Software Supply Chain
Minimal images, provenance, SBOMs, signing, rebuilds, and transparent exceptions.
See the programThe lab studies software supply chains, defensive deception, intelligence fusion, infrastructure automation, and the operational systems around them.
Selected work will be published through Lab Notes and the public wiki. Sensitive implementation detail remains controlled.
Minimal images, provenance, SBOMs, signing, rebuilds, and transparent exceptions.
See the programModular honeypots, sensor telemetry, adversary behavior, and detection engineering.
See WatchtowerCollection, provenance, entity resolution, correlation, and analyst-centered systems.
See FoxSightPolicy-driven workflows, approvals, connectors, audit evidence, and safe execution.
See AlfredIdentity, platform boundaries, deployment patterns, observability, and resilience.
Read Lab NotesCyber, military, economic, physical, and open-source information in usable context.
Work with the lab