Perspectives on security operations, analyst cognition, and workflow design
Research-grounded thinking on how modern security operations work and where they break.
The Automation Ceiling: Why SOAR Playbooks Stall at the Hard Part of Response
SOAR automates enrichment, evidence collection, and containment actions cleanly, then stalls at the verdict. Why decision-tree automation breaks on the incidents that matter, and what it means to automate the gathering while leaving judgment to the analyst.
From Cloud Alert to Attack Path: Why Isolated Cloud Findings Waste the SOC's Time
Cloud posture tools fire findings one at a time, each with a severity label and no sense of whether it matters. Why standalone severity scores mislead, why the attack path is the real unit of triage, and what cloud SOC teams should correlate to surface the findings that actually chain into a breach.
Threat Hunting That Sticks: Turning Hunts Into Durable Detections
Most SOC threat hunting is ad-hoc indicator searching that leaves nothing behind. Why the real output of a hunt is a detection, how to frame hunts around a hypothesis or baseline, and how to measure a program where most hunts find nothing.
Detection Decay: Why Your Best Rules Quietly Stop Working
A detection that fires zero alerts looks identical whether the environment is clean or the rule has been broken for months. Why detections degrade silently as log sources drift and environments change, and how to make broken coverage measurable.
Triaging the Machine: Why Non-Human Identity Breaks the SOC Playbook
Service accounts, OAuth tokens, and AI agents don't behave like people — yet SOC triage still assumes they do. Why human-centric detection fails for non-human identity, and what to do about it.
AI XDR vs Traditional XDR: What Multi-Tenant Security Operations Actually Require
Traditional XDR breaks down in multi-tenant environments. AI-powered XDR promises automation — but without tenant-aware context, it makes the problem worse. Here's what MSSPs actually need from an AI XDR platform.
The Shift Handoff Problem: Why SOC Investigations Restart Every 8 Hours
Every SOC shift change destroys investigation context. Analysts rebuild understanding from scratch, attackers exploit the seams, and multi-day threats go untracked.
The Illusion of Visibility: Why More Security Tools Are Making You Less Secure
Adding detection coverage doesn't improve security outcomes. The relationship between signal volume and analyst capacity is breaking the modern SOC.
