Nicholai Imbong
Security researcher and engineer
AuvaLabs is my independent security research and engineering lab, where I build ThreatWatch and RedBlue.
Primary work
project details →Core expertise
about my work →Threat intelligence
Turning public reporting and structured data into useful intelligence with clear evidence and provenance.
Exposure management
Building authorised, scope-aware workflows for understanding an organisation's external attack surface.
Detection engineering
Connecting adversary behaviour to telemetry, testable detections, and measurable coverage gaps.
From the research blog
read the blog →Why 32 Threat Leads Did Not Become Hunt Packages
A production snapshot of ThreatWatch shows how corroboration, observables, ATT&CK context, and readiness thresholds keep developing leads out of the qualified hunt queue.
Public Discovery Is Not Permission to Scan
Why RedBlue keeps public asset research separate from direct testing, and what NIST and bug-bounty scope guidance say about authority.
Subdomain Takeover Checks Start With the Asset Graph
An August RedBlue retrospective on registrable domains, retained subdomains, and why better enumeration must remain behind an exact scope boundary.