research
Research
Whitepapers, repo briefs, and short actionable notes—always linked to the primary source.
Whitepapers
2 items
2026-02-02
NIST SP 800-61r2: Computer Security Incident Handling Guide
The classic incident-response playbook: definitions, lifecycle phases, and what to operationalize before you get hit.
2026-02-02
SLSA: Supply-chain Levels for Software Artifacts (What to actually implement)
SLSA is a maturity model for build provenance and tamper resistance. The real value is disciplined build pipelines and signed attestations.
Repo briefs
2 items
2026-02-02
Repo Brief: Open Policy Agent (OPA) — Policy-as-code for authorization and guardrails
OPA lets you centralize policy decisions (Rego) for authz and compliance across microservices, Kubernetes, CI, and more.
2026-02-02
Repo Brief: SigmaHQ/Sigma (Portable Detection Rules)
Sigma is a detection-rule format that lets you write once and translate to multiple SIEM backends (Splunk, Sentinel, etc.).
Suggested sections to add next
- Top Git repos with “what it’s for” + “when to use it”
- Whitepaper summaries with direct links + key claims
- Security advisories / vendor notes (curated)