What our analysts and engineers learn from real cases, written for small security teams.

7 min read
What 214 alerts a day actually contain
We sorted a month of alerts from 40 customers by what they turned out to be. Most of them were the same six things.
Dana Reyes

6 min read
How we page a human at 3 am without waking you
The rules behind night coverage: what pages an analyst, what waits for morning, and what always wakes your team.
Marcus Shaw

5 min read
Detections as YAML, and why we show you every rule
Black-box scoring is hard to trust and impossible to audit. Every Wardell detection is a file you can read.
Sam Whitaker

8 min read
A consent phishing case, minute by minute
A real case with the names changed: from the click at 2:38 am to the CFO call at 7:05.
Dana Reyes

4 min read
SOC 2 monitoring evidence in one export
Auditors ask the same questions about monitoring every year. Here is how to answer them in one file.
Nadia Farouk

4 min read
Why we price per employee, not per gigabyte
Per-GB pricing makes you choose between visibility and budget. We think that is the wrong choice to ask for.
Ada Lindqvist
Send us one week of logs. We send back what we found.
Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.