Archives
- 20 Aug How I Would Lead a Security Engineering Team: Outcomes, Evidence, and Trust
- 19 Aug Scaling Security Through Paved Roads, Guardrails, and Team Growth
- 18 Aug From One-Off Reviews to Reusable Security Architecture
- 17 Aug How I Approach Principal-Level Security Engineering
- 14 Aug How I Facilitate a Cybersecurity Tabletop Exercise
- 13 Aug Measuring Whether a Tabletop Exercise Improved Readiness
- 12 Aug Turning Tabletop Findings into Owned Engineering Work
- 11 Aug Building a Cybersecurity Scenario That Tests Authority and Coordination
- 10 Aug Designing Tabletop Exercises Around Decisions That Matter
- 07 Aug A Leadership Review for Security Priorities and Tradeoffs
- 06 Aug Operating a Security Roadmap as a Learning System
- 05 Aug Making the Investment Case for Security Engineering Platforms
- 04 Aug Sequencing Security Foundations, Guardrails, and Product Adoption
- 03 Aug Building a Security Roadmap Around Outcomes Instead of Tools
- 31 Jul Leading a Difficult Security Risk Conversation
- 30 Jul Security Metrics for Executives: What Belongs in the Room
- 29 Jul Building a Security Narrative from Evidence, Options, and Tradeoffs
- 28 Jul Translating Technical Exposure into Business Risk Without Losing Precision
- 27 Jul Writing Security Decision Memos Executives Can Act On
- 24 Jul A Leadership Playbook for Security Analysts and Developers
- 23 Jul Measuring a Mixed Security and Development Team
- 22 Jul Turning Analyst Findings into Durable Engineering Improvements
- 21 Jul Designing the Interface Between Security Analysis and Engineering
- 20 Jul How I Would Structure a Team of Security Analysts and Developers
- 17 Jul Leading the Shift from Security Gatekeeper to Engineering Partner
- 16 Jul Operating a Security Engineering Program: Capacity, Escalation, and Feedback
- 15 Jul Building a Security Service Catalog That Engineering Teams Can Use
- 14 Jul Centralized, Embedded, or Platform-Led Security: Designing the Interfaces
- 13 Jul Choosing a Security Engineering Operating Model That Can Scale
- 10 Jul A Team Playbook for Improving AI-Enabled Application Security
- 09 Jul Operating AI-Enabled Application Security: Ownership, Evidence, and Exceptions
- 08 Jul Engineering AI-Enabled Application Security into the Paved Road
- 07 Jul An Architecture Review Playbook for AI-Enabled Application Security
- 06 Jul AI-Enabled Application Security: What the Team Must Decide Before Building
- 03 Jul How to Lead a Review of Privacy Engineering
- 02 Jul Measuring Privacy Engineering Without Vanity Metrics
- 01 Jul Turning Requirements for Privacy Engineering into Delivery Guardrails
- 30 Jun Designing Privacy Engineering: Trust Boundaries, Failure Modes, and Tradeoffs
- 29 Jun A Practical Risk Model for Privacy Engineering
- 26 Jun A Practical Failure Exercise for Abuse Cases and Fraud Resistance
- 25 Jun Abuse Cases and Fraud Resistance in Production: Signals That Show the Control Works
- 24 Jun Implementing Abuse Cases and Fraud Resistance Without Slowing Delivery
- 23 Jun Failure Modes in Abuse Cases and Fraud Resistance: A Design-Level Analysis
- 22 Jun Defining the Security Outcome for Abuse Cases and Fraud Resistance
- 19 Jun A Team Playbook for Improving Red and Blue Team Collaboration
- 18 Jun Operating Red and Blue Team Collaboration: Ownership, Evidence, and Exceptions
- 17 Jun Engineering Red and Blue Team Collaboration into the Paved Road
- 16 Jun An Architecture Review Playbook for Red and Blue Team Collaboration
- 15 Jun Red and Blue Team Collaboration: What the Team Must Decide Before Building
- 12 Jun How to Lead a Review of Penetration Testing as an Engineering Input
- 11 Jun Measuring Penetration Testing as an Engineering Input Without Vanity Metrics
- 10 Jun Turning Requirements for Penetration Testing as an Engineering Input into Delivery Guardrails
- 09 Jun Designing Penetration Testing as an Engineering Input: Trust Boundaries, Failure Modes, and Tradeoffs
- 08 Jun A Practical Risk Model for Penetration Testing as an Engineering Input
- 05 Jun A Practical Failure Exercise for Security-Focused Code Review
- 04 Jun Security-Focused Code Review in Production: Signals That Show the Control Works
- 04 Jun Cost and Reliability Guardrails for n8n on Fargate
- 03 Jun Implementing Security-Focused Code Review Without Slowing Delivery
- 02 Jun Failure Modes in Security-Focused Code Review: A Design-Level Analysis
- 01 Jun Defining the Security Outcome for Security-Focused Code Review
- 30 May Incident Response Runbooks as n8n Workflows
- 29 May A Team Playbook for Improving Secure Legacy Modernization
- 28 May Synthetic Checks for n8n Webhook and Worker SLAs
- 28 May Operating Secure Legacy Modernization: Ownership, Evidence, and Exceptions
- 27 May Engineering Secure Legacy Modernization into the Paved Road
- 26 May CI/CD Promotion for n8n Workflow Bundles
- 26 May An Architecture Review Playbook for Secure Legacy Modernization
- 25 May Secure Legacy Modernization: What the Team Must Decide Before Building
- 23 May ECS Task IAM Least Privilege for n8n
- 22 May How to Lead a Review of AWS Security Engineering
- 21 May Tenant Aware Automation Boundaries in n8n
- 21 May Measuring AWS Security Engineering Without Vanity Metrics
- 20 May Turning Requirements for AWS Security Engineering into Delivery Guardrails
- 19 May Designing AWS Security Engineering: Trust Boundaries, Failure Modes, and Tradeoffs
- 19 May Backing Up n8n Workflows and State on AWS
- 18 May A Practical Risk Model for AWS Security Engineering
- 16 May GuardDuty Triage for ECS Hosted Automation
- 15 May A Practical Failure Exercise for Python Security Automation
- 14 May Scaling Case Enrichment Workflows With ECS
- 14 May Python Security Automation in Production: Signals That Show the Control Works
- 13 May Implementing Python Security Automation Without Slowing Delivery
- 12 May Failure Modes in Python Security Automation: A Design-Level Analysis
- 12 May Blue Green Releases for n8n on ECS
- 11 May Defining the Security Outcome for Python Security Automation
- 09 May Detecting Suspicious n8n Workflow Changes
- 08 May A Team Playbook for Improving Ruby on Rails Security
- 07 May Operating Ruby on Rails Security: Ownership, Evidence, and Exceptions
- 07 May CloudWatch Dashboards for n8n Worker Health
- 06 May Engineering Ruby on Rails Security into the Paved Road
- 05 May Private Subnet Design for n8n on ECS
- 05 May An Architecture Review Playbook for Ruby on Rails Security
- 04 May Ruby on Rails Security: What the Team Must Decide Before Building
- 02 May ECS Deployment Circuit Breakers for n8n
- 01 May How to Lead a Review of Webhooks, Jobs, and File Processing
- 30 Apr Measuring Webhooks, Jobs, and File Processing Without Vanity Metrics
- 30 Apr Managing n8n Secrets With AWS Secrets Manager
- 29 Apr Turning Requirements for Webhooks, Jobs, and File Processing into Delivery Guardrails
- 28 Apr Running n8n Queue Mode on ECS With Redis
- 28 Apr Designing Webhooks, Jobs, and File Processing: Trust Boundaries, Failure Modes, and Tradeoffs
- 27 Apr A Practical Risk Model for Webhooks, Jobs, and File Processing
- 25 Apr A Blue Team ECS Log Baseline for n8n
- 24 Apr A Practical Failure Exercise for Cryptographic Engineering
- 23 Apr Hardening n8n Webhooks Behind ALB and WAF
- 23 Apr Cryptographic Engineering in Production: Signals That Show the Control Works
- 22 Apr Implementing Cryptographic Engineering Without Slowing Delivery
- 21 Apr Failure Modes in Cryptographic Engineering: A Design-Level Analysis
- 21 Apr Deploying n8n on AWS ECS Fargate
- 20 Apr Defining the Security Outcome for Cryptographic Engineering
- 17 Apr n8n Egress Controls for Security Automation
- 17 Apr A Team Playbook for Improving OAuth and OpenID Connect
- 16 Apr Operating OAuth and OpenID Connect: Ownership, Evidence, and Exceptions
- 15 Apr Engineering OAuth and OpenID Connect into the Paved Road
- 14 Apr Designing a Replayable Authorization Control Plane for Agentic Systems
- 14 Apr An Architecture Review Playbook for OAuth and OpenID Connect
- 13 Apr OAuth and OpenID Connect: What the Team Must Decide Before Building
- 10 Apr How to Lead a Review of Zero Trust for Applications
- 09 Apr Measuring Zero Trust for Applications Without Vanity Metrics
- 09 Apr AI Security Scorecard for Engineering Teams
- 08 Apr Turning Requirements for Zero Trust for Applications into Delivery Guardrails
- 07 Apr Designing Zero Trust for Applications: Trust Boundaries, Failure Modes, and Tradeoffs
- 07 Apr Building a SOC Co-Pilot with Safe Retrieval Boundaries
- 06 Apr A Practical Risk Model for Zero Trust for Applications
- 03 Apr A Practical Failure Exercise for Microservice Trust
- 02 Apr RAG Retention and Data Lifecycle Controls
- 02 Apr Microservice Trust in Production: Signals That Show the Control Works
- 01 Apr Implementing Microservice Trust Without Slowing Delivery
- 31 Mar n8n Change Management and Workflow Provenance
- 31 Mar Failure Modes in Microservice Trust: A Design-Level Analysis
- 30 Mar Defining the Security Outcome for Microservice Trust
- 27 Mar A Team Playbook for Improving SaaS and Integration Security
- 26 Mar Operating SaaS and Integration Security: Ownership, Evidence, and Exceptions
- 26 Mar Eval-Driven Security Testing for LLM Apps
- 25 Mar Engineering SaaS and Integration Security into the Paved Road
- 24 Mar Incident Response for AI Workflow Failures
- 24 Mar An Architecture Review Playbook for SaaS and Integration Security
- 23 Mar SaaS and Integration Security: What the Team Must Decide Before Building
- 20 Mar How to Lead a Review of Third-Party Component Security
- 19 Mar Secure MCP and Tool Server Patterns for Agentic Systems
- 19 Mar Measuring Third-Party Component Security Without Vanity Metrics
- 18 Mar Turning Requirements for Third-Party Component Security into Delivery Guardrails
- 17 Mar Detecting Token Abuse and API Key Theft in LLM Platforms
- 17 Mar Designing Third-Party Component Security: Trust Boundaries, Failure Modes, and Tradeoffs
- 16 Mar A Practical Risk Model for Third-Party Component Security
- 13 Mar A Practical Failure Exercise for Forensic Readiness
- 12 Mar PII Redaction in AI Pipelines Before Retrieval and Logging
- 12 Mar Forensic Readiness in Production: Signals That Show the Control Works
- 11 Mar Implementing Forensic Readiness Without Slowing Delivery
- 10 Mar Red Teaming RAG Applications in a Home Lab
- 10 Mar Failure Modes in Forensic Readiness: A Design-Level Analysis
- 09 Mar Defining the Security Outcome for Forensic Readiness
- 06 Mar A Team Playbook for Improving Ransomware Resilience
- 05 Mar Operating Ransomware Resilience: Ownership, Evidence, and Exceptions
- 05 Mar Automating Phishing Triage with n8n and Guardrailed LLMs
- 04 Mar Engineering Ransomware Resilience into the Paved Road
- 03 Mar Model Supply Chain Security for Self-Hosted AI
- 03 Mar An Architecture Review Playbook for Ransomware Resilience
- 02 Mar Ransomware Resilience: What the Team Must Decide Before Building
- 27 Feb How to Lead a Review of Network Detection Engineering
- 26 Feb RAG Access Control with Attribute-Based Authorization
- 26 Feb Measuring Network Detection Engineering Without Vanity Metrics
- 25 Feb Turning Requirements for Network Detection Engineering into Delivery Guardrails
- 24 Feb Policy as Code for LLM Prompts and n8n Flows
- 24 Feb Designing Network Detection Engineering: Trust Boundaries, Failure Modes, and Tradeoffs
- 23 Feb A Practical Risk Model for Network Detection Engineering
- 20 Feb A Practical Failure Exercise for SIEM Architecture
- 19 Feb SIEM Architecture in Production: Signals That Show the Control Works
- 19 Feb Canary Tokens for RAG Exfiltration Detection
- 18 Feb Implementing SIEM Architecture Without Slowing Delivery
- 17 Feb Failure Modes in SIEM Architecture: A Design-Level Analysis
- 17 Feb Building an AI Security Logging Baseline
- 16 Feb Defining the Security Outcome for SIEM Architecture
- 13 Feb A Team Playbook for Improving Threat Hunting
- 12 Feb Secure Tool Calling for LLM Agents
- 12 Feb Operating Threat Hunting: Ownership, Evidence, and Exceptions
- 11 Feb Engineering Threat Hunting into the Paved Road
- 10 Feb Human-in-the-Loop Approval Gates in n8n Security Workflows
- 10 Feb An Architecture Review Playbook for Threat Hunting
- 09 Feb Threat Hunting: What the Team Must Decide Before Building
- 06 Feb How to Lead a Review of Security Logging and Telemetry
- 05 Feb Vector Database Isolation for Multi-Tenant AI Systems
- 05 Feb Measuring Security Logging and Telemetry Without Vanity Metrics
- 04 Feb Turning Requirements for Security Logging and Telemetry into Delivery Guardrails
- 03 Feb Designing Security Logging and Telemetry: Trust Boundaries, Failure Modes, and Tradeoffs
- 03 Feb Defending RAG Pipelines from Data Poisoning
- 02 Feb A Practical Risk Model for Security Logging and Telemetry
- 30 Jan A Practical Failure Exercise for Detection Engineering
- 29 Jan RAG Threat Modeling: Prompt Injection to Data Exfiltration
- 29 Jan Detection Engineering in Production: Signals That Show the Control Works
- 28 Jan Implementing Detection Engineering Without Slowing Delivery
- 27 Jan Securing n8n Webhooks Against Replay and Abuse
- 27 Jan Failure Modes in Detection Engineering: A Design-Level Analysis
- 26 Jan Defining the Security Outcome for Detection Engineering
- 23 Jan A Team Playbook for Improving Incident Readiness
- 22 Jan Operating Incident Readiness: Ownership, Evidence, and Exceptions
- 22 Jan n8n Credential Hygiene for Security Automation
- 21 Jan Engineering Incident Readiness into the Paved Road
- 20 Jan An Architecture Review Playbook for Incident Readiness
- 19 Jan Security Metrics That Help Engineering Teams
- 19 Jan Incident Readiness: What the Team Must Decide Before Building
- 16 Jan How to Lead a Review of Product Security Incident Response
- 15 Jan Measuring Product Security Incident Response Without Vanity Metrics
- 14 Jan Turning Requirements for Product Security Incident Response into Delivery Guardrails
- 13 Jan Designing Product Security Incident Response: Trust Boundaries, Failure Modes, and Tradeoffs
- 12 Jan Linux Auditd Essentials for Privilege Escalation Detection
- 12 Jan A Practical Risk Model for Product Security Incident Response
- 09 Jan A Practical Failure Exercise for Security Exceptions
- 08 Jan Security Exceptions in Production: Signals That Show the Control Works
- 07 Jan Implementing Security Exceptions Without Slowing Delivery
- 06 Jan Failure Modes in Security Exceptions: A Design-Level Analysis
- 05 Jan Secrets Management for Small Teams: AWS Secrets Manager + CI
- 05 Jan Defining the Security Outcome for Security Exceptions
- 02 Jan A Team Playbook for Improving Security Guardrails and Paved Roads
- 01 Jan Operating Security Guardrails and Paved Roads: Ownership, Evidence, and Exceptions
- 31 Dec Engineering Security Guardrails and Paved Roads into the Paved Road
- 30 Dec An Architecture Review Playbook for Security Guardrails and Paved Roads
- 29 Dec Security Guardrails and Paved Roads: What the Team Must Decide Before Building
- 29 Dec Email Authentication in Practice: SPF, DKIM, and DMARC
- 26 Dec How to Lead a Review of Developer Security Education
- 25 Dec Measuring Developer Security Education Without Vanity Metrics
- 24 Dec Turning Requirements for Developer Security Education into Delivery Guardrails
- 23 Dec Designing Developer Security Education: Trust Boundaries, Failure Modes, and Tradeoffs
- 22 Dec Vulnerability Management Cadence for a Home Lab
- 22 Dec A Practical Risk Model for Developer Security Education
- 19 Dec A Practical Failure Exercise for Security Champions
- 18 Dec Security Champions in Production: Signals That Show the Control Works
- 17 Dec Implementing Security Champions Without Slowing Delivery
- 16 Dec Failure Modes in Security Champions: A Design-Level Analysis
- 15 Dec Supply Chain Security in CI: SBOMs, SLSA, and Sigstore
- 15 Dec Defining the Security Outcome for Security Champions
- 12 Dec A Team Playbook for Improving Application Security Metrics
- 11 Dec Operating Application Security Metrics: Ownership, Evidence, and Exceptions
- 10 Dec Engineering Application Security Metrics into the Paved Road
- 09 Dec Log Clustering and Triage with LMStudio, Python, and SQLite
- 09 Dec An Architecture Review Playbook for Application Security Metrics
- 08 Dec Application Security Metrics: What the Team Must Decide Before Building
- 05 Dec How to Lead a Review of Risk-Based Remediation
- 04 Dec Measuring Risk-Based Remediation Without Vanity Metrics
- 03 Dec Turning Requirements for Risk-Based Remediation into Delivery Guardrails
- 03 Dec Ransomware Recovery Lab: Immutable Backups and Restore Drills
- 02 Dec Designing Risk-Based Remediation: Trust Boundaries, Failure Modes, and Tradeoffs
- 01 Dec A Practical Risk Model for Risk-Based Remediation
- 28 Nov A Practical Failure Exercise for Vulnerability Management
- 27 Nov Vulnerability Management in Production: Signals That Show the Control Works
- 27 Nov Reverse Proxy WAF with Nginx and ModSecurity
- 26 Nov Implementing Vulnerability Management Without Slowing Delivery
- 25 Nov Failure Modes in Vulnerability Management: A Design-Level Analysis
- 24 Nov Defining the Security Outcome for Vulnerability Management
- 21 Nov A Team Playbook for Improving Cloud Data Protection
- 20 Nov Operating Cloud Data Protection: Ownership, Evidence, and Exceptions
- 19 Nov Engineering Cloud Data Protection into the Paved Road
- 18 Nov An Architecture Review Playbook for Cloud Data Protection
- 17 Nov Linux Binary Hardening: RELRO, PIE, NX, and CET
- 17 Nov Cloud Data Protection: What the Team Must Decide Before Building
- 14 Nov How to Lead a Review of Cloud Detection and Logging
- 13 Nov Measuring Cloud Detection and Logging Without Vanity Metrics
- 12 Nov Turning Requirements for Cloud Detection and Logging into Delivery Guardrails
- 11 Nov Kerberos Attack Lab: AS-REP Roasting and Detection
- 11 Nov Designing Cloud Detection and Logging: Trust Boundaries, Failure Modes, and Tradeoffs
- 10 Nov A Practical Risk Model for Cloud Detection and Logging
- 07 Nov Container Breakout Detection with eBPF and Tracee
- 07 Nov A Practical Failure Exercise for Cloud Network Security
- 06 Nov Cloud Network Security in Production: Signals That Show the Control Works
- 05 Nov Implementing Cloud Network Security Without Slowing Delivery
- 04 Nov Failure Modes in Cloud Network Security: A Design-Level Analysis
- 03 Nov Defining the Security Outcome for Cloud Network Security
- 31 Oct A Team Playbook for Improving Cloud Identity and Access Management
- 30 Oct Threat Intel Enrichment with STIX/TAXII and Python
- 30 Oct Operating Cloud Identity and Access Management: Ownership, Evidence, and Exceptions
- 29 Oct Engineering Cloud Identity and Access Management into the Paved Road
- 28 Oct An Architecture Review Playbook for Cloud Identity and Access Management
- 27 Oct Cloud Identity and Access Management: What the Team Must Decide Before Building
- 24 Oct Local LLM Log Summaries with LMStudio and Python
- 24 Oct How to Lead a Review of SBOMs and Build Provenance
- 23 Oct Measuring SBOMs and Build Provenance Without Vanity Metrics
- 22 Oct Turning Requirements for SBOMs and Build Provenance into Delivery Guardrails
- 21 Oct Designing SBOMs and Build Provenance: Trust Boundaries, Failure Modes, and Tradeoffs
- 20 Oct A Practical Risk Model for SBOMs and Build Provenance
- 17 Oct A Practical Failure Exercise for Software Supply Chain Security
- 16 Oct Software Supply Chain Security in Production: Signals That Show the Control Works
- 15 Oct Implementing Software Supply Chain Security Without Slowing Delivery
- 14 Oct Hardening SSH: Modern Ciphers, MFA, and Audit Trails
- 14 Oct Failure Modes in Software Supply Chain Security: A Design-Level Analysis
- 13 Oct Defining the Security Outcome for Software Supply Chain Security
- 10 Oct A Team Playbook for Improving CI/CD Pipeline Security
- 09 Oct Operating CI/CD Pipeline Security: Ownership, Evidence, and Exceptions
- 08 Oct Engineering CI/CD Pipeline Security into the Paved Road
- 07 Oct Detecting Lateral Movement with SMB and WinRM Telemetry
- 07 Oct An Architecture Review Playbook for CI/CD Pipeline Security
- 06 Oct CI/CD Pipeline Security: What the Team Must Decide Before Building
- 03 Oct TLS 1.3 Handshake Analysis with OpenSSL and Wireshark
- 03 Oct How to Lead a Review of Kubernetes Security
- 02 Oct Measuring Kubernetes Security Without Vanity Metrics
- 01 Oct Turning Requirements for Kubernetes Security into Delivery Guardrails
- 30 Sep Designing Kubernetes Security: Trust Boundaries, Failure Modes, and Tradeoffs
- 29 Sep A Practical Risk Model for Kubernetes Security
- 26 Sep Home SIEM Architecture: Wazuh + OpenSearch + Zeek
- 26 Sep A Practical Failure Exercise for Container Security
- 25 Sep Container Security in Production: Signals That Show the Control Works
- 24 Sep Implementing Container Security Without Slowing Delivery
- 23 Sep Failure Modes in Container Security: A Design-Level Analysis
- 22 Sep Defining the Security Outcome for Container Security
- 19 Sep A Team Playbook for Improving Infrastructure as Code Security
- 18 Sep Practical YARA Engineering for Malware Triage
- 18 Sep Operating Infrastructure as Code Security: Ownership, Evidence, and Exceptions
- 17 Sep Engineering Infrastructure as Code Security into the Paved Road
- 16 Sep An Architecture Review Playbook for Infrastructure as Code Security
- 15 Sep Infrastructure as Code Security: What the Team Must Decide Before Building
- 12 Sep How to Lead a Review of Secrets Management
- 11 Sep Windows Telemetry in Depth: Sysmon + WEF in a Lab
- 11 Sep Measuring Secrets Management Without Vanity Metrics
- 10 Sep Turning Requirements for Secrets Management into Delivery Guardrails
- 09 Sep Designing Secrets Management: Trust Boundaries, Failure Modes, and Tradeoffs
- 08 Sep A Practical Risk Model for Secrets Management
- 05 Sep Detecting DNS Tunneling with Zeek, Passive DNS, and Python
- 05 Sep A Practical Failure Exercise for Dependency Risk Management
- 04 Sep Dependency Risk Management in Production: Signals That Show the Control Works
- 03 Sep Implementing Dependency Risk Management Without Slowing Delivery
- 02 Sep Failure Modes in Dependency Risk Management: A Design-Level Analysis
- 01 Sep Defining the Security Outcome for Dependency Risk Management
- 29 Aug A Team Playbook for Improving Dynamic Application Security Testing
- 28 Aug Operating Dynamic Application Security Testing: Ownership, Evidence, and Exceptions
- 28 Aug Building a Zeek and Suricata Dual Sensor for a Home Lab
- 27 Aug Engineering Dynamic Application Security Testing into the Paved Road
- 26 Aug An Architecture Review Playbook for Dynamic Application Security Testing
- 25 Aug Dynamic Application Security Testing: What the Team Must Decide Before Building
- 22 Aug How to Lead a Review of Static Application Security Testing
- 21 Aug Measuring Static Application Security Testing Without Vanity Metrics
- 20 Aug Turning Requirements for Static Application Security Testing into Delivery Guardrails
- 19 Aug Designing Static Application Security Testing: Trust Boundaries, Failure Modes, and Tradeoffs
- 19 Aug Build a Command-Line LLM with Python
- 18 Aug A Practical Risk Model for Static Application Security Testing
- 15 Aug A Practical Failure Exercise for Security Requirements
- 14 Aug Security Requirements in Production: Signals That Show the Control Works
- 13 Aug Implementing Security Requirements Without Slowing Delivery
- 12 Aug Failure Modes in Security Requirements: A Design-Level Analysis
- 11 Aug Defining the Security Outcome for Security Requirements
- 08 Aug A Team Playbook for Improving Secure Software Development Lifecycle
- 07 Aug Operating Secure Software Development Lifecycle: Ownership, Evidence, and Exceptions
- 07 Aug Cross-Site Scripting (XSS): A Technical Deep Dive
- 06 Aug Engineering Secure Software Development Lifecycle into the Paved Road
- 05 Aug An Architecture Review Playbook for Secure Software Development Lifecycle
- 04 Aug Secure Software Development Lifecycle: What the Team Must Decide Before Building
- 01 Aug How to Lead a Review of Security Design Review Programs
- 31 Jul Measuring Security Design Review Programs Without Vanity Metrics
- 30 Jul Turning Requirements for Security Design Review Programs into Delivery Guardrails
- 29 Jul Designing Security Design Review Programs: Trust Boundaries, Failure Modes, and Tradeoffs
- 28 Jul A Practical Risk Model for Security Design Review Programs
- 25 Jul A Practical Failure Exercise for Secure Architecture
- 24 Jul Secure Architecture in Production: Signals That Show the Control Works
- 23 Jul Implementing Secure Architecture Without Slowing Delivery
- 22 Jul Failure Modes in Secure Architecture: A Design-Level Analysis
- 21 Jul Defining the Security Outcome for Secure Architecture
- 18 Jul A Team Playbook for Improving API Security
- 17 Jul Operating API Security: Ownership, Evidence, and Exceptions
- 16 Jul Engineering API Security into the Paved Road
- 15 Jul An Architecture Review Playbook for API Security
- 14 Jul API Security: What the Team Must Decide Before Building
- 11 Jul How to Lead a Review of Output Encoding and Browser Security
- 10 Jul Measuring Output Encoding and Browser Security Without Vanity Metrics
- 09 Jul Turning Requirements for Output Encoding and Browser Security into Delivery Guardrails
- 08 Jul Designing Output Encoding and Browser Security: Trust Boundaries, Failure Modes, and Tradeoffs
- 07 Jul A Practical Risk Model for Output Encoding and Browser Security
- 04 Jul A Practical Failure Exercise for Input Validation and Injection Prevention
- 03 Jul Input Validation and Injection Prevention in Production: Signals That Show the Control Works
- 02 Jul Implementing Input Validation and Injection Prevention Without Slowing Delivery
- 01 Jul Failure Modes in Input Validation and Injection Prevention: A Design-Level Analysis
- 30 Jun Defining the Security Outcome for Input Validation and Injection Prevention
- 27 Jun A Team Playbook for Improving Session Security
- 26 Jun Operating Session Security: Ownership, Evidence, and Exceptions
- 25 Jun Engineering Session Security into the Paved Road
- 24 Jun An Architecture Review Playbook for Session Security
- 23 Jun Session Security: What the Team Must Decide Before Building
- 20 Jun How to Lead a Review of Authorization
- 19 Jun Measuring Authorization Without Vanity Metrics
- 18 Jun Turning Requirements for Authorization into Delivery Guardrails
- 17 Jun Designing Authorization: Trust Boundaries, Failure Modes, and Tradeoffs
- 16 Jun A Practical Risk Model for Authorization
- 13 Jun A Practical Failure Exercise for Authentication
- 12 Jun Authentication in Production: Signals That Show the Control Works
- 11 Jun Implementing Authentication Without Slowing Delivery
- 10 Jun Failure Modes in Authentication: A Design-Level Analysis
- 09 Jun Defining the Security Outcome for Authentication
- 06 Jun A Team Playbook for Improving Threat Modeling
- 05 Jun Operating Threat Modeling: Ownership, Evidence, and Exceptions
- 04 Jun Engineering Threat Modeling into the Paved Road
- 04 Jun Understanding the MITRE ATT&CK Framework
- 03 Jun An Architecture Review Playbook for Threat Modeling
- 02 Jun Threat Modeling: What the Team Must Decide Before Building
- 30 May How to Lead a Review of Security-First Product Engineering
- 29 May Measuring Security-First Product Engineering Without Vanity Metrics
- 28 May Turning Requirements for Security-First Product Engineering into Delivery Guardrails
- 27 May Building a Home Lab Firewall
- 20 May Social Engineering Awareness
- 13 May Introduction to Threat Hunting
- 06 May Automating Tasks with Bash
- 29 Apr Incident Response Essentials
- 22 Apr Basics of File System Forensics
- 15 Apr Cryptography Fundamentals
- 08 Apr Understanding TLS and SSL
- 01 Apr Hardening Windows Systems
- 25 Mar What Are Syscalls in Linux and How Can We Use Them?
- 18 Mar Python for Security Professionals
- 14 Mar Mastering Autorecon: A Comprehensive Guide
- 11 Mar How to run a successful cybersecurity tabletop exercise
- 05 Mar Exploiting Ivanti Connect Secure RCE (CVE-2025-0282)
- 27 Feb Understanding the Slowloris Attack
- 18 Feb Why Password Strength Matters
- 11 Feb Packet Sniffing with Wireshark
- 28 Jan OWASP Top 10 Overview
- 21 Jan Intro to Virtualization
- 14 Jan Essential Linux Commands for Security
- 07 Jan Network Scanning Basics
- 02 Jan Building Your Home Lab