Security Data Works

Start here

How this site fits together.

There's a lot of research here, and it isn't obvious on a first visit where to begin or how the pieces connect, so this page is the reading order. The short version is that the site makes one argument, backs it with evidence you can check, and then goes deep in whichever direction your question points — and claims are labeled by how strong their evidence is, because separating what's measured from what's claimed is most of the point.

If you only have ten minutes, read the thesis and skim one benchmark on the lab page. Everything else is depth on demand.

The map: claim, evidence, depth.

The core sections play one of three roles. The thesis states the claim; the matrix, the lab, and the research notebook carry the evidence for and against it; and the writing catalog plus the reference architecture are the depth, where the argument gets worked out topic by topic. Engagements sits apart, because it isn't research: it's the same method applied to your environment.

How the site's sections connectThree columns. Left: the Thesis states the claim. Middle: three evidence surfaces test it — the Matrix scores platforms, the Lab holds first-party benchmarks, and Research tracks open hypotheses and contradictions. Right: two depth surfaces — the Writing catalog's ten pillars and the MOAR reference architecture. Arrows flow from claim to evidence to depth, and a band beneath links to Engagements, where the method is applied to your environment.THE CLAIMTHE EVIDENCETHE DEPTHThesisthe argument, three propertiesMatrixthe scoring instrumentLabfirst-party benchmarksResearchopen hypotheses + contradictionsWriting80+ essays, ten pillarsMOAR Architecturethe reference designEngagements — the same method, applied to your environment
The reading order runs left to right: the thesis states the claim, three evidence surfaces test it (and keep the contradictions on the record), and the depth surfaces work it out topic by topic.

A first visit in three moves.

  1. 1

    Read the thesis, the argument that security at scale uses modern data architecture, and the three properties it holds every platform to: trustworthy, well-connected, and performant. It's a short read, and the rest of the site hangs off it.

  2. 2

    Check the evidence: first-party benchmarks with methods and raw results posted, plus a cost model you can run against your own numbers. The Matrix is the scoring instrument behind the platform evaluations, and the research notebook keeps the open questions and the contradictions on the record, because an argument you can't check is just marketing.

  3. 3

    Go deep where your question lives, in the essay catalog, which is organized as ten pillars in dependency order, from storage formats up through detection engineering and economics, and each pillar marks its own "start here" essay so you can enter mid-stack without reading everything above it.

If you came with a specific question.

Four three-essay reading paths, each built to answer one question a security data team actually asks, so you can read three pieces instead of eighty.

Leaving Splunk without breaking detections

The cost case, the migration trap most teams walk into, and what the timeline actually costs.

  1. 1The cost math: schema-on-read vs schema-on-write
  2. 2The field-mapping anti-pattern
  3. 3Hidden costs and timeline reality

Whether you can trust your data

The quietest failures in security data — the parsing layer, and the measurement problem underneath it.

  1. 1The parsing layer nobody owns
  2. 2Flattening away your detection logic
  3. 3Why vendor benchmarks are the only benchmarks

Picking the query engine

Where each engine wins, from petabyte-scale detection down to an analyst's laptop.

  1. 1ClickHouse at petabyte scale
  2. 2DuckDB for analyst-driven hunting
  3. 3Push vs pull query engines

When hunting becomes data science

The path threat hunters are already on, made reproducible.

  1. 1PEAK and the lakehouse
  2. 2MLOps tools for threat hunters
  3. 3Where detection-as-code notebooks should live

Start where your question is.