Poxek Research · English only
Research for exposure and response teams.
Source-backed analysis of exposure management, AI runtime security, vulnerability operations, and SOC workflows.
An evidence-aware handoff is the unit of work for an AI SOC
A product approach for using bounded automation to prepare reviewable L3/L4 SOC cases.
Read article →AI traffic monitoring needs execution context
Why LLM and agent observability must connect model activity to policy, tools, identities, and outcomes.
Read article →An EASM private preview should begin with evidence, not a dashboard promise
A private-preview approach for external attack-surface work that keeps discovery, review, and ownership boundaries explicit.
Read article →Decision records are the future of external vulnerability management
A future-facing view of vulnerability management that preserves evidence, uncertainty, and decisions as the external perimeter changes.
Read article →The future of SOC automation is a review system, not an autonomous authority
A future-state view of AI-assisted investigations with constrained tools, recorded evidence, and human authority.
Read article →An LLM firewall is a runtime control plane, not a prompt filter
A product view of capability boundaries, traffic monitoring, and governed agent execution.
Read article →External vulnerability findings need an asset decision
Why public-facing vulnerability evidence should be handled as an asset-specific decision, not a generic list of CVEs.
Read article →The next perimeter model needs confidence and time
A future-facing view of external discovery where evidence quality and change history are first-class data.
Read article →Runtime boundaries matter more as agents gain tools
Why tool-using AI needs capabilities, authorization, and evidence outside the model.
Read article →Context should come before SOC autonomy
Why AI-assisted SOC work should begin with evidence reconstruction and accountable analyst decisions.
Read article →Vulnerability prioritization needs more than a score
A private-preview product note on turning externally observed vulnerability evidence into reviewable remediation decisions.
Read article →Continuous visibility starts with an asset model
Why an external inventory needs evidence, relationships, and time—not a periodically exported host list.
Read article →