I’m Alexander Romanov — a cyber defence practitioner.
I came up through red-team work and now lead security operations: detection engineering, threat hunting, incident response, and the architecture that holds them together. I work the defender’s side of the board, using the attacker’s perspective to build capability that actually catches things — the point of knowing how things break is being there when they do.
This site is where I write about that work — purple teaming, detection and response, secure architecture, and the open-source tools I build — and where I think out loud about where the threat model is heading, including the new attack surface that AI agents are opening up. That’s one lane of the work, not the whole of it.
The bias here is evidence over assertions: I’d rather show you something that runs — code you can read, run, and disagree with — than a slide that says trust me.
Everything on this site is personal and independent. Views are my own, not my employer’s.
- LinkedIn — linkedin.com/in/webr0ck
- GitHub — github.com/webr0ck