Research

Practical security observability.

Notes for teams operating detections, telemetry pipelines, networks and cloud infrastructure.

CRA reporting starts before the 24-hour clock

How to connect product vulnerabilities, runtime exposure and technical evidence before notification is required.

Read article →

Monitoring security data is not the same as proving coverage

A concrete model for testing the complete path from source to owner.

Read article →

Why a valid detection rule still cannot fire

How to expose missing fields, routes and dependencies before an incident.

Read article →

What NetFlow sees, what it misses and where sensors belong

A deployment guide for useful network visibility without agents everywhere.

Read article →