ForensicPost exists because most reporting on intrusions is written from press releases and most technical writing about them is written to sell something. We do neither. Every file we publish states what we reviewed, how confident we are, and what we still cannot answer.
We name the number of artefacts we reviewed and the number of independent sources behind each claim. Where a file rests on one source, the file says so, in the file, not in a footnote.
No vendor sponsorship, no sponsored files, no embargoed marketing. Revenue is subscriptions and institutional licences for the Case Files database. Our licence holders get no editorial input, ever.
We publish hashes and infrastructure. We do not publish victim data, file trees that identify individuals, or working exploit detail. We never name the analyst who took the call.
We do not pay sources, and we do not pay actors for data. We do not accept exclusives conditioned on framing. If an organisation asks us to delay for containment, we weigh the delay against reader harm and record the decision in the file.
Our examiners hold no equity in security vendors and disclose prior employment on every file where it touches the subject. Conference travel is paid by us. When we get something wrong, the correction runs at the top of the file, not the bottom.