
Where ML Actually Helps in Security, and Where It Just Adds Queue
Unsupervised baselining earns its keep on network telemetry. Classification on alert triage mostly does not. A candid look at which security problems are genuinely learnable.
Halonex // Execution control
Trust policy · default deny
Refused
0050
Verified
0011
Notes from the research team on what we are seeing, what we got wrong, and what we would do differently. Written for people who have to act on it, not forward it.

Harvest-now-decrypt-later means data you transmit today is already at risk. A practical migration order for key exchange, signatures, and long-lived stored secrets — and what can safely wait.
8 articles found

Unsupervised baselining earns its keep on network telemetry. Classification on alert triage mostly does not. A candid look at which security problems are genuinely learnable.

Signature and behavioural detection both require a prior. Isolation does not. Why the boundary, not the classifier, is what actually holds against a genuine zero-day.

Logical qubit counts, error correction overhead, and what they imply for RSA-2048. A sober estimate of when this becomes an operational problem rather than a research one.

Exfiltration first, encryption second, and the ransom priced against your disclosure obligations. Tracing how the business model changed, and why backups alone no longer answer it.

Every dependency is code you did not write, running with your credentials. What to actually verify between commit and release, and which controls are theatre.

Architectures, feature representations, and the distribution shift that quietly ruins evaluation. Including the approaches we tried that did not work, and why.

Authentication, rate limits, webhook verification, and containment triggers — with working examples in Python, JavaScript, and Go you can paste and run.

Most automation projects speed up the wrong loop and make triage worse. How to pick the steps worth automating, and how to tell when you have made things quieter.
Featured Author
AI Security Specialist
Sarah Kim works on malware classification — which parts of the problem are genuinely learnable, and which ones the industry keeps trying to solve with a model when a rule would do. She writes up the approaches that did not work alongside the ones that did.
2
Articles Published