About
The person behind this research, and the post to read first.
I’m Henry Parks. I set detection strategy and research priorities for a global endpoint protection platform, and I publish independent research here on my own time.
What I believe #
I judge a detection by what it catches on real telemetry. Rule counts tell me nothing.
I think pointing a frontier model at every security problem is the wrong default. Clustering, similarity search and small models trained on your own alerts are often cheaper, faster and more private.
A confidence score from a language model is generated text, not a probability. Treat it as a lead to check.
What I work on #
My day job is the path from threat intelligence to a production protection. I designed the detection engineering model we use to turn intelligence, telemetry and incident findings into governed protections, and to measure how they perform after they ship. I also set our detection-quality standards and the automated evaluation that runs before release, to cut alert noise and make rollouts safer.
A lot of detection gaps are really telemetry gaps. I work across engineering, product, data science and threat intelligence to close them.
On my own time, I’m thinking through how AI-written detections should be evaluated and governed before they ship. I’ll publish that work here. Industrial-systems security is the other area I research.
Where to start #
Read Understanding How LLMs Process Security Telemetry. It measures how a language model reads a command line, then runs the numbers on 16,248 real Sysmon events. Every measurement reruns from the companion notebook.
Background #
I’m a Principal Security Researcher at Microsoft, working on Defender. Before that, I led criminal and nation-state intrusion investigations in incident response, advised enterprises as a security consultant and worked in endpoint security engineering. I hold an MS in Computer Science from the University of Tulsa.
Contact #
Email research@henryparks.com with research questions, corrections, collaboration ideas or advisory and speaking requests.
Views here are my own and do not represent Microsoft.