All writing
Defense engineering
Detection engineering, SIEM, threat-informed defense, and the tooling that keeps a blue team honest.
Articles in this collection
5 articles- "Ask the User to Approve" Is Not a Security ControlApproval prompts get clicked through by the tenth repetition. Treat human review as a scarce resource and spend it where the blast radius is — everywhere else, enforce in code.#agentic-ai#agent-architecture#human-in-the-loop6 min read
- Your Voice Is Not a Password AnymoreThree seconds of audio from an old video is enough to convincingly be someone you love. The check that works doesn't happen on the call.#ai-security#threat-modeling7 min read
- Threat Modeling for AI Agent SystemsThreat modeling fails because it runs as a quarterly workshop. Run it in sprints, at the architecture layer, and start with the agent surfaces scanners can't see: tool calls, memory, MCP servers.#threat-modeling#appsec#agentic-ai17 min read
- Threat-Informed Defense Is Detection Engineering, Minus the GuessingA detection built on a file hash lasts until the next build. One built on a technique costs the adversary something to route around. That's the whole argument.#detection-engineering#threat-informed-defense#mitre-attack5 min read
- Most Alerts Are Noise. Design for That.A detection rule that fires 200 times a day and gets ignored isn't a detection — it's a decoration.#detection-engineering#siem2 min read