Writing
Research and field notes
Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.
All4+1 ArchitectureAccess ControlAI AgentsAI Safety ResearchArchitecture DiagramsAssuranceC4 ModelCybersecurityDetection EngineeringDocumentationEnterprise ArchitectureEvaluationHardware SecurityHome LabIdentityIndustrial SecurityIntegrityKruchtenLoggingMemoryMicrosoft EntraMSPPerformancePythonReproducibilitySecurity ArchitectureSQLSystem ArchitectureTenancyThreat HuntingTOGAFToolsUpdatesZachman FrameworkZero Trust
Latest
A Repeatable Threat-Hunting Exercise for Small Security Teams
A local identity hunt with synthetic records, executable SQL, negative cases, and explicit blind spots.
September 9, 20264 min readDetection Engineering
Read note
September 9, 20264 min read
Evaluating Identity Detection Coverage Across MSP Tenants
A bounded Microsoft Entra evaluation method, with synthetic cases for correlation and tenant separation.
Microsoft EntraIdentityMSP