Tag — security-notes
SIEM Alert Fatigue: Why Tuning Matters More Than Rules
Most SOCs do not have a detection problem — they have a signal-to-noise problem. Why the tuning loop, not the rule count, decides what gets caught.
Read →Verified Boot and Secure Elements: What GrapheneOS Gets Right
A relocked bootloader, a hardware root of trust, and a boot chain you can independently verify — how verified boot actually works and why the discrete secure element matters.
Read →WireGuard vs OpenVPN: A Practical Comparison
Auditability, failure behaviour, and cryptokey routing: the comparison that matters in practice, grounded in running full-tunnel WireGuard on real infrastructure.
Read →Sec+ SY0-701: Domain 2 — Threats, Vulnerabilities and Mitigations
Study notes for Security+ Domain 2 (22% of the exam): threat actors, attack surfaces, vulnerability types, malicious activity, and mitigations.
Read →