Mara
R · 4 notes

From the lab. Written carefully.

Short essays on how Mara works, how we measure it, and the choices we make about what to publish and what to keep closed.

  1. R-01

    Reasoning about an unknown sample.

    How Mara approaches a piece of malware it has never seen before: what to look at, what to suspend judgement on, and where to begin.

  2. R-02

    Attribution under uncertainty.

    Why Mara hedges on threat-actor names, and why we believe a model that hedges well is more useful than one that names confidently.

  3. R-03

    A note on evals.

    How we measure whether Mara is actually useful for the work analysts do, not the work benchmarks pretend they do.

  4. R-04

    Working in the open.

    Why our research notes, our model cards and our evals are public, and which parts of Mara we keep closed, and why.