Wiston Lestin

Writing

Field notes on building and measuring detections — for classic logs and for attacks against AI systems.

2026-07-12

My detection models score 100% on everything. That's a red flag, not a feature.

A weekend detection lab, sixteen trained models, perfect metrics on almost every row — and why the most honest number on the dashboard was a 0.0%. On synthetic fixtures, dataset naivety masquerades as model quality.

2026-07-07

Backtesting detection rules — including the ones for AI attacks

A lottery-prediction backtester, stripped of its models and repointed at Sigma rules. Two findings from real public data: a rule that was right and still blind, and keyword rules that catch under 9% of real jailbreaks.