Principal Security Researcher

I turn adversary tradecraft into detections, and measure what they catch.

Independent research on AI, detection engineering and industrial security.

Today I build and evaluate endpoint protections derived from threat intelligence. Earlier in my career, I led criminal and nation-state intrusion investigations and designed endpoint security architectures.

AI detection engineeringOctober 2026 22 min read

Understanding How LLMs Process Security Telemetry

What a language model actually does with a command line, measured on Phi-4-mini and on two days of real Sysmon events, and what to do before you paste telemetry into one.

  1. A tokenizer is not a parser. powershell.exe becomes powers + hell + .exe, and IEX becomes I + EX.
  2. A “95 percent malicious” verdict is generated text. The model writes the number the way it writes every other word, and it is not a calibrated probability until you test it against labeled outcomes.
  3. One developer workstation’s process starts fill the largest frontier context window in about eight hours, even trimmed to the fields an analyst reads.

Research areas

  • AI security research forthcoming Offensive research on AI systems in security operations. Agents, MCP servers, retrieval, and the model supply chain.
  • AI detection engineering 1 post Putting models and agents into the detection pipeline, and measuring what they actually produce.
  • Detection engineering forthcoming Evaluation, coverage, governance and delivery of detection content at scale.
  • Threat research forthcoming Adversary tradecraft, measured, and the detections that follow from it.