Research
What we see, written down
PuReAI runs 12 OSINT modules over real estates every day. The patterns that recur are worth publishing — actor behaviour, sector exposure and the gap between what an organisation thinks it exposes and what it actually does.
Programme
Quarterly threat report
Ransomware and extortion group activity by sector, mapped to MITRE ATT&CK techniques, with the exposure patterns those groups exploited. Available as a redacted sample on request.
Actor analyses
Standalone write-ups on individual ransomware and APT groups: infrastructure, initial-access preferences and the supplier paths they favour.
Sector exposure findings
Aggregated, anonymised findings across finance, telecoms, government and insurance estates — subdomain sprawl, certificate hygiene and supplier concentration.
Glossary
Plain definitions for EASM, KEV, TTP, ICT third-party risk and the rest of the vocabulary this category insists on using.
PuReAI Quarterly Threat Report
A named research output, published each quarter: actor activity by sector, the MITRE ATT&CK techniques observed, and the exposure patterns that made those intrusions possible. Distributed to registered readers.
How every finding is produced is documented on the methodology page.