Community guidelines
Short, because a long code of conduct is one nobody reads. The summary: post real work, protect the people whose incident it was, and argue with the evidence rather than the person.
What belongs here
Incidents you worked and what the evidence supported. Detections offered for critique — especially ones you are not sure about. Questions where you are genuinely stuck: an artifact nobody recognises, a gap in telemetry you cannot close, a technique you can see the effect of but not the mechanism. Tooling that saved you a day.
The best posts here are specific and include the part that went wrong. “We chased the wrong process for six hours because the parent PID was reused” is worth more to the next person than a clean narrative that skips it.
Redact before you post
Hostnames, internal addresses, ticket numbers, staff names, customer names, screenshots with any of the above in a title bar. A good write-up never needs them — substitute consistently (HOST-01, 10.0.0.0/8) so the narrative still holds together.
If you are under an NDA or a client agreement, that governs. Do not post material you are not free to share, and do not post about an incident that is still live for the affected organisation.
Malware, exploits and live infrastructure
Hashes, IOCs, detection logic and analysis are welcome. Working exploit code and malware samples are not — not as attachments, not as pastes, not as links to a bucket you control. Point at a published advisory or a recognised repository instead.
Do not post live C2 addresses in a form that invites people to visit them, and do not ask the room to scan, probe or otherwise touch infrastructure that is not theirs.
Disagreement
Disagreeing with an analysis is the point of publishing it. Say what the evidence does not support and what would change your mind. Attacking the person who wrote it, their employer or their competence is not the same activity and gets removed.
There is no downvote here. If something is wrong, reply with why; if it breaks these guidelines, report it and a moderator will read it.
Moderation
Everything is reviewed before it appears, usually within a day. Rejections come with a reason attached, visible to the author on their own post. Substantially editing something after it is published sends it back to the queue — that is not a punishment, it is how the review stays meaningful.
Nothing is hard-deleted. A removed post keeps its row so that a report about abuse of this site has something to point at.
Self-promotion
A link to your own write-up, tool or talk is fine when it is the substance of the post and you say it is yours. A post whose purpose is to sell something is not, and neither is a feed of your company's blog.