Independent cyber threat intelligence research and digital investigations by Deividas Lis.
HECAVEX studies the infrastructure, behaviour and people behind phishing, fraud, malware, cybercrime and information operations. The work combines long-form research, structured intelligence, reproducible evidence and small open-source tools.
Research 路 Radar 路 APT Notes 路 Labs 路 Public data
| Project | Purpose |
|---|---|
| HECAVEX Research | Bilingual investigations, technical assessments, commentary and weekly Signal Briefs. |
| HECAVEX Radar | Public, read-only view of recently observed potential phishing infrastructure relevant to Lithuania. |
| Open Domain Radar | Brand-neutral, self-hosted Python application for collecting, reviewing and enriching candidate impersonation domains. |
| APT Notes | Source-driven records connecting threat actors, aliases, campaigns, malware, tools and techniques. |
| HECAVEX Labs | Inspectable CTI workspaces, ATT&CK workflows, evidence pivots and public datasets. |
| Research Artifacts | Versioned evidence bundles and reproducible supporting data for published research. |
- An observation is not automatically a finding.
- Infrastructure overlap is not automatically attribution.
- Confidence, provenance, time and limitations belong beside the claim.
- Public indicators are defanged, and sensitive evidence stays out of public repositories.
- Open-source tools should remain inspectable, deployable and useful without an account where possible.
HECAVEX is an independent publication and research identity maintained by Deividas Lis in Lithuania.
For research collaboration, corrections or media enquiries, use the HECAVEX contact page.