/var/www/html/intel_logs/
// CLASSIFIED_INTEL_REPOSITORY
field notes from the watch floor — soc, grc, threat intel, ai security
STATUS: ONLINE
ACCESS: PUBLIC
ENCRYPTION: AES-256
AUTHOR: NAS-982-202-ALPHA
ENTRIES: 04
LOG_004
2025-11-15
// architecture
ZERO TRUST
The Castle is Dead: Zero Trust Architecture
The era of “Castle and Moat” is over. A walkthrough of NIST 800-207, identity as the new perimeter, and why “Never Trust, Always Verify” is the only defensible posture for hybrid and remote-first enterprises — with a practical maturity ladder you can take to leadership.
LOG_003
2025-10-02
// threat_intel
THREAT INTEL
Signal vs. Noise: Actionable Intelligence
Raw data is not intelligence. How to filter IOCs, map activity to MITRE ATT&CK, and translate technical alerts into strategic decisions a CISO can actually fund — the analyst’s translation layer between SOC and boardroom.
LOG_002
2025-09-10
// siem_ops
SIEM OPS
Hunting in the Noise: Advanced Splunk Queries
Moving beyond signature matching. Real SPL patterns I use to hunt lateral movement, beaconing, credential abuse, and anomalies in enterprise logs — with notes on tuning out false positives without going blind.
LOG_001
2025-08-22
// human_int
HUMAN INT
The Unpatchable Vulnerability: The Human Element
Firewalls cannot stop a user who clicks. Inside the psychology of phishing, pretext design, and how to actually build a “Human Firewall” culture — with metrics that matter to GRC instead of vanity click rates.