S SyberOps Try the agent
Research · Long-form essays

The arguments behind the agent.

Long-form essays on agentic AI in security operations. The threat models, the information-theoretic limits, the design principles. Written for SOC engineers and security architects who have to make this work in production.

Threat Model · Agentic AI

Prompt injection inside a SOC agent

The threat model nobody wrote down, a five-pattern attack taxonomy, the defenses that don't work, and the structural defenses that do. The full field guide for any team shipping LLM-assisted triage in front of a SIEM.

18 min read · 25 April 2026
Theory · SOC Architecture

Why rule-based SIEM hits a mathematical ceiling above 10k alerts/day

It's not a tooling problem. It's an information-theory problem. A first-principles argument for why throwing more analysts at the queue can never close the gap — and what the bound implies for how SOC architecture has to change.

11 min read · 22 April 2026
Architecture · Compliance

Building an accountable autonomous SOC

Six design principles for AI triage that scales without becoming a compliance bomb. Built from incident reviews, audit findings, and what we've learned shipping an agent that has to survive its own mistakes in production.

14 min read · 20 April 2026