Built in public
Writeups
Architecture decisions, adversarial experiments, and operational lessons—including the approaches that failed before the shipped design worked.
Adding a detection layer that prompt injection can’t touch
Behavioral baselining on the bare Suricata alert stream, what calibrating it on 1.5 million real alerts taught us, and where the signal remains limited.
I found a prompt injection in my own IDS triage tool
The real URL injection vulnerability, why the obvious fix did not hold, and the field-isolation design that replaced it.
How I cut 13,000 Suricata alerts an hour down to 200 worth reading
The original two-tier architecture, production numbers, and what happened when it was tested on a 2018 laptop.