Thirty-eight posts across seven topic areas
The SOC tooling layer and the agents that run on it: sandboxing, credential exposure, security-automation architecture, and where vendor pricing distorts design.
- 2026-05-29The decision is always upstream
- 2026-05-29A microVM is not a sandbox
- 2026-05-28The password is in another process's memory
- 2026-05-26Monitoring is not understanding
- 2026-05-23Agent memory is an attack surface
- 2026-05-21The syslog you can't get back
- 2026-04-02Adaptive WAF rate caps
- 2026-02-05LLM-as-a-judge for alert triage
- 2025-04-22The SOAR anti-pattern tax
Foundation models, LLM post-training, retrieval, and the sovereign agent built on top of them.
- 2026-05-24What Zoya is, and why it's built from scratch
- 2026-05-23Web-reading tools for a sovereign agent
- 2026-02-23ThreatFM: a unified telemetry embedding
- 2026-02-13Scaling LLM post-training
- 2026-01-28Cross-source incident search
Caching, metadata validation, semantic layers, and event spines, the plumbing underneath everything else.
- 2026-04-06Interval-aware caching for Druid
- 2026-02-06The data canary
- 2026-01-15DataJunction
- 2026-01-08One audit-event spine
Small VMs, instruction sets, GPU shaders, and close-to-metal work you can read every line of in an afternoon.
- 2026-05-29Small enough to hold in your head
- 2026-05-21Conway on the GPU
- 2026-05-21Conway in ambient mode
- 2026-05-21Labs background settings
- 2026-04-27What balanced ternary buys, in one instruction
- 2026-04-19An LC-3 toolchain in Zig 0.16
- 2026-01-22JDK Vector API for recommendations
How the work itself gets done: intent over specs, briefs that outlive tasks, and habits that compound.
- 2026-05-29The Buddy System
- 2026-05-28Intent-driven development
- 2026-05-25The furnace and the thermostat
- 2026-04-19Specs with subscribers
Ads, rent, funding, and fees: who pays for software and for expertise, and what a rent-free alternative actually takes.
- 2026-05-30The sale is the sample
- 2026-05-29Who pays for the patient's app
- 2026-05-29How to fund the rent-free alternative
- 2026-02-17Follow the rent: from ads to a co-op
Notes about the blog itself and the tools underneath it, the layout, the server, the choices behind how this site is built.
- 2026-04-21The log beats the article
- 2026-04-20Why scroll.pub is on my mind
- 2026-04-18Two servers, same shape: servo in Bun
- 2026-04-17What is servo, and what's a servo app
- 2026-04-16H2 Labs: an iteration log