Writing
Notes on security engineering, architecture, and the things that only show up once you've shipped.
The Vulnerable State of Vulnerability Management
Scanner findings tell you what exists, not what matters. How CTEM and a FAIR-inspired residual risk model reorder the queue around actual exposure, without a new tool or a renewal invoice.
Endpoint Privilege Management: The Gap Between Marketed and Actual Least Privilege
A case study from evaluating several leading EPM platforms: where the tooling falls short of the principle it claims to enforce, and what a genuinely granular policy model looks like.
From Noise to Signal: Reducing Alert Fatigue Through High-Fidelity Detection Engineering
How I took a stream of 120,000+ low-fidelity daily EDR events down to under 7,000 high-value ones, and the three-step process that made it repeatable.