New The 2026 Continuous Validation Methodology Paper is now available. Read the paper →

VORNAC RESEARCH

8

Defensive Operations & Governance.

Blue-team operations, the security-product landscape, and compliance posture.

6
Notes in this domain
0
Featured
4
Reference
2
Background

Reference

Reference

SIEM Architecture — Reference

Reference architecture for a working SIEM: ingestion, normalization, detection layer, response loop — with the cost and quality trade-offs at each junction.

ReportingRecon
Reference

SSL/TLS Threat Model

TLS attack surface organized by ceremony stage: handshake, certificate path, cipher choice, record layer — with the deprecation and mitigation timeline.

Reference

Host & Network Hardening

Linux operator hardening, TCP/IP operational notes for detection engineers, AD defense from the defender's perspective, and data-center host hardening where physical access intersects vendor patches.

Reporting

Background

From reference to evidence

Validate these gaps in your own environment.