# research

The themes I keep coming back to.

These are the recurring topics across my writeups, internal engagements, and personal lab work. Each one is an area where I think the gap between best practice and reality is wide enough to justify writing about it.

research/ — ls -la
drwxr-xr-x  active-directory/
drwxr-xr-x  attack-surface-reduction/
drwxr-xr-x  printer-security/
drwxr-xr-x  tls-hardening/
drwxr-xr-x  bitlocker-security/
drwxr-xr-x  ot-security/
drwxr-xr-x  vulnerability-management/
# areas

Research areas

Active Directory Security

Tiering, delegation models, Kerberos hygiene, and detecting common AD misconfigurations before they become incidents.

/research/active-directory-security

Attack Surface Reduction

Killing legacy protocols, restricting management planes, and shrinking what is reachable to what is necessary.

/research/attack-surface-reduction

Printer Security

Hardening multi-function devices and print servers in segmented enterprise and OT environments.

/research/printer-security

TLS Hardening

Cipher suite curation, certificate lifecycle, and getting recovery and admin portals to a defensible posture.

/research/tls-hardening

BitLocker Security

Key protector strategy, recovery workflows, MBAM/BitLocker policy gaps, and tamper-resistant deployments.

/research/bitlocker-security

OT Security

Working with IT/OT seams, Purdue model boundaries, and pragmatic controls in low-tolerance environments.

/research/ot-security

Vulnerability Management

From scanner output to a triage model that engineers and ops actually act on — without the noise.

/research/vulnerability-management