September 9, 2026 — Detection Engineering — 5 min readA Repeatable Threat-Hunting Exercise for Small Security TeamsRun a failed-sign-in and role-grant query against invented events. Eight cases expose its timing rules, tenant boundaries, and missing-event problem.September 9, 2026 — AI Systems — 4 min readChoosing an AI Agent Memory Service: Security and Performance TradeoffsStart with ownership and deletion, then measure retrieval. A runnable SQLite example tests tenant scope and records local lookup timings.September 9, 2026 — Detection Engineering — 4 min readEvaluating Identity Detection Coverage Across MSP TenantsCheck what each customer tenant is sending, then follow a detection through the central case and back to an authorized response.September 9, 2026 — AI Security — 4 min readHow to Evaluate Tools for Securing Production AI AgentsGive a vendor a support workflow and inspect what reaches the resource APIs. Test changed approvals, alternate paths, retries, and outages.September 9, 2026 — Security Engineering — 5 min readTamper-Evident AI Agent Logs: Integrity, Gaps, and LimitsA valid log can still be incomplete. A small Python verifier shows what changes when you retain a checkpoint and what a compromised signer can forge.September 9, 2026 — AI Security — 4 min readWhat AI Agent Assurance Claims Actually CoverReading an agent assurance report closely enough to find out which permissions were tested and when the results need revisiting.June 3, 2026 — AI Safety Research — 4 min readInfluenceChat: What Failed While Building A Manipulation DatasetKeywords and embeddings found the vocabulary of manipulation more often than the intent. The June 2026 results and the plan for synthetic pairs.January 18, 2026 — Industrial Security — 4 min readAI Safety in Industrial Control SystemsFollowing a proposed temperature change from historian data to operator review, including stale readings and an unknown command result.January 17, 2026 — Hardware Security — 3 min readWhat Destructive Chip Inspection Can Tell YouOpening a suspect chip can reveal the problem and destroy information you still need. The test sequence and comparison sample matter.January 9, 2026 — Tools — 3 min readInside The /ghs Label BuilderOne canvas renderer feeds the label preview, PNG export, and print image. Notes on saving drafts, fitting text, and reviewing the source information.December 15, 2025 — Updates — 3 min readDecember 2025 Site NotesMoving to Alexandria, clarifying device reviews, and making more room for unfinished research on the site.January 17, 2025 — Cybersecurity — 4 min readZero Trust Without The Vendor FogFollow an employee, contractor, and export job into one reporting application. Then test what grants access and what actually revokes it.January 15, 2025 — Home Lab — 5 min readHome Lab FoundationsA single-host Proxmox layout with separate test networks and recovery copies, plus the work that makes rebuilding a guest routine.July 2, 2021 — Enterprise Architecture — 4 min readTOGAF And Zachman For Security ArchitectureUse contractor access expiry to work through the difference between planning an architecture change and finding gaps in its description.June 15, 2021 — Architecture — 4 min readUsing C4 Diagrams In Security WorkFollow a customer attachment from the browser to storage, using C4 to locate the ownership check and the paths that might bypass it.May 20, 2021 — Architecture — 4 min read4+1 Architecture Views For Security ReviewsA refund times out and two workers may retry it. Follow the same operation through the logical, code, runtime, and deployment views.