Now.
A snapshot of where my attention is. Inspired by the /now movement.
Day-to-day at IT Audit Labs: SOAR playbook design, alert triage, and detection engineering across a multi-tenant SOC.
Continuing client work on Cloudflare Workers + Durable Objects. Pulling lessons from production back into reusable patterns.
Going deeper into Cortex XSIAM, detection-as-code patterns, and pairing SIEM signal with SOAR response. Recent reading on browser-extension threat surface (see writing).
Publishing on the IT Audit Labs blog when I hit something the community would benefit from. Latest: browser extensions as a quiet SSO bypass vector.
If you're reading this months from now, the page is probably stale. Ping me for a current snapshot.