SPRINT
Single-hypothesis sprint · 2 weeks
One concrete hypothesis, scoped, hunted, and answered. Pick a technique that keeps you awake — your sector's currently-active adversary, a new CVE, a recent breach in your peer group. Two weeks later you have an evidence-backed finding or absence, plus new detection rules you didn't have before.
- · 2-week fixed scope, fixed price
- · One named hypothesis · 1–3 ATT&CK techniques
- · Output: signed report + Sigma / EQL / YARA rules
- · Findings routed to DFIR if confirmed