edge services, currently under peer review.

Sources: CIS Benchmarks

Using AI-Assisted Annotation in Research Review (Draft)

draft OpenTrojan Research Notes · 2026

An early draft exploring how AI-assisted annotation can accelerate research review without automating publication.

Sources: OpenTrojan Research Annotations

Related: Researchers · AI Research Mode