Research · Tag · Taxonomy

Posts tagged taxonomy.

7 entries · sorted: recency← All research
NRDAX
2026-07-30

Which chains fail the same way

Twenty-eight of the 118 techniques we have reproduced appear on more than one chain. The registry could always report that number but never draw the line between the chains. The chain graph draws it, and most of the lines it draws are arithmetic rather than evidence, which is the part worth publishing.

Simon Morley
Read →4 min read
NRDAX
2026-07-16

The overlap is empty

We crosswalked NRDAX against MITRE AADAPT. Twenty-two NRDAX techniques touch AADAPT and none are reproduced. Everything we have reproduced sits where MITRE does not model; everything MITRE models, we have only read about. The empty column is the finding.

Simon Morley
Read →3 min read
NRDAX
2026-07-13

NRDAX: browsable by chain and family, readable by machines

NRDAX now holds 623 techniques across 64 chains, 162 reproduced with bundles. New per-chain and per-family landing pages, a pretty Atom feed, JSON and STIX 2.1 and knowledge-pack distributions surfaced for machines, and a fix for the first_seen date bug.

Simon Morley
Read →2 min read
NRDAX
2026-07-11

NRDAX now includes known-but-not-reproduced techniques

NRDAX v0.1-import now contains 368 techniques across 21 chains: 140 with reproduced instances and bundles, and 228 known from public disclosures (CVEs, GHSAs, vendor advisories) but not yet reproduced in the lab. A CVE maps to its technique even when no bundle exists yet.

Simon Morley
Read →1 min read
NRDAX
2026-07-09

NRDAX: the canonical technique registry for decentralized infrastructure attacks

We have published NRDAX, the NullRabbit Decentralised Attack indeX, at nrdax.com. It is the reference registry for attack techniques against decentralized infrastructure: 135 chain-agnostic techniques, grouped into mechanism families, with a coverage matrix across 21 chains.

Simon Morley
Read →1 min read
SECURITY-RESEARCH
2026-07-07

Eighteen advisories, ten node implementations, one attack class

Since NR-2026-001, eighteen advisories across ten independent node implementations. Not unrelated bugs: one recurring attack class, unauthenticated ingress surfaces where a cheap request forces disproportionate cost. Egress and memory amplification, pre-auth CPU exhaustion, connection exhaustion, and crashes.

Simon Morley
Read →1 min read
SUBSTRATE
2026-04-26

Introducing Substrate: An Open Format for Validator Threat Intelligence

Validator threat intelligence has no shared format. We're publishing a bundle spec, a ten-family taxonomy, and seeding a 1,092-bundle corpus to fix that.

Simon
Read →7 min read