Starting a dev blog
June 2, 2026
I detect threats, and I build the infrastructure that stops the next ones. This blog is where the two meet.
It starts with one number. The real false-positive rate a SIEM feeds the ticketing system, the kind most teams run for years without ever measuring. I measured it. The number was high enough to settle where the problem was: everything upstream.
That’s the thread I’m pulling on here. On my own time I’ve been rebuilding SOC triage from first principles: deterministic parsing, live enrichment, and agentic interpretation, evaluated instead of guessed at. I’m writing it up as a series, from the first parsing tool to the agent-governance layer at the end. That layer is now its own project: Periheliax, a control plane for AI in the SOC.
That one number is the blog’s center of gravity. Fewer hot takes, more here is what I tried, what it cost, and what I would do again. The series is where it begins.