Threat Investigation1 min read

Exposed by Their Paperwork

The most interesting detail in OpenAI's new report isn't that state actors used ChatGPT to write propaganda. It's that Russian operatives used it to…

Read →
Threat Investigation2 min read

Signal vs. Noise

Analysts at managed security service providers say 53% of the alerts they get are false positives, and 44% say they ignore alerts when the queue gets…

Read →
Phishing1 min read

How I Work a Phishing Case

21 seconds. That's the median time between someone opening a phishing email and clicking the link, in the simulation data behind Verizon's 2024 DBIR…

Read →
Spoofing1 min read

The Spoofing Timeline

Spoofed mail got past controls that were supposed to stop it. The question was simple: why didn't anything block this?

Read →
Career1 min read

How I Got Here

I didn't start in threat investigation. I started in Tier 1 support. Tier 1 to Tier 2. Then promoted into MSP Escalations based on investigation…

Read →
AI1 min read

Why I Built 4 Agents

SOC teams get an average of 2,992 alerts a day, and 63% of them go unaddressed. (Vectra AI, 2026 State of Threat Detection and Response)

Read →
Investigation1 min read

The UI Lies by Omission

The UI tells you what the product decided. The backend tells you why. When a case gets weird, I stop trusting the dashboard and start querying:

Read →
Escalation1 min read

498 Defects, 315 Fixed

I've documented and escalated 498 product defects to R&D. 315 of them reached DONE. Every one went in with logs, artifacts, and reproduction steps.

Read →
BEC1 min read

The Inbox Rule Nobody Made

Microsoft's own guidance on compromised mailboxes lists suspicious inbox rules as a warning sign: rules that auto-forward mail to unknown addresses…

Read →
Identity1 min read

MFA Is a Data Point, Not a Verdict

Microsoft's 2025 Digital Defense Report: more than 97% of identity attacks are password spray or brute force, and identity-based attacks rose 32% in…

Read →
Third-Party Risk1 min read

When the Real Vendor Is the Attacker

Verizon's 2026 DBIR: 48% of breaches involved a third party, up from 30% the year before. In email, one of the nastiest versions of that is vendor…

Read →
Quishing1 min read

The Link You Can't See

Microsoft Threat Intelligence tracked QR code phishing attacks rising from 7.6 million in January 2026 to 18.7 million in March. A 146% increase in…

Read →
DMARC1 min read

Compliant Is Not Protected

Since February 2024, Gmail has required anyone sending more than 5,000 messages a day to personal Gmail accounts to authenticate with SPF, DKIM and…

Read →
Incident Response1 min read

21 Seconds vs. 254 Days

21 seconds: the median time to click a phishing link after opening the email, in the simulation data behind Verizon's 2024 DBIR.

Read →
AI1 min read

Typos Are Dead

In a 2024 study by Heiding, Schneier, Vishwanath and colleagues, fully AI-automated spear phishing emails got a 54% click-through rate. Phishing…

Read →
AI1 min read

Useful Only If You Can Audit It

IBM's 2026 Cost of a Data Breach report: organizations making extensive use of security AI and automation lowered their average breach costs by $1.93…

Read →
AI Safety1 min read

Stress-Testing AI Models

Outside my day job, I test AI models the way I'd investigate anything else: assume nothing, collect evidence, look for patterns.

Read →
Awareness1 min read

The Click Isn't the Failure

From Verizon's 2024 DBIR: in phishing simulation data, 20% of users reported the phishing email, and 11% of the users who clicked it also reported it.

Read →
Incident Response1 min read

The Clock After the Wire

In 2025, the FBI's Recovery Asset Team froze $679 million in fraudulent transfers, about 58% of the roughly $1.16 billion it went after. (FBI IC3…

Read →
Root Cause1 min read

The Click Is Just the Surface

"The user clicked a phishing link" is a symptom, not a root cause. Walk a typical account compromise backward and the real questions show up:

Read →
DLP1 min read

Why DLP Isn't a Checkbox

Change Healthcare told HHS's Office for Civil Rights that about 192.7 million people were affected by its breach.

Read →
Malware1 min read

Investigate the Near Miss

Verizon's 2026 DBIR found ransomware in 48% of breaches. Exploited vulnerabilities are now the top way in, per the same report. But email is still a…

Read →
Community1 min read

22%: Women on Security Teams

In ISC2's 2024 Workforce Study, women made up 22% of security teams on average. I'm one of them, and I didn't get here alone.

Read →
Threat Investigation1 min read

$20 Billion and Counting

Losses reported to the FBI passed $20 billion in 2025 for the first time, from more than 1 million complaints. (FBI IC3 2025 Internet Crime Report)

Read →