[nicholai.me]
  • projects
  • journal
  • about
~/research

Build Journal

I now publish every two weeks. I choose one problem from ThreatWatch or RedBlue and write down what changed my mind: the constraint, the decision, the evidence, and what I would do differently. No release notes, no filler.

Entry 725 December 2025

Campaign-Level Detection Coverage

Why I moved away from flat rule counts and towards campaign paths, telemetry, and the gaps between them.

Detection EngineeringATT&CKResearch
Entry 618 December 2025

Modelling the Detection Lifecycle

I turned the coverage sketches into a model that separates available rules from detections an environment can actually run.

Detection EngineeringATT&CKSigmaThreatWatch
Entry 511 December 2025

ThreatWatch Expansion and Analysis Guardrails

Adding sources was easy. Keeping automated analysis tied to evidence became the more important constraint.

ThreatWatchLLM SecurityThreat Intelligence
Entry 44 December 2025

Authorised Simulation and Detection Lessons

What an end-to-end lab simulation taught me about scope, evidence collection, and useful reporting.

Security TestingDetection EngineeringThreatWatch
Entry 327 November 2025

Content Fingerprinting and Defensive Mapping

I replaced headline matching with content fingerprints and used D3FEND to make defensive coverage less vague.

ThreatWatchD3FENDDetection Engineering
Entry 220 November 2025

ThreatWatch First Run and the Signal Problem

The first ThreatWatch run collected plenty of reporting. Finding the part worth reading was the harder problem.

ThreatWatchThreat IntelligenceDetection Engineering
Entry 113 November 2025

Starting the Research Journal

Why I started ThreatWatch narrowly, and the telemetry question that shaped the detection work beside it.

ThreatWatchDetection EngineeringPlanning
page 3 of 3
← newer
123
older →
~/nicholai▌LinkedInGitHubAuvaLabsRSS