$ ls /blog
Blog
Technical deep dives, practical lessons, personal experiences, and the occasional random thing worth sharing, all shaped by real-world experience and curiosity.
/ posts
7 posts
Reducing AI Token Usage with Caching
Explore how prompt caching, application caching, retrieval, context management, and better prompt design can reduce token usage when building applications with OpenAI, Claude, Gemini, and Grok.
The Reconnaissance Agent [Lab Part 4]
Follow the Helixora reconnaissance agent as it discovers staging, exposed configuration, employee information, API documentation, anonymous shares, credentials, and recovery metadata.
Designing Safe Tools for Security Agents [Lab Part 3]
How the Helixora learner lab constrains AI security agents with an explicit hostname allowlist, bounded enumeration, role-specific tools, local services, human approval, and auditable evidence.
Inside the Lab [Lab Part 2]
A guided tour of the fictional applications, identities, APIs, evidence, and defensive telemetry inside the self-contained AI agent reconnaissance lab.
Conditional Access for AI Agents
Exploring how Microsoft Entra Conditional Access extends Zero Trust controls to AI agents, agent identities, autonomous access, and agent user accounts.
AI Agents for Security Reconnaissance [Lab Part 1]
Exploring how AI agents can transform the reconnaissance phase of security assessments by orchestrating discovery and reasoning about the environment.
Metasploit Framework 6.5: What's New and Why It Matters
Metasploit Framework 6.5 brings a collection of improvements across the framework, including authentication, Active Directory, credentials, payloads, modules, and post-exploitation capabilities.