I turn adversary tradecraft into detections, and measure what they catch.
Independent research on AI, detection engineering and industrial security.
Today I build and evaluate endpoint protections derived from threat intelligence. Earlier in my career, I led criminal and nation-state intrusion investigations and designed endpoint security architectures.
Research
AI detection engineeringOctober 2026 · 22 min read
What a language model actually does with a command line, measured on Phi-4-mini and on two days of real Sysmon events, and what to do before you paste telemetry into one.
A tokenizer is not a parser.powershell.exe becomes powers + hell + .exe, and IEX becomes I + EX.
A “95 percent malicious” verdict is generated text. The model writes the number the way it writes every other word, and it is not a calibrated probability until you test it against labeled outcomes.
One developer workstation’s process starts fill the largest frontier context window in about eight hours, even trimmed to the fields an analyst reads.
Research areas
AI security researchforthcomingOffensive research on AI systems in security operations. Agents, MCP servers, retrieval, and the model supply chain.
AI detection engineering1 postPutting models and agents into the detection pipeline, and measuring what they actually produce.
Detection engineeringforthcomingEvaluation, coverage, governance and delivery of detection content at scale.
Threat researchforthcomingAdversary tradecraft, measured, and the detections that follow from it.