A Repeatable Threat-Hunting Exercise for Small Security Teams
A local identity hunt with synthetic records, executable SQL, negative cases, and explicit blind spots.
Read article
Research and field notes on AI security, threat detection, and the systems I build and test.
By Kevin O'Connor
A local identity hunt with synthetic records, executable SQL, negative cases, and explicit blind spots.
Read articleA memory-service decision method with a small local SQLite experiment, tenant checks, deletion limits, and latency measurements.
Read articleA bounded Microsoft Entra evaluation method, with synthetic cases for correlation and tenant separation.
Read articleA few ways into the research, depending on what you’re working on.
Follow the data, permissions, and evidence behind an agent system.
Explore this reading pathTurn a detection claim into a repeatable exercise and an analyst question.
Explore this reading pathMake system boundaries, assumptions, and design decisions easier to review.
Explore this reading pathDecode tokens, inspect indicators, calculate subnets, and check security headers.
Hide messages in images, inspect the pixels, and learn how steganography works.
An interactive app for exploring AI systems, model families, and the relationships between them.
Create chemical labels with GHS pictograms and hazard statements.
Create and print NFPA 704 fire diamonds.
Evaluates autonomous AI agents against adversarial patterns such as prompt injection, memory poisoning, tool misuse, and context drift.
New research, technical notes, and experiments.
Delivered when there's something worth sharing.
SecurityWeek
A conversation about offensive and defensive cybersecurity work.
Security Magazine
How security teams can prepare for cyber threats over holiday weekends.
CISO Tradecraft
Security challenges for small and midsize businesses, including managed detection and response.
BrightTALK
On-demand talks on threat detection, security monitoring, and threat hunting.
I'm Kevin O'Connor, a security researcher and engineer working on adversarial AI systems, detection engineering, and practical security tools.
Alexandria, Virginia / Washington, DC Metro — available nationwide
Get in touchServed in technical leadership roles supporting computer network operations and defensive security work.
Worked on threat intelligence and advanced security research.
Led research into ransomware, intrusions, and detection methods.
AI security research, assessments, and defensive tools.