Threat Modeling That Produces Testable Controls
A practical method for turning system boundaries and abuse paths into owned controls, observable evidence, and repeatable tests.
Published
Bryan Oubaita created Baitaphish and publishes practical cybersecurity education and source-linked research.
His work focuses on cloud and AWS security, identity, phishing defense, AI security, and agent governance. Baitaphish separates original analysis from source records and makes provenance, review dates, automation, and limitations visible.
A practical method for turning system boundaries and abuse paths into owned controls, observable evidence, and repeatable tests.
Published
Provenance turns a security claim into a traceable record of source, transformation, review, and intended use—without pretending lineage alone guarantees truth.
Published
NIST's current incident-response guidance integrates preparation, response, recovery, and continuous improvement across the six CSF 2.0 Functions.
Published
OPA lets you centralize policy decisions (Rego) for authz and compliance across microservices, Kubernetes, CI, and more.
Published
Sigma is a detection-rule format that lets you write once and translate to multiple SIEM backends (Splunk, Sentinel, etc.).
Published
SLSA is a maturity model for build provenance and tamper resistance. The real value is disciplined build pipelines and signed attestations.
Published
Baitaphish writing names its sources, records review dates, labels AI assistance, and states what the available evidence cannot establish. Corrections should preserve the history of a claim rather than silently replacing it.