Tracemill Research

When detections break silently, the evidence should be public.

Reproducible investigations into failures introduced by pipeline configuration, add-on behavior, and telemetry contracts. Each investigation identifies the tested versions, affected rules, and runs behind the result.

In the pipeline

Open investigations

Each one publishes only once its runtime evidence, affected scope, and exact versions clear review - so these are the questions, not the verdicts yet.

  • TM-2026-002recheck pending

    O365 inbox-rule fields disappear before detection aggregation

    The data contract between O365 inbox-rule events and the top-level fields the shipped detection groups by, measured against the current add-on.

  • TM-2026-004in review

    Broad Cribl Mask rules break O365 identity detections

    A Cribl masking rule that redacts emails and IPs across the stream, and what it leaves behind for the identity fields O365 detections group and correlate on.

  • TM-2026-005in review

    An allowlist of one: detections that watch only user_type=IAMUser

    Shipped ESCU AWS detections that filter on user_type=IAMUser - and the assumed-role, SSO, federation, and root activity that never reaches them, on any add-on version.

Follow new research findings via RSS.