false-positive

8 posts

The watchman doesn't know who you are — when integrity monitoring points at the administrator
Segurança
Sep 07, 2026

The watchman doesn't know who you are — when integrity monitoring points at the administrator

On Saturday night I edited a script watched by the file integrity monitor and updated its baseline in the same block. Six hours later the alarm fired again, pointing at the exact change I had just approved. The monitor didn't fail: it did the only job it can do. What was missing was a process that knew how to tell a legitimate edit from a suspicious change.

Continue reading →
The exception that got written twice — silencing an alarm is not defining policy
Segurança
Sep 05, 2026

The exception that got written twice — silencing an alarm is not defining policy

On August 11 I put a secret scanner on this blog's pipeline. The next day it flagged a build cache file as if it were a key. I silenced it with an entry pinned to that finding's exact fingerprint. Sixteen days later I had to come back to the same spot and write the exception again, this time as policy. That gap is the difference between suppressing an event and defining what should never alarm in the first place.

Continue reading →
Two hunters, one alarm — how the Security Agent learned to silence the false positive
Segurança
Aug 18, 2026

Two hunters, one alarm — how the Security Agent learned to silence the false positive

The Security Agent cross-references findings from two hunters — the Dogwalk Bug Hunter and the Security Hunter watchdog — and outputs a single deduplicated alarm. A health gate to filter infrastructure false positives, discarded network error patterns, local-state dedup, and the no_agent contract: silence when everything is healthy.

Continue reading →