Skip to main content
Trym HåkanssonSwitch to Labs

TECHNICAL NOTES · PERSONALLY PUBLISHED

Security operations, identity and AI systems.

The archive contains source-linked threat research, KQL, implementation guides and technical notes. I maintain and publish it personally.

All writing

11 published notes

  1. 6 min read

    AI Security Readiness: Turn Survey Concern Into an Operating Plan

    Darktrace reports a gap between perceived AI threat impact and preparedness among surveyed security professionals. Close it with inventory, telemetry, playbooks, exercises and named ownership.

    • ai-security
    • security-strategy
    • threat-landscape
    • ciso
    • defender-readiness
  2. 6 min read

    Moltbook Exposure: What Wiz Actually Found

    Wiz found unauthenticated read and write access to Moltbook's production database. The confirmed scope was 1.5 million authentication tokens, 35,000 email addresses and 4,060 private DM conversations.

    • ai-security
    • moltbook
    • data-breach
    • prompt-injection
    • agentic-ai
  3. 7 min read

    AI Agent Identity: Inventory, Scope and Revoke

    AI agents use machine credentials to act across APIs and tools. The security work is concrete: identify each agent, bind it to an owner, limit its authority, log its actions and remove access when the use case ends.

    • ai-security
    • agentic-ai
    • identity-management
    • shadow-ai
    • iam
  4. 7 min read

    Secure AI Adoption: Start With the Data Path

    Microsoft's 2026 Data Security Index shows a control gap among surveyed organizations. This is a practical Microsoft security sequence for finding AI use, reducing data exposure and handling incidents.

    • ai-security
    • data-protection
    • microsoft-purview
    • defender-xdr
    • advanced-hunting
    • dlp
  5. 10 min read

    Hunting TA584 and Tsundere Bot in Defender XDR

    A source-based Defender XDR hunting note for Proofpoint's TA584 ClickFix chain and the Tsundere Bot payload.

    • threat-hunting
    • defender-xdr
    • advanced-hunting
    • initial-access-broker
    • malware