About

Plain Text Security is a research site on the parts of security that don't survive contact with real data: agentic AI runtime, malware tradecraft, and detection engineering. Every piece traces a claim down to the mechanism behind it, the API call, the config key, the token, the memory layout, rather than stopping at the category of thing a system is supposed to do.

I write it because most security content stops one level above where the interesting part starts. A post says a technique evades detection, or a control blocks an attack class, and moves on. The question that matters is how, specifically, and what that mechanism assumes that turns out not to hold. That's the level this site works at.

Articles ship when they're done. No fixed schedule, no filler between findings. Interactive figures (token-level heatmaps, annotated code, replayed attack sequences) carry as much of the argument as the prose, because a mechanism is often easier to see than to describe.

I'm Herman Errico. Questions, corrections, or tips: reach me through the subscribe form and reply to the confirmation email.