Argelius Labs is an independent investigations and research firm founded by Matt Edmondson. The firm brings together open-source intelligence, technical analysis, and experience investigating complex digital activity.
Our focus is practical: develop the evidence needed to answer a question, explain how we reached our conclusions, and make the findings useful to the team receiving them.
We offer investigative and research support for government and national security requirements, along with technical exposure assessments for acquisition and investment teams. Tailored briefings and workshops support teams developing their own investigative practice.
Matt Edmondson brings two decades of experience conducting investigations and advancing the use of open-source intelligence and digital forensics in national security and law enforcement work.
He is a SANS Senior Instructor and course author, and has presented at Black Hat and other security conferences. Through Argelius Labs, he applies that investigative and technical background to focused research, analysis, and advisory engagements.
Our services are designed for government and national security teams, the organizations supporting them, and security teams with complex investigative questions. We also provide technical exposure assessments for acquisition and investment teams.
Examples include whether online accounts or websites are connected, how a network distributes and amplifies content, what digital infrastructure supports observed activity, and which findings need further corroboration. We scope each engagement around a specific question.
We define the research question, sources, deliverables, and timeframe before proposing a fee. Work can be structured as a defined project or, where appropriate, recurring research support with an agreed reporting cadence.
Depending on the engagement, deliverables can include a findings report, source register, timeline, relationship map, technical asset inventory, and a briefing. Reporting explains what was observed, how conclusions were reached, and what remains uncertain.
We investigate connections among accounts, entities, and infrastructure and assess competing explanations. Attribution depends on the evidence available. Reports distinguish documented links from judgments about control, intent, or sponsorship.
Our initial focus is the target’s technical footprint and observable exposure. Deeper technical validation depends on scope, access, and authorization. The assessment supports the transaction’s wider diligence process and identifies questions that need further investigation.
Use the contact form or business email to provide a general description and your preferred way to connect. We will discuss an appropriate channel before you share sensitive project information.