1. What a Good ICS Detection Looks Like in Practice

    There is a lot of advice about ICS detection that talks about MODBUS, DNP3, and the protocol layers. This is the part that comes after the protocol talk: what a good detection actually looks like in the SIEM, and what the SOC analyst does with it

    ICS OT Security

  2. How to Build an Insider-Risk Programme That Actually Catches the Bad Cases

    Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter

    Insider Threat Blue Team

  3. The Detection Rule That Changed How I Think About Fidelity

    There is one detection rule in my career that genuinely changed how I think about detection fidelity. It was not a clever rule. It was a simple rule. The simplicity is what taught me the most. Here is the rule and what it taught me

  4. How to Hire a Detection Engineer When You Have Never Hired One Before

    Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire

    Blue Team

  5. The Six-Month Build: What a Real Detection Engineering Programme Looks Like

    Most 'detection engineering programmes' are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs

    Blue Team

  6. What a Good Detection Engineer Actually Does All Day

    The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right

    Blue Team

  7. Building a Detection Baseline: The Work Nobody Wants to Do

    Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work

    Blue Team

  8. Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts

    Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not

    Purple Teaming

  9. Living Off the Land: Why the Best Attackers Don't Look Like Attackers

    Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…

    Red Team Blue Team

  10. The Insider Threat Problem Is Not What You Think

    Your insider threat programme is aimed at the wrong target

    Insider Threat Threat Modelling