Journal · 4 notes
Working notes, including the ones that make us look bad.
Detection design, measured overhead, latency budgets and the occasional public retraction. Written by the people who built the thing, published when it is finished rather than when marketing needs a post.
- detection
- engineering
- kubernetes
- latency
- opinion
- performance
- product
Latest
We deleted 1,900 detections and caught more
Detection coverage is a vanity metric. Here is what happened when we replaced a rule library with forty correlation patterns, and what it cost us.
2026
A risk score is an argument you are not allowed to hear
Why Aegis shows you a rule, its evidence and its query instead of a number between 0 and 100 — and the two places where we admit a score would be more convenient.
- opinion
- product
- 4 min
eBPF is not free: what our sensor actually costs you
Measured CPU, memory and latency overhead of the Aegis runtime sensor across four workload shapes — including the two where we tell customers not to deploy it.
- engineering
- kubernetes
- performance
- 4 min
The 38-second budget
Where every second between an event happening and a phone ringing actually goes — and the one delay we cannot fix because it belongs to your cloud provider.
- engineering
- latency
- 4 min
No newsletter funnel
The feed is the whole subscription.
No email capture, no gated PDFs, no "download the whitepaper". If you want to be told when we publish, the RSS feed is the product.