- Home
- Resources
- Blog
Notes from the line.
Short, practical writing on application security, one station at a time.
All posts
Most threat intel is not for you. The useful part is a fast answer to one question: is this advisory in what we actually run?
PipelineDeep diveWhat is actually running?Trace a container in production back to its commit, build and pull request using image digests, OCI labels and attestations.
PipelineChecklistWho can unlock prod? A deploy approvals checklistRequired reviewers on a production environment only work if the person who wrote the change cannot also approve it. Run this checklist to find out.
TestingChecklistAre you ready for a bug bounty?A checklist to run in one meeting before you invite outside researchers: disclosure basics, scope, triage SLAs, reward structure and the loop that turns reports into fixes.
AI & toolingChecklistHardening a developer laptop in a dayFive controls, one working day: encrypted disk, secrets out of dotfiles, protected SSH keys, signed commits and tokens that can only do their job.
TestingGuideAuthorisation tests your QA team can ownBroken access control is the bug QA is best placed to catch. A role by endpoint matrix and a few lines of pytest make it routine.
DetectionGuideFrom pentest findings to SOC detectionsEvery pentest finding tells you how someone attacked you. Use it twice: fix the bug, then write the detection that would have caught the attempt.
Supply chainGuideOne gate for every installRoute every package through one proxy, make new versions wait a few days, switch off install scripts and let the lockfile decide.
ProgramOpinionPolicies engineers actually readShort policies mapped to real controls, with evidence pulled from your pipelines, beat long documents nobody opens until the audit.
TestingGuideWhich diffs deserve a human security reviewYou cannot security-review every pull request. Route the few that matter to people who know what to look for, using paths and CODEOWNERS.
AI & toolingDeep diveThe IDE extension problemEditor extensions run as your code, with your files and your tokens. How they work, how to inventory them, and how to build an allowlist people will accept.
Supply chainGuideSBOM, provenance and signatures in plain wordsThree artefacts, three questions: what is inside, who built it and has it changed. Here is how to produce and check each one.
ProgramGuideFrom a team of one to a working program: a 90-day planA station-by-station plan for the lone security engineer, plus four measures that tell you whether the program is actually working.
DesignOpinionKeep your threat model in layersA single threat model document is out of date the week after the workshop. Split it into layers and update each one when that layer changes.
AI & toolingDeep diveWhat an MCP server can reachAn MCP server runs with your tokens, your filesystem and your network. Here is what that means, and how to inventory and scope it.
PipelineGuidePin your actions: a one-afternoon fixTags move, SHAs do not. Pin every action, let a bot keep them current and cut the token down to what each job needs.
TestingGuideReading a pentest report like an engineerA pentest report is a list of bugs with evidence. Triage it, reproduce it, fix the root cause, and make sure each finding can never quietly return.
DesignDeep diveTrust boundaries you can draw on one pageIf your architecture diagram cannot show where trust changes, it cannot tell you where the attacks go. Here is how to draw one that does.
PipelineOpinionScans that developers do not muteRunning every scanner on every commit is easy. Getting developers to read the output is the real work, and it starts with showing less.
Supply chainDeep diveAnatomy of a malicious packageFour ways a bad package reaches your build, what each one looks like in a manifest or a log, and how to check yourself.
ProgramOpinionYour first security hireWhen to hire, which profile to look for first, what the first 90 days should produce, and when a fractional lead is the smarter opening move.
DesignGuideAbuse cases belong next to user storiesWrite the misuse story in the same ticket as the feature, and security requirements stop being a document nobody opens.
DesignGuideThreat modeling, togetherWhy the best threat models happen with business, developers and cyber in one room, and how to run one in an hour.
Nothing in this category yet.