Halonex // Execution control

Trust policy · default deny

Refused

0050

Verified

0011

Halonex PQC Migration Report — what a routine database migration exposes in transit, and what post-quantum cryptography changes.Get the report

Security Insights

Notes from the research team on what we are seeing, what we got wrong, and what we would do differently. Written for people who have to act on it, not forward it.

Post-Quantum Cryptography: What to Migrate, and in What Order
Featuredresearch

Post-Quantum Cryptography: What to Migrate, and in What Order

Harvest-now-decrypt-later means data you transmit today is already at risk. A practical migration order for key exchange, signatures, and long-lived stored secrets — and what can safely wait.

Dominic Watson2025-04-268 min read
Quantum ComputingCryptographyFuture Security

8 articles found

Where ML Actually Helps in Security, and Where It Just Adds Queue
ai6 min read2025-04-24

Where ML Actually Helps in Security, and Where It Just Adds Queue

Unsupervised baselining earns its keep on network telemetry. Classification on alert triage mostly does not. A candid look at which security problems are genuinely learnable.

Sarah Kim·AI Security Specialist
You Cannot Detect What You Have Never Seen. So Stop Trying.
cybersecurity7 min read2025-04-22

You Cannot Detect What You Have Never Seen. So Stop Trying.

Signature and behavioural detection both require a prior. Isolation does not. Why the boundary, not the classifier, is what actually holds against a genuine zero-day.

Marcus James·Threat Intelligence Lead
Reading the Quantum Timeline Without the Hype
research10 min read2025-04-20

Reading the Quantum Timeline Without the Hype

Logical qubit counts, error correction overhead, and what they imply for RSA-2048. A sober estimate of when this becomes an operational problem rather than a research one.

Alex Chen·Chief Security Researcher
Ransomware Stopped Being About Encryption Years Ago
cybersecurity8 min read2025-04-18

Ransomware Stopped Being About Encryption Years Ago

Exfiltration first, encryption second, and the ransom priced against your disclosure obligations. Tracing how the business model changed, and why backups alone no longer answer it.

Dominic Watson·Director of Product Security
Your Build Pipeline Is the Least Monitored Thing You Own
industry9 min read2025-04-15

Your Build Pipeline Is the Least Monitored Thing You Own

Every dependency is code you did not write, running with your credentials. What to actually verify between commit and release, and which controls are theatre.

Marcus James·Threat Intelligence Lead
What We Learned Training Malware Classifiers on Real Telemetry
ai12 min read2025-04-12

What We Learned Training Malware Classifiers on Real Telemetry

Architectures, feature representations, and the distribution shift that quietly ruins evaluation. Including the approaches we tried that did not work, and why.

Sarah Kim·AI Security Specialist
Wiring the Halonex API Into an Existing Pipeline
tutorials15 min read2025-04-10

Wiring the Halonex API Into an Existing Pipeline

Authentication, rate limits, webhook verification, and containment triggers — with working examples in Python, JavaScript, and Go you can paste and run.

Alex Chen·Chief Security Researcher
Automating SecOps Without Automating the Noise
tutorials11 min read2025-04-08

Automating SecOps Without Automating the Noise

Most automation projects speed up the wrong loop and make triage worse. How to pick the steps worth automating, and how to tell when you have made things quieter.

Dominic Watson·Director of Product Security

Featured Author

Sarah Kim

AI Security Specialist

Sarah Kim works on malware classification — which parts of the problem are genuinely learnable, and which ones the industry keeps trying to solve with a model when a rule would do. She writes up the approaches that did not work alongside the ones that did.

2

Articles Published