Blog
Release notes, security deep dives, and engineering notes from the team building coreX Platform.
What an AI Agent Finds When You Connect It to Your Security Stack and SIEM
After 20+ years of threat hunting and writing WAF/DLP/IDS signatures, I put an MCP gateway in front of an AI agent. It found rules that don't behave the way people intended, concrete fixes for false positives, and bad traffic still getting through — in minutes, not hours.
Read post →Fingerprinting the HTTP Request — Beyond User-Agent, JA4, and QUIC
User-Agent is a marketing string. JA4 names the TLS library. H2/QUIC fingerprints describe the transport. None of them capture how a client actually builds an HTTP request. The request fingerprint does.
Read post →