Yesterday I wrote about moving autonomous-agent secrets out of a flat .env file. Why I kept Vaultwarden for people and recovery, added HashiCorp Vault for workloads, and treated identity, audit, PKI, and tested recovery as part of the deployment rather than follow-up work.
For a long time, my autonomous agent found credentials the same way many applications do. Why I replaced a flat environment file with scoped Vaultwarden access, short-lived agent sessions, and a verified audit trail that now reaches Graylog and Wazuh.
I spend my working hours telling teams how to do security well. Segment the network. Write the change down. Model the threat before you build the control. Then I go home, and if I am honest with myself, the temptation is to cut every one of those corners because it is "just the lab."
I have taught this material before as two sessions, and I usually open each session the same way: this is not a tool class. Tools get named below, plenty of them, but every one is an implementation of the same pipeline, and the pipeline is what transfers to whatever product your employer bought...
Welcome back to the Basics Series. In Basics Series - #3 we compared the firewall market, picked OPNsense for the lab, and installed it as a VM. In Basics Series - #4 we worked through the traditional vs. transparent-bridged decision and I promised a configuration walkthrough. This is that post...
We've climbed through the rings of the architecture... This installment goes further upstream than any of them. It steps back to the code itself — and asks how you find the flaw while it's still cheap to fix and it hasn't shipped yet. That's the domain at the heart of Application Security Testing.
This installment does something different. Every domain we've covered so far — even the unglamorous hygiene loop — was, at bottom, an attempt to keep the bad day from arriving. This one starts the morning after it did...
I've been working through the second edition of the Cybersecurity Architect's Handbook's "secret menu" one domain at a time...the controls that still mean something after everything else has fallen. This installment does something different...it looks down at the ground all of them are standing on.
Every query a device makes is a statement of intent — what it wanted to reach, when, and how often — and once you're logging them, you're no longer just blocking bad names. You're watching behavior....
Before we get into the core of the article — a quick, time-bound note. Packt is sponsoring a giveaway on my LinkedIn channel...This post moves to the first place that thinking touches wire: Category 2, Network Security Controls...
"Instead of just rehashing abstract theory, it bridges the gap between high-level security principles and real-world execution. It's practical, actionable, and a great tool for anyone designing or engineering modern infrastructure."
In the last post I gave you the tour — the foundational labs, the eight operational categories...So let's start where the whole discipline starts: Category 1, Threat Modeling and Risk Assessment.