Dralvia Labs

Research notes, experiments, and threat models from building trust before action

Dralvia Labs investigates how risky actions happen before compromise: clicks, signatures, repository execution, SaaS connections, data sharing, and AI agent tool use. Each note shows the threat model, how we tested it, what worked, what did not, and what we improved.

What Dralvia Labs is

The daily digest shows what Dralvia sees. Dralvia Labs explains what we investigate: the threat model, the test we ran, what worked, what did not, and the product change that came out of it. Every note ends with its limitations and what we improved. We publish on cadence, not on a quota, so a quiet window means no post rather than filler.

Research categories

Five areas, matched to where risky actions actually happen. Open a category to see its notes.

How we label each note

Each post carries a research level, so you know how strong the claim is before you read it.

Observation

Something we saw, with the evidence behind it.

Experiment

A test we ran, with the setup written down.

Benchmark

Reproducible numbers from a fixed corpus.

Methodology

How we test, so you can check our work.

Latest Labs notes

Limitations and ethics

  • We describe attacker patterns and defender guidance, never copy-paste exploit payloads.
  • We report on behavior, not accusations against named companies whose brand an attacker copied.
  • We do not claim total detection. Every note states what it does not cover.
  • Numbers come from fixed, reproducible corpora and the same checks we run in the live service.

Want the methodology behind the labels and the quality bar every note passes? Read the Dralvia Labs methodology.

Dralvia Labs | Security Research, Experiments & Threat Models