whoami

My name is Tayvion. For the last ten years I've been sharing what I figure out as I go, starting back when I was trying to land an internship and running through the first full time job and everything after it. Eight of those years have been detection engineering and cloud security, and lately most of my time goes to applied AI in security, some of it at work and a lot of it on my own.

what this isn't

I know how much of what gets posted about this field is really marketing. There's a whole lane of people handing out information they know is incomplete, because the incomplete version sells a course about landing a six figure job in six months. This isn't that. I'm not selling you anything.

what's here

Most of what I write starts as a question I couldn't get a straight answer to. Lately those questions are about AI in security work, since we're handing agents real permissions and real tooling and pointing them at data other people can influence. When I can't find an answer I go build the thing, run it, and write down what actually happened.

Three kinds of things end up here. Research is work I actually ran, with the question, the method, and the limits attached. Labs is what I build, so home labs, Terraform, tooling, and cert work. Career is the other half of this job, meaning what it actually takes and what I got wrong on the way up.

ground rules

Security writing runs observation and speculation together constantly, and that's where most of the bad advice comes from. So I mark mine. If I tested something, I say I tested it. If I'm guessing, I say I'm guessing. When a finding only holds under certain conditions, those conditions go right next to it.

I test in accounts I own and can burn down. Nothing here will include credentials, customer data, private telemetry, or working code against something you depend on. When I write up an attack, I write up how you catch it. The code, infrastructure, payloads, and detection logic go on GitHub at github.com/tayontech, and posts link the version they were built against.

reach me

If I get something wrong, tell me. I'd rather hear it from you than leave it sitting there. You can reach me at info@tayontech.io.

The rest of what I do is at tayontech.io.

User's avatar

Subscribe to TayOnTech

Independent research on AI agents, cloud security, and detection engineering.

People