Journal
Field notes
Short pieces rooted in application security event and anomaly analytics — written for owners and analysts who live with the telemetry.
What counts as a security event in an application log
Not every error line is a security event. Here is a practical way to decide which application messages deserve retention and review.
Reading silence: when missing events are the anomaly
Spikes get attention. Flatlines that should not be flat deserve equal scrutiny in application security analytics.
False positives that burn trust in detection rules
A detection rule that fires constantly teaches analysts to ignore it. Tuning is not optional polish — it is how application security analytics stays usable.
Preparing event samples for an external analytics review
A tidy sample pack shortens an engagement and protects personal data. Here is what we ask clients to assemble before a security event analytics review.
Auth anomalies worth ranking above volume noise
Authentication events are dense. Ranking which anomalies matter keeps application security analytics focused on account takeover risk.