Entry 171 March 2026

RedBlue Architecture Takes Shape

A scoring script was no longer enough, so I shaped RedBlue around the full path from exposure to response.

RedBlueDetection EngineeringSecurity Operations
Entry 1622 February 2026

ThreatWatch Feed Audit Planning

The source audit I wanted for ThreatWatch: freshness, reliability, evidence, duplication, and genuinely unique signal.

ThreatWatchThreat IntelligencePlanning
Entry 1515 February 2026

Indirect Prompt Injection and RAG

I treat retrieved documents as hostile input, especially when a model can reach tools, credentials, or side effects.

LLM SecurityPrompt InjectionRAG
Entry 148 February 2026

ThreatWatch Analysis Quality

Keyword ranking kept rewarding familiar names. I started measuring novelty, freshness, and source health instead.

ThreatWatchThreat IntelligenceCTI
Entry 131 February 2026

Session-Based Phishing and Strong Authentication

Why I avoid the phrase MFA bypass, and why origin-bound authentication changes the session problem.

Identity SecurityPhishingDetection Engineering
Entry 1225 January 2026

QR Phishing as a Cross-Device Detection Gap

The interesting part of QR phishing is not the code. It is the jump from a managed inbox to a less visible device.

PhishingDetection EngineeringSecurity Awareness
Entry 1118 January 2026

D3FEND Mapping and the First Coverage Output

Adding D3FEND gave me the first honest view of which campaign stages had rules, controls, telemetry, or nothing.

Detection EngineeringD3FENDATT&CKThreatWatch
Entry 1011 January 2026

Long-Context Model Security

My notes on many-shot jailbreaking and why long context changes the security boundary around model-assisted workflows.

LLM SecurityJailbreakingSecurity Research
Entry 94 January 2026

Detection Lifecycle Implementation Begins

I put the campaign model into code while keeping ThreatWatch analysis quality as the parallel constraint.

Detection EngineeringATT&CKSigmaThreatWatch
Entry 828 December 2025

First Journal Review and Q1 Direction

A short look back at the first build cycle, and why connecting intelligence to action became the next priority.

ThreatWatchDetection EngineeringPlanning