Mohit Sharma

Research notes

Security field notes

Methods, tooling, and evidence from applied security research.

  1. · 4 min

    The benchmark said 85. Accuracy said zero.

    A mock Quorum run produced a handsome judge score and no correct answers. That contradiction became the evaluation design.

    • AI evaluation
    • Benchmarking
    • LLM
    • Reproducibility
  2. · 4 min

    8,218 CVEs, 411 seats

    The arithmetic behind ExploitRank's fixed review queue is simple. The hard part is refusing to make the queue mean more than it does.

    • Vulnerability management
    • Threat intelligence
    • EPSS
    • CISA KEV
  3. · 3 min

    The TLP label that stopped this post

    I was documenting Malscope's public release boundary when its own fixture data proved the boundary was not enforced yet.

    • Malware analysis
    • Detection engineering
    • ATT&CK
    • Data protection
  4. · 4 min

    Field notes, not victory laps

    The first version of this blog promised transparent methods in 175 tidy words. The useful version has to show the awkward parts too.

    • Security research
    • Threat intelligence
    • ATT&CK