<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Alankrit Chona</title><description>Writing on security, AI, and autonomous SecOps.</description><link>https://www.alankrit.io/</link><item><title>The Eager SOC</title><link>https://www.alankrit.io/blog/the-eager-soc/</link><guid isPermaLink="true">https://www.alankrit.io/blog/the-eager-soc/</guid><description>A security investigation is slow because it gathers context the way it always has: reactively, one artifact at a time, because thinking used to be the expensive step. Cheap calibrated decision models flip that. Pull the whole context bundle up front, decide once, and you can judge every event instead of the few a detector flagged.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The Sycophantic SOC</title><link>https://www.alankrit.io/blog/sycophantic-soc/</link><guid isPermaLink="true">https://www.alankrit.io/blog/sycophantic-soc/</guid><description>A story about a self-improving SOC that did everything right: three correct dismissals, a model that learned from each one, and an intrusion that walked through the boundary it drew. Analyst feedback can only describe attacks that happened. The value of a detection lives in the ones that haven&apos;t.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Everyone Is an IC Now, and Nobody Is in Flow</title><link>https://www.alankrit.io/blog/everyone-is-an-ic-now/</link><guid isPermaLink="true">https://www.alankrit.io/blog/everyone-is-an-ic-now/</guid><description>AI harnesses reward long solo sessions, so collaborative roles are turning into individual contributor roles. But the solo time they produce is supervision, not flow. Managers lost the room; engineers lost the zone; both landed in the same new mode.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Triage Doesn&apos;t Produce a Verdict. It Produces Residual Risk.</title><link>https://www.alankrit.io/blog/residual-risk-triage/</link><guid isPermaLink="true">https://www.alankrit.io/blog/residual-risk-triage/</guid><description>Anton Chuvakin is right that triage must die. But the filter is only half of it: the binary verdict is the real 2003 artifact. An investigation never proves &apos;benign&apos;; it runs out of budget. The honest output isn&apos;t true-positive or false-positive. It&apos;s the risk you couldn&apos;t rule out.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate></item><item><title>How to Train Your AI Attacker</title><link>https://www.alankrit.io/blog/how-to-train-your-ai-attacker/</link><guid isPermaLink="true">https://www.alankrit.io/blog/how-to-train-your-ai-attacker/</guid><description>Walk through the actual RL loop that makes an AI better at breaking in, cell by cell. Then run the identical loop for defense and watch it die at one cell, the reward, which is why offense keeps pulling ahead.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The Unbounded Investigation</title><link>https://www.alankrit.io/blog/the-unbounded-investigation/</link><guid isPermaLink="true">https://www.alankrit.io/blog/the-unbounded-investigation/</guid><description>One risky sign-in alert, five good analysts, five different investigations, all defensible. Why a security investigation has no natural end, why &apos;benign&apos; has no proof, and the one move that makes detection measurable.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>The Work You Can&apos;t Check</title><link>https://www.alankrit.io/blog/verifiability-across-industries/</link><guid isPermaLink="true">https://www.alankrit.io/blog/verifiability-across-industries/</guid><description>Some work you can check in seconds. Some you can never check at all. That gap, verifiability, quietly decides how work gets trusted and priced, and where AI actually creates value.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>A Patch Going Public Is an Attack Map Going Public</title><link>https://www.alankrit.io/blog/patch-is-an-attack-map/</link><guid isPermaLink="true">https://www.alankrit.io/blog/patch-is-an-attack-map/</guid><description>Patch-diffing was never new - attackers have turned fixes into N-days for decades. What changed is the labor. When an agent can read a fix and build the payload in an afternoon, the exposure window becomes a race you&apos;re now losing by default.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI SOC Rewrites the Shared Responsibility Contract</title><link>https://www.alankrit.io/blog/ai-soc-alignment-operators/</link><guid isPermaLink="true">https://www.alankrit.io/blog/ai-soc-alignment-operators/</guid><description>SOAR and AI SOC aren&apos;t two flavors of the same tool. They&apos;re two different contracts with your vendor - and the shift moves your best people from monitoring the queue to aligning the system.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The $1 Trillion Signal That Was Sitting on a Job Board</title><link>https://www.alankrit.io/blog/reading-tea-leaves-ai-frontier/</link><guid isPermaLink="true">https://www.alankrit.io/blog/reading-tea-leaves-ai-frontier/</guid><description>Frontier AI capabilities don&apos;t debut at keynotes. They&apos;re assembled in training data pipelines  - and the hiring patterns are visible months in advance.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Architecture Designed for Removal</title><link>https://www.alankrit.io/blog/architecture-designed-for-removal/</link><guid isPermaLink="true">https://www.alankrit.io/blog/architecture-designed-for-removal/</guid><description>Every system in history was designed to last. AI agent architecture is the first that should be designed to disappear. The best code you write today is code that becomes unnecessary tomorrow.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>WTF Is Security Context</title><link>https://www.alankrit.io/blog/wtf-is-security-context/</link><guid isPermaLink="true">https://www.alankrit.io/blog/wtf-is-security-context/</guid><description>The industry uses &apos;context&apos; as a synonym for &apos;more data.&apos; It&apos;s not. Here&apos;s a first-principles framework for what context actually means - from events to chains to storylines - and why most SOCs are stuck at Layer 1.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI-Powered Security Starts with Your Tribal Knowledge</title><link>https://www.alankrit.io/blog/tribal-knowledge-context-analyst/</link><guid isPermaLink="true">https://www.alankrit.io/blog/tribal-knowledge-context-analyst/</guid><description>The greatest vulnerability in the modern SOC is not a lack of data - it is a lack of memory. How tribal knowledge, context lakes, and a new role called the Context Analyst change everything.</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Why a Fixed Capacity SOC Is a Liability</title><link>https://www.alankrit.io/blog/fixed-capacity-soc-liability/</link><guid isPermaLink="true">https://www.alankrit.io/blog/fixed-capacity-soc-liability/</guid><description>We treat the SOC as a defensive funnel, but functionally it&apos;s a bottleneck. When attack volume goes exponential, a fixed capacity model forces you to ignore the vast majority of signals to save the sanity of the team.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Why Every Dismissed Alert Is Technical Debt</title><link>https://www.alankrit.io/blog/dismissed-alert-technical-debt/</link><guid isPermaLink="true">https://www.alankrit.io/blog/dismissed-alert-technical-debt/</guid><description>Maliciousness isn&apos;t an inherent property of an event - it&apos;s a property of its relationship to future context. Every dismissed alert is a liability on your balance sheet.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate></item><item><title>The Overfitting Problem in Detection Engineering</title><link>https://www.alankrit.io/blog/overfitting-detection-engineering/</link><guid isPermaLink="true">https://www.alankrit.io/blog/overfitting-detection-engineering/</guid><description>Every time you tune a detection rule to silence a noisy alert, you&apos;re hard-coding a blind spot. We&apos;re trading false positives for false negatives.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Why Long Context Windows Create an Asymmetric Advantage for Attackers</title><link>https://www.alankrit.io/blog/long-context-windows-attacker-advantage/</link><guid isPermaLink="true">https://www.alankrit.io/blog/long-context-windows-attacker-advantage/</guid><description>AI&apos;s expanding context windows sound like a defensive breakthrough. In reality, they&apos;re structurally easier for attackers to exploit - attackers save the whole board state while defenders rebuild from fragments every move.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate></item><item><title>SecOps Is Chaos Engineering</title><link>https://www.alankrit.io/blog/secops-chaos-engineering/</link><guid isPermaLink="true">https://www.alankrit.io/blog/secops-chaos-engineering/</guid><description>Security is theoretically simple. But SecOps in practice is a war against entropy - where the real task isn&apos;t correlation, it&apos;s intent recognition.</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate></item><item><title>The Scaffolding Trap in Agent Architecture</title><link>https://www.alankrit.io/blog/scaffolding-trap-agent-architecture/</link><guid isPermaLink="true">https://www.alankrit.io/blog/scaffolding-trap-agent-architecture/</guid><description>Teams build elaborate state machines to compensate for model limitations. The result benchmarks well - and doesn&apos;t think. Your architecture is a commitment, not a snapshot.</description><pubDate>Mon, 05 Jan 2026 00:00:00 GMT</pubDate></item><item><title>The Great Unbundling of RAG: Why AI Agents Are Building Their Own Context</title><link>https://www.alankrit.io/blog/great-unbundling-of-rag/</link><guid isPermaLink="true">https://www.alankrit.io/blog/great-unbundling-of-rag/</guid><description>We spent two years perfecting our RAG pipeline. Then our AI started reading markdown files from a filesystem instead of querying our vector store. This isn&apos;t a bug - it&apos;s the future.</description><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title>The Detection Bias Trap: Why AI SOC Evolution Needs Adversarial Balance</title><link>https://www.alankrit.io/blog/detection-bias-trap/</link><guid isPermaLink="true">https://www.alankrit.io/blog/detection-bias-trap/</guid><description>AI SOCs inherit and amplify human bias - favoring detections that reduce workload over ones that maximize threat coverage. Without a sparring partner, even AI-generated rules drift conservative.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate></item><item><title>The Homunculus Fallacy - and Why GPT-5 Might Be Walking Right Into It</title><link>https://www.alankrit.io/blog/homunculus-fallacy-gpt5/</link><guid isPermaLink="true">https://www.alankrit.io/blog/homunculus-fallacy-gpt5/</guid><description>You can&apos;t explain intelligence by inserting another intelligent agent. If GPT-5&apos;s router needs sophisticated judgment to route intelligence, who&apos;s routing the router?</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Risk Is Unquantifiable</title><link>https://www.alankrit.io/blog/risk-is-unquantifiable/</link><guid isPermaLink="true">https://www.alankrit.io/blog/risk-is-unquantifiable/</guid><description>Howard Marks argues you can&apos;t quantify risk even after the fact. We&apos;ve built an entire vulnerability management industry around measuring the unmeasurable.</description><pubDate>Fri, 20 Jun 2025 00:00:00 GMT</pubDate></item><item><title>The False Positive Rate: First Casualty of AI-driven SOC Operations</title><link>https://www.alankrit.io/blog/false-positive-rate-ai-soc/</link><guid isPermaLink="true">https://www.alankrit.io/blog/false-positive-rate-ai-soc/</guid><description>False Positive Rates were never about detection accuracy - they were always about human capacity. AI triage changes the equation entirely.</description><pubDate>Sun, 11 May 2025 00:00:00 GMT</pubDate></item><item><title>The Bitter Lesson in Security Operations</title><link>https://www.alankrit.io/blog/bitter-lesson-security-operations/</link><guid isPermaLink="true">https://www.alankrit.io/blog/bitter-lesson-security-operations/</guid><description>Sutton&apos;s Bitter Lesson says intelligence emerges from scalable learning, not encoded knowledge. Does that mean we&apos;ll outgrow MITRE ATT&amp;CK?</description><pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate></item><item><title>Impedance Mismatch: The Data Engineering Challenge at the Heart of Security Operations</title><link>https://www.alankrit.io/blog/impedance-mismatch-secops/</link><guid isPermaLink="true">https://www.alankrit.io/blog/impedance-mismatch-secops/</guid><description>SecOps reasoning is graph-based but our data arrives as time-series logs. This impedance mismatch - like ORMs bridging objects and tables - is the core data engineering problem in security.</description><pubDate>Thu, 06 Mar 2025 00:00:00 GMT</pubDate></item></channel></rss>