Publications

Featured Image
2025 • OpenAI

OpenAI Internal Model Red Teaming

Red Team Network contributions to Operator, GPT-4o, o3-mini, and Deep Research system cards.

Security research
Featured Image
2024 • eBPF Foundation

eBPF Foundation Security Threat Model

A comprehensive threat model for eBPF-based security solutions.

Threat model
Featured Image
2024 • NIST (National Institute of Standards and Technology)

NIST SP 800-233 Service Mesh Proxy Models

Security guide to service mesh proxy models for cloud-native applications.

Security standard
Featured Image
2024 • Flux CD

Flux D1 Reference GitOps Architecture

A hardened reference architecture for GitOps with Flux CD.

Reference architecture
Featured Image
2024 • FINOS (Fintech Open Source Foundation)

FINOS AI Security Reference Architecture

AI security reference architecture for financial services.

Reference architecture
Featured Image
2024 • FINOS (Fintech Open Source Foundation)

FINOS AI Governance Framework

AI governance framework for financial services.

Governance framework
Featured Image
2023 • TAG Security (Technical Advisory Group on Security, CNCF)

CNCF Flatcar Threat Model

A project graduation threat model with the TAG Security community.

Threat model
Featured Image
2023 • TAG Security (Technical Advisory Group on Security, CNCF)

CNCF FluxCD Threat Model

Security assessment and threat model for Flux CD as part of CNCF graduation.

Threat model
Featured Image
2023 • CNCF (Cloud Native Computing Foundation)

CNCF ArgoCD End User Hardening Guide

A guide to hardening ArgoCD for end users.

Hardening guide
Featured Image
2023 • Community

Kubernetes for Security Operations Centres

Community collaboration with JP Morgan CyberOps.

Hardening guide
Featured Image
2022 • CNCF (Cloud Native Computing Foundation)

CNCF Envoy Gateway Threat Model

A comprehensive threat model for the Envoy Gateway.

Threat model
Featured Image
2021 • O'Reilly Media

Hacking Kubernetes

The definitive guide to Kubernetes offensive and defensive security.

Book
Featured Image
2020 • FS-ISAC (Financial Services Information Sharing and Analysis Center)

Financial Services User Group Kubernetes Threat Model

Financial services-specific threat model for Kubernetes.

Threat model
Featured Image
2019 • WeaveWorks

Hardening Git for GitOps

How to secure Git workflows for GitOps.

Security guide
Featured Image
2018 • Google Cloud Platform

CIS Benchmarks for Google Kubernetes Engine

Center for Internet Security hardening guide for GKE.

Security standard