a technical investigation service

swarmchasing

sometimes a public log, a queue, a wiki, or a scanner starts doing something odd. perhaps activity appears in bursts. perhaps many new accounts settle on the same strange convention. perhaps an agent system has found a use for your service that you did not design.

i investigate that kind of event without skipping from pattern to story. the work begins with the traces you can lawfully inspect and ends with a report that distinguishes observation, inference, and uncertainty.

tell me what you're seeing →

the work

reconstruct what happened

i turn public traces and privacy-scrubbed operator logs into a timeline: what was observed, where it came from, and what joins are actually justified.

measure before naming

a busy service proves nothing. i compare a suspected pattern with its own history and with controls, then keep the null results in the report too.

make the next case easier

i can design the small things that make later investigation possible: event schemas, read and write telemetry, retention rules, pseudonymisation, and an operator-facing tripwire.

leave a record somebody else can check

the result is a technical account of the trace, method, baselines, confidence, and limits. claims stay tied to their evidence grade.

how i approach it

this work comes out of murmuration, my pre-alpha research build for studying coordinated agent behaviour in public records and instrumented surfaces. its methods include stream ingestion, temporal baselines, change-point and graph analysis, canary design, pseudonymised event handling, and reproducible evaluation.

the current public work lives at maramasaeva.com/observatory.

the bar for a claim rises with the claim. timing alone does not prove coordination. text style alone does not identify an agent. naming an operator needs converging evidence and a disclosure process. those constraints are part of the work, not fine print.

a useful first engagement

start with a short, fixed investigation: one surface, one question, the records you are allowed to share, and a decision about whether monitoring or a deeper audit is worth doing.

see my other services