engineering deep-dives
network visibility

TAP vs SPAN — Visibility Design Tradeoffs

When to use a physical TAP, when SPAN is good enough, and why in-line bypass design decides whether your visibility layer can ever take down the production network.

VISIBILITY REFERENCE
policy management

Firewall Rule Recertification — A Repeatable Methodology

A practical method for fighting firewall policy entropy: usage-driven review cycles, owner re-justification, and safe, reversible decommissioning backed by data instead of nerve.

ORCHESTRATION METHOD
deployment retrospective

Enterprise In-Line Tapping: Gigamon + NetScout

How a packet-visibility layer was inserted into live enterprise production paths without inheriting new outage risk — the role of bypass design, aggregation, and a tested cutover.

GIGAMON FIELD NOTE
deployment retrospective

Network Visibility at a Utility

A packet-broker fabric, Arbor edge DDoS defense, and a SIEM/SOAR pipeline — and why accurate technical inventory is the foundation that makes all of it work.

DDOS / NDR FIELD NOTE
current areas of research & interest
cloud security

Public Cloud IAM

Identity and access management as the real control plane of the cloud. How least-privilege actually breaks down at scale, role/permission boundary design, and detecting privilege drift.

IAM ONGOING
workload security

Container Security

Securing containerized workloads: image provenance and scanning, runtime isolation, the network policy model inside an orchestrator, and where the old perimeter assumptions stop holding.

CONTAINERS ONGOING
automation

DevOps for MSSP Tool Stacks

Treating security tooling as code — repeatable, version-controlled deployment of the tool stacks an MSSP runs across many customers, so onboarding a client is a pipeline run, not a bespoke build.

DEVOPS ONGOING
platforms & tooling
Check Point
firewall
Enterprise firewall policy. CCSA + CCSE certified; primary platform across professional-services deployments.
Tufin
orchestration
Security policy orchestration. TOS Aurora certified (TCSE 1–3); change automation and audit workflow.
AlgoSec
orchestration
Policy analysis and change management. CADE and Security Master certified; risk analysis and recertification.
Gigamon
packet broker
Visibility fabric. Aggregation, de-duplication, and tool-rail distribution for IDS/NDR and capture.
NetScout
analysis
Packet-level performance and security analysis, fed from the tapping layer.
Arbor
edge defense
Edge DDoS detection and mitigation. Baseline-driven, pre-authorized volumetric defense.
VMware vSphere