Writing
Research and field notes
Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.
Start here
A few ways into the research, depending on what you’re working on.
AI and agent security
Follow the data, permissions, and evidence behind an agent system.
- How to Evaluate Tools for Securing Production AI Agents
Start with a practical method for evaluating agent security.
- Choosing an AI Agent Memory Service: Security and Performance Tradeoffs
Examine memory, tenant boundaries, and deletion with a local experiment.
- Tamper-Evident AI Agent Logs: Integrity, Gaps, and Limits
Test what an audit trail can prove and where it loses evidence.
Detection and threat research
Turn a detection claim into a repeatable exercise and an analyst question.
- A Repeatable Threat-Hunting Exercise for Small Security Teams
Run an identity hunt against synthetic records and negative cases.
- Evaluating Identity Detection Coverage Across MSP Tenants
Check identity coverage and tenant separation before relying on an alert.
Security architecture
Make system boundaries, assumptions, and design decisions easier to review.
- Using C4 Diagrams In Security Work
Use diagrams to explain trust boundaries and data flows.
- Zero Trust Without The Vendor Fog
Connect Zero Trust principles to implementation decisions.
- 4+1 Architecture Views For Security Reviews
Choose the views that answer a security reviewer’s questions.
Latest
A Repeatable Threat-Hunting Exercise for Small Security Teams
A local identity hunt with synthetic records, executable SQL, negative cases, and explicit blind spots.
Read article
Choosing an AI Agent Memory Service: Security and Performance Tradeoffs
A memory-service decision method with a small local SQLite experiment, tenant checks, deletion limits, and latency measurements.
Evaluating Identity Detection Coverage Across MSP Tenants
A bounded Microsoft Entra evaluation method, with synthetic cases for correlation and tenant separation.
How to Evaluate Tools for Securing Production AI Agents
An evaluation method that follows identity, authority, approval, and failure behavior through a real agent workflow.
Tamper-Evident AI Agent Logs: Integrity, Gaps, and Limits
A runnable local log-chain experiment covering edits, deletion, replay, truncation, drops, restarts, and signer compromise.
What AI Agent Assurance Claims Actually Cover
How to read an agent assurance claim through its scope, assessor, test version, and renewal conditions.
InfluenceChat: What Failed While Building A Manipulation Dataset
A research note on why real manipulative assistance requests were much harder to retrieve from public LLM logs than expected.
AI Safety in Industrial Control Systems
A hypothetical laboratory boundary case showing where AI recommendations, human authorization, and independent safety controls belong.
What Destructive Chip Inspection Can Tell You
What destructive chip inspection can answer, and why opening the package is only one part of hardware verification.
Inside The /ghs Label Builder
Why I built a browser label tool, how its canvas workflow is structured, and where review still belongs.
December 2025 Site Notes
A short update on the site, privacy language, and the kind of work I am taking on.
Zero Trust Without The Vendor Fog
A practical reading of NIST SP 800-207 and the parts of Zero Trust that matter during implementation.
Home Lab Foundations
A Proxmox-based starting layout, with separate management access, disposable test networks, and a restore test before the next hardware purchase.
TOGAF And Zachman For Security Architecture
Using contractor access to separate TOGAF's method for changing architecture from Zachman's way of organizing its description.
Using C4 Diagrams In Security Work
A practical way to use C4 diagrams for trust boundaries, data flows, and incident response.
4+1 Architecture Views For Security Reviews
How the 4+1 view model can keep security architecture from collapsing into one overloaded diagram.