Poxek Research · English only

Research for exposure and response teams.

Source-backed analysis of exposure management, AI runtime security, vulnerability operations, and SOC workflows.

An evidence-aware handoff is the unit of work for an AI SOC

A product approach for using bounded automation to prepare reviewable L3/L4 SOC cases.

Read article →

AI traffic monitoring needs execution context

Why LLM and agent observability must connect model activity to policy, tools, identities, and outcomes.

Read article →

An EASM private preview should begin with evidence, not a dashboard promise

A private-preview approach for external attack-surface work that keeps discovery, review, and ownership boundaries explicit.

Read article →

Decision records are the future of external vulnerability management

A future-facing view of vulnerability management that preserves evidence, uncertainty, and decisions as the external perimeter changes.

Read article →

The future of SOC automation is a review system, not an autonomous authority

A future-state view of AI-assisted investigations with constrained tools, recorded evidence, and human authority.

Read article →

An LLM firewall is a runtime control plane, not a prompt filter

A product view of capability boundaries, traffic monitoring, and governed agent execution.

Read article →

External vulnerability findings need an asset decision

Why public-facing vulnerability evidence should be handled as an asset-specific decision, not a generic list of CVEs.

Read article →

The next perimeter model needs confidence and time

A future-facing view of external discovery where evidence quality and change history are first-class data.

Read article →

Runtime boundaries matter more as agents gain tools

Why tool-using AI needs capabilities, authorization, and evidence outside the model.

Read article →

Context should come before SOC autonomy

Why AI-assisted SOC work should begin with evidence reconstruction and accountable analyst decisions.

Read article →

Vulnerability prioritization needs more than a score

A private-preview product note on turning externally observed vulnerability evidence into reviewable remediation decisions.

Read article →

Continuous visibility starts with an asset model

Why an external inventory needs evidence, relationships, and time—not a periodically exported host list.

Read article →