KevinBytes

Security research, tools, and writing by Kevin O'Connor

KevinBytes circuit wave brand artwork
A Repeatable Threat-Hunting Exercise for Small Security TeamsRun a failed-sign-in and role-grant query against invented events. Eight cases expose its timing rules, tenant boundaries, and missing-event problem.Choosing an AI Agent Memory Service: Security and Performance TradeoffsStart with ownership and deletion, then measure retrieval. A runnable SQLite example tests tenant scope and records local lookup timings.Evaluating Identity Detection Coverage Across MSP TenantsCheck what each customer tenant is sending, then follow a detection through the central case and back to an authorized response.How to Evaluate Tools for Securing Production AI AgentsGive a vendor a support workflow and inspect what reaches the resource APIs. Test changed approvals, alternate paths, retries, and outages.
Steganography postcard artwork used by the steganography tools on this site
Tamper-Evident AI Agent Logs: Integrity, Gaps, and LimitsA valid log can still be incomplete. A small Python verifier shows what changes when you retain a checkpoint and what a compromised signer can forge.What AI Agent Assurance Claims Actually CoverReading an agent assurance report closely enough to find out which permissions were tested and when the results need revisiting.InfluenceChat: What Failed While Building A Manipulation DatasetKeywords and embeddings found the vocabulary of manipulation more often than the intent. The June 2026 results and the plan for synthetic pairs.AI Safety in Industrial Control SystemsFollowing a proposed temperature change from historian data to operator review, including stale readings and an unknown command result.What Destructive Chip Inspection Can Tell YouOpening a suspect chip can reveal the problem and destroy information you still need. The test sequence and comparison sample matter.
Sample artifact visual from the forensic tooling write-ups
Inside The /ghs Label BuilderOne canvas renderer feeds the label preview, PNG export, and print image. Notes on saving drafts, fitting text, and reviewing the source information.December 2025 Site NotesMoving to Alexandria, clarifying device reviews, and making more room for unfinished research on the site.Zero Trust Without The Vendor FogFollow an employee, contractor, and export job into one reporting application. Then test what grants access and what actually revokes it.Home Lab FoundationsA single-host Proxmox layout with separate test networks and recovery copies, plus the work that makes rebuilding a guest routine.TOGAF And Zachman For Security ArchitectureUse contractor access expiry to work through the difference between planning an architecture change and finding gaps in its description.Using C4 Diagrams In Security WorkFollow a customer attachment from the browser to storage, using C4 to locate the ownership check and the paths that might bypass it.
KevinBytes banner artwork
4+1 Architecture Views For Security ReviewsA refund times out and two workers may retry it. Follow the same operation through the logical, code, runtime, and deployment views.