Home/Labs
Things Andrew is building, testing, and turning into artifacts
Labs, field notes, and applied research
Purple Team consulting is connected to practical lab work, vulnerability intelligence, AI research, and field notes
that sharpen how Andrew turns field evidence into artifacts leaders can use.
Applied cyber lab
Purple Firefish
Applied cybersecurity lab work for converting field observations, threat models, and consulting patterns into practical decision artifacts.
Discuss Purple Firefish
What it produces
Risk memo structures, prioritization worksheets, tabletop prompts, operating-model patterns, and field notes that make advisory work more useful.
Why it matters to clients
It keeps consulting grounded in reusable work product instead of vague recommendations or one-off slideware.
How it supports focused sprints
It helps shape executive risk memos, attack-path narratives, remediation plans, tabletop materials, and AI abuse-case review patterns.
Vulnerability intelligence
Purple Radar
Vulnerability intelligence work for turning public threat data into clearer prioritization and action.
Open Purple Radar
What it produces
Exposure snapshots, vulnerability-prioritization thinking, executive risk language, and clearer questions for remediation owners.
Why it matters to clients
It helps convert public threat and vulnerability data into conversations about exploitability, business impact, ownership, and sequencing.
How it supports risk radar sprints
It helps frame exposure snapshots, critical vulnerability prioritization, business-risk memos, and executive readouts.
AI research edge
Evening Star AI
AI research and product work focused on anomaly intelligence, cyber-native AI systems, and launch-review questions.
Visit Evening Star AI
What it produces
AI security questions, anomaly-intelligence patterns, governance prompts, and review checklists for high-consequence workflows.
How it informs advisory work
It keeps consulting grounded in current AI security questions, anomaly detection thinking, governance concerns, and workflow-level evidence needs.
Field notes
Practical notes for high-pressure security decisions.
These are non-sensitive, original notes Andrew can point buyers and operators to when a conversation needs structure before a formal engagement.
Vulnerability prioritization
How to prioritize a vulnerability backlog when everything is marked critical
A worksheet for grouping findings by exposed asset, owner, business workflow, and next remediation motion.
Read the field note
AI launch risk
AI abuse-case matrix for launch reviews
A practical review artifact for AI workflows, data exposure, tool action, guardrails, and launch decisions.
Read the field note
Executive risk translation
Board-ready cyber risk memo structure
A concise memo structure for turning technical evidence into leadership options, owners, and next actions.
Read the field note
Practical artifacts
Reusable outlines, not generic reports.
These examples are representative templates for memos, matrices, and worksheets. They are not client case studies and do not contain sensitive operational details.
Executive risk memo
- Decision needed
- Business context
- Evidence summary
- Options and tradeoffs
- Owner, date, and next checkpoint
AI abuse-case matrix
- Workflow boundary
- Data and tool access
- Abuse scenarios at a safe summary level
- Controls and gaps
- Launch decision criteria
Vulnerability prioritization worksheet
- Finding cluster
- Asset and business context
- Exposure and exploitability context
- Owner and remediation motion
- Decision and reporting status
Client benefit
How the lab work benefits clients
The lab work gives Purple Team stronger ways to frame exposure backlogs, AI launch reviews, incident exercises, and executive risk memos.
- Better prioritization
- Better evidence trails
- Better AI governance conversations
- Better threat/risk translation
- Better decision artifacts