Blog

Perspectives on security operations, analyst cognition, and workflow design

Research-grounded thinking on how modern security operations work and where they break.

AutomationJun 12, 20269 min read

The Automation Ceiling: Why SOAR Playbooks Stall at the Hard Part of Response

SOAR automates enrichment, evidence collection, and containment actions cleanly, then stalls at the verdict. Why decision-tree automation breaks on the incidents that matter, and what it means to automate the gathering while leaving judgment to the analyst.

Cloud SecurityJun 11, 20269 min read

From Cloud Alert to Attack Path: Why Isolated Cloud Findings Waste the SOC's Time

Cloud posture tools fire findings one at a time, each with a severity label and no sense of whether it matters. Why standalone severity scores mislead, why the attack path is the real unit of triage, and what cloud SOC teams should correlate to surface the findings that actually chain into a breach.

Threat HuntingJun 8, 20269 min read

Threat Hunting That Sticks: Turning Hunts Into Durable Detections

Most SOC threat hunting is ad-hoc indicator searching that leaves nothing behind. Why the real output of a hunt is a detection, how to frame hunts around a hypothesis or baseline, and how to measure a program where most hunts find nothing.

Detection EngineeringJun 5, 20268 min read

Detection Decay: Why Your Best Rules Quietly Stop Working

A detection that fires zero alerts looks identical whether the environment is clean or the rule has been broken for months. Why detections degrade silently as log sources drift and environments change, and how to make broken coverage measurable.

IdentityJun 3, 20268 min read

Triaging the Machine: Why Non-Human Identity Breaks the SOC Playbook

Service accounts, OAuth tokens, and AI agents don't behave like people — yet SOC triage still assumes they do. Why human-centric detection fails for non-human identity, and what to do about it.

OperationsMar 30, 20268 min read

AI XDR vs Traditional XDR: What Multi-Tenant Security Operations Actually Require

Traditional XDR breaks down in multi-tenant environments. AI-powered XDR promises automation — but without tenant-aware context, it makes the problem worse. Here's what MSSPs actually need from an AI XDR platform.

OperationsMar 28, 20267 min read

The Shift Handoff Problem: Why SOC Investigations Restart Every 8 Hours

Every SOC shift change destroys investigation context. Analysts rebuild understanding from scratch, attackers exploit the seams, and multi-day threats go untracked.

OperationsMar 12, 20269 min read

The Illusion of Visibility: Why More Security Tools Are Making You Less Secure

Adding detection coverage doesn't improve security outcomes. The relationship between signal volume and analyst capacity is breaking the modern SOC.

Looking for deeper research?

Our whitepapers cover SOC analytics, threat modeling, and security architecture in depth.