Identity threat detection and response in plain English
ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply.
Opinionated analysis, guides, and expert takes from security operations practitioners.
ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply.
Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it.
Security culture is behavior under pressure, not a values doc. Here's how to build it from scratch before it builds itself into something you'll spend years fixing.
Most CNAPPs and CSPMs are sold as cloud-native security but deliver cloud hygiene. Here's the structural gap and how to spot it in a vendor demo.
AI triage is live in production SOCs. Learn which pipeline stages to trust it with, which to keep human-reviewed, and how to catch the new failure modes.
AI triage hasn't moved alert fatigue. The structural causes start upstream. Here's what to fix before another AI SOC pilot.
Detection engineering stalls when it's treated as a person, not a function. Here's what the function actually owns, and how to build it from Level 0.
Most IRPs are written for auditors, not analysts. Here's what a usable incident response plan actually contains, plus a stripped-down template.