Build Journal
I now publish every two weeks. I choose one problem from ThreatWatch or RedBlue and write down what changed my mind: the constraint, the decision, the evidence, and what I would do differently. No release notes, no filler.
RedBlue Architecture Takes Shape
A scoring script was no longer enough, so I shaped RedBlue around the full path from exposure to response.
ThreatWatch Feed Audit Planning
The source audit I wanted for ThreatWatch: freshness, reliability, evidence, duplication, and genuinely unique signal.
Indirect Prompt Injection and RAG
I treat retrieved documents as hostile input, especially when a model can reach tools, credentials, or side effects.
ThreatWatch Analysis Quality
Keyword ranking kept rewarding familiar names. I started measuring novelty, freshness, and source health instead.
Session-Based Phishing and Strong Authentication
Why I avoid the phrase MFA bypass, and why origin-bound authentication changes the session problem.
QR Phishing as a Cross-Device Detection Gap
The interesting part of QR phishing is not the code. It is the jump from a managed inbox to a less visible device.
D3FEND Mapping and the First Coverage Output
Adding D3FEND gave me the first honest view of which campaign stages had rules, controls, telemetry, or nothing.
Long-Context Model Security
My notes on many-shot jailbreaking and why long context changes the security boundary around model-assisted workflows.
Detection Lifecycle Implementation Begins
I put the campaign model into code while keeping ThreatWatch analysis quality as the parallel constraint.
First Journal Review and Q1 Direction
A short look back at the first build cycle, and why connecting intelligence to action became the next priority.