About

The person behind this research, and the post to read first.

I’m Henry Parks. I set detection strategy and research priorities for a global endpoint protection platform, and I publish independent research here on my own time.

What I believe #

I judge a detection by what it catches on real telemetry. Rule counts tell me nothing.

I think pointing a frontier model at every security problem is the wrong default. Clustering, similarity search and small models trained on your own alerts are often cheaper, faster and more private.

A confidence score from a language model is generated text, not a probability. Treat it as a lead to check.

What I work on #

My day job is the path from threat intelligence to a production protection. I designed the detection engineering model we use to turn intelligence, telemetry and incident findings into governed protections, and to measure how they perform after they ship. I also set our detection-quality standards and the automated evaluation that runs before release, to cut alert noise and make rollouts safer.

A lot of detection gaps are really telemetry gaps. I work across engineering, product, data science and threat intelligence to close them.

On my own time, I’m thinking through how AI-written detections should be evaluated and governed before they ship. I’ll publish that work here. Industrial-systems security is the other area I research.

Where to start #

Read Understanding How LLMs Process Security Telemetry. It measures how a language model reads a command line, then runs the numbers on 16,248 real Sysmon events. Every measurement reruns from the companion notebook.

Background #

I’m a Principal Security Researcher at Microsoft, working on Defender. Before that, I led criminal and nation-state intrusion investigations in incident response, advised enterprises as a security consultant and worked in endpoint security engineering. I hold an MS in Computer Science from the University of Tulsa.

Contact #

Email research@henryparks.com with research questions, corrections, collaboration ideas or advisory and speaking requests.

Views here are my own and do not represent Microsoft.