Blue Team of One field notes · security

Practitioner field notes

Security, taken apart from every vector

Deep teardowns and quick lessons from real detection engineering, identity hardening, and incident response work. Patterns over headlines — the wiring, not the buzzwords.

Latest

Why a stolen token dies on the wrong laptop

The real cryptography behind Entra token protection — key generation, TPM sealing, the signing model, and the handful of half-truths that make it confusing. Sign vs. encrypt, which key signs what, and why replay fails.

Read the teardown →
More on the way. This blog runs on a weekly rhythm — one deep teardown and one short lesson, drawn from live security work and written up as patterns. Detection tuning, identity edge cases, IR anatomies, and cloud hardening are all in the pipeline.