Blog

Perspectives on security operations, analyst cognition, and workflow design

Research-grounded thinking on how modern security operations work and where they break.

Operations•Sep 21, 2026•7 min read

The Variance Problem: Why the Same Alert Gets Two Different Answers

The same alert, worked by two analysts, routinely produces two different conclusions. The gap between your strongest and weakest analyst is the least measured risk in security operations.

Detection Engineering•Sep 10, 2026•9 min read

Seven Hundred Attackers, One Investigation

The Hugging Face incident was not one model breaking out. It was a swarm that organized itself, divided labor, and split an attack across hundreds of actors. Nothing in a normal detection stack is built to see that.

Automation•Jun 12, 2026•9 min read

The Automation Ceiling: Why SOAR Playbooks Stall at the Hard Part of Response

SOAR automates enrichment, evidence collection, and containment actions cleanly, then stalls at the verdict. Why decision-tree automation breaks on the incidents that matter, and what it means to automate the gathering while leaving judgment to the analyst.

Cloud Security•Jun 11, 2026•9 min read

From Cloud Alert to Attack Path: Why Isolated Cloud Findings Waste the SOC's Time

Cloud posture tools fire findings one at a time, each with a severity label and no sense of whether it matters. Why standalone severity scores mislead, why the attack path is the real unit of triage, and what cloud SOC teams should correlate to surface the findings that actually chain into a breach.

Threat Hunting•Jun 8, 2026•9 min read

Threat Hunting That Sticks: Turning Hunts Into Durable Detections

Most SOC threat hunting is ad-hoc indicator searching that leaves nothing behind. Why the real output of a hunt is a detection, how to frame hunts around a hypothesis or baseline, and how to measure a program where most hunts find nothing.

Detection Engineering•Jun 5, 2026•8 min read

Detection Decay: Why Your Best Rules Quietly Stop Working

A detection that fires zero alerts looks identical whether the environment is clean or the rule has been broken for months. Why detections degrade silently as log sources drift and environments change, and how to make broken coverage measurable.

Identity•Jun 3, 2026•8 min read

Triaging the Machine: Why Non-Human Identity Breaks the SOC Playbook

Service accounts, OAuth tokens, and AI agents don't behave like people, yet SOC triage still assumes they do. Why human-centric detection fails for non-human identity, and what to do about it.

Operations•Mar 30, 2026•8 min read

AI XDR vs Traditional XDR: What Multi-Tenant Security Operations Actually Require

Traditional XDR breaks down in multi-tenant environments. AI-powered XDR promises automation, but without tenant-aware context, it makes the problem worse. Here's what MSSPs actually need from an AI XDR platform.

Operations•Mar 12, 2026•9 min read

The Illusion of Visibility: Why More Security Tools Are Making You Less Secure

Adding detection coverage doesn't improve security outcomes. The relationship between signal volume and analyst capacity is breaking the modern SOC.

Looking for deeper research?

Our whitepapers cover SOC analytics, threat modeling, and security architecture in depth.