Blog

/var/www/html/intel_logs/

// CLASSIFIED_INTEL_REPOSITORY

field notes from the watch floor — soc, grc, threat intel, ai security
STATUS: ONLINE ACCESS: PUBLIC ENCRYPTION: AES-256 AUTHOR: NAS-982-202-ALPHA ENTRIES: 04
LOG_004
2025-11-15
// architecture
ZERO TRUST

The Castle is Dead: Zero Trust Architecture

The era of “Castle and Moat” is over. A walkthrough of NIST 800-207, identity as the new perimeter, and why “Never Trust, Always Verify” is the only defensible posture for hybrid and remote-first enterprises — with a practical maturity ladder you can take to leadership.
NIST 800-207 · ZTA · IDENTITY · SEGMENTATION
[ DECRYPT_FILE ]
LOG_003
2025-10-02
// threat_intel
THREAT INTEL

Signal vs. Noise: Actionable Intelligence

Raw data is not intelligence. How to filter IOCs, map activity to MITRE ATT&CK, and translate technical alerts into strategic decisions a CISO can actually fund — the analyst’s translation layer between SOC and boardroom.
MITRE ATT&CK · IOC · CTI · REPORTING
[ DECRYPT_FILE ]
LOG_002
2025-09-10
// siem_ops
SIEM OPS

Hunting in the Noise: Advanced Splunk Queries

Moving beyond signature matching. Real SPL patterns I use to hunt lateral movement, beaconing, credential abuse, and anomalies in enterprise logs — with notes on tuning out false positives without going blind.
SPLUNK · SPL · THREAT HUNTING · DETECTION
[ DECRYPT_FILE ]
LOG_001
2025-08-22
// human_int
HUMAN INT

The Unpatchable Vulnerability: The Human Element

Firewalls cannot stop a user who clicks. Inside the psychology of phishing, pretext design, and how to actually build a “Human Firewall” culture — with metrics that matter to GRC instead of vanity click rates.
PHISHING · AWARENESS · CULTURE · GRC
[ DECRYPT_FILE ]
Scroll to Top