Sign in

Lenny Zeltser

@lennyzeltser.com
2.4K followers 375 following 111 posts

Builder of security products and programs. Teacher of those who run them. zeltser.com

PostsRepliesMedia
Lenny Zeltser @lennyzeltser.com · 29/09/2026
My new cheat sheet is out! This one helps malware analysts incorporate AI agents into their workflows, including how to spot an agent reporting a timed-out tool as having found nothing. zeltser.com/ai-assisted-malware-ana…
zeltser.com
AI-Assisted Malware Analysis Tips
An AI agent can amplify a malware analyst's skills, but the analyst must direct it and verify its findings. These tips cover how to split the work, set up a contained lab, delegate tasks, and question conclusions.
120
Lenny Zeltser @lennyzeltser.com · 28/09/2026
Here's a short template for capturing and communicating details about a high-profile vulnerability. It helps you share your findings with internal stakeholders and is a starting point for external comms. zeltser.com/high-profile-vulnerabil…
zeltser.com
Handling High-Profile Vulnerabilities
When a high-profile vulnerability surfaces, executives and customers want to know whether it affects you. With a one-page brief and a short process, you can capture the key details and reach the answer without scrambling.
000
Lenny Zeltser @lennyzeltser.com · 25/09/2026
AI-generated code was the AI asset our survey respondents most often reported having. Yet almost no one named it as a worry. This is just one of the findings that caught my attention. zeltser.com/ai-security-decisions-r…
zeltser.com
My Favorite Findings From the AI Security Decisions Report
Over 300 security professionals told Sounil Yu and me how their organizations secure AI. We published what we learned as the AI Security Decisions Report, so you can compare your AI security decisions with your peers'. Several of the findings were surprising, and each one is worth checking against y
010
Lenny Zeltser @lennyzeltser.com · 22/09/2026
Sounil Yu and I surveyed 300+ security professionals about how their organizations secure AI. We published what we learned as a report, and here are the findings that surprised me most. zeltser.com/ai-security-decisions-r…
zeltser.com
My Favorite Findings From the AI Security Decisions Report
Over 300 security professionals told Sounil Yu and me how their organizations secure AI. We published what we learned as the AI Security Decisions Report, so you can compare your AI security decisions with your peers'. Several of the findings were surprising, and each one is worth checking against y
011
Lenny Zeltser @lennyzeltser.com · 15/09/2026
I'm starting to look for my next role as a CISO, a security product leader, or an uncommon mix of the two. I was VP of Product at two security companies before becoming the founding CISO at one of them. If you know of a fit, I'd like to hear about it. zeltser.com/about
062
Lenny Zeltser @lennyzeltser.com · 03/09/2026
What may your AI agents do on their own? Many security teams reconstruct the answer from tool settings, runbooks, and whoever configured them. Recording those decisions in one table, one row per workflow, turns them into policy you can enforce. zeltser.com/security-autonomy-matrix
zeltser.com
The Security Autonomy Matrix: Deciding AI Authority
The Security Autonomy Matrix is a framework for deciding how much authority to grant your security AI agents, one kind of action at a time. You record those decisions in one table, one row per workflow, capturing the autonomy level, who answers for it, and when the grant expires.
000
Lenny Zeltser @lennyzeltser.com · 28/08/2026
The AI security capability on your shortlist may already be in your stack, perhaps as a feature of a platform you license or a control another team operates. zeltser.com/ai-security-buying-ques…
zeltser.com
Five Questions to Answer Before Buying an AI Security Product
In the young security-for-AI market, what a product protects and how it ships can differ from what its label promises. With five questions drawn from the AI Defense Matrix Catalog work, you'll know what you're buying, whether that's a capability you already own or an early startup worth a closer loo
031
Lenny Zeltser @lennyzeltser.com · 27/08/2026
AI security products that sound alike can solve very different problems. I organized the questions I use to tell them apart, sorted by product type. zeltser.com/ai-security-market-fiel…
zeltser.com
A Field Guide to the AI Security Market
The market for products that secure AI is crowded and hard to read, with overlapping categories and products that each do many jobs. With the AI Defense Matrix, you can ask the right questions, tell what a product was built for, and staff the gaps no product fills yet.
001
Lenny Zeltser @lennyzeltser.com · 26/08/2026
AI agents can earn autonomy the way medical residents earn unsupervised procedures, by performing under supervision first. The Security Autonomy Matrix lets you record each grant, how its autonomy can grow, and the trigger that takes it back. zeltser.com/security-autonomy-matrix
zeltser.com
The Security Autonomy Matrix: Deciding AI Authority
The Security Autonomy Matrix is a framework for deciding how much authority to grant your security AI agents, one kind of action at a time. You record those decisions in one table, one row per workflow, capturing the autonomy level, who answers for it, and when the grant expires.
041
Lenny Zeltser @lennyzeltser.com · 25/08/2026
The AI security market is full of future-tense products, announced before they're built. These five questions separate what works today from what's promised. zeltser.com/ai-security-buying-ques…
zeltser.com
Five Questions to Answer Before Buying an AI Security Product
In the young security-for-AI market, what a product protects and how it ships can differ from what its label promises. With five questions drawn from the AI Defense Matrix Catalog work, you'll know what you're buying, whether that's a capability you already own or an early startup worth a closer loo
000
Lenny Zeltser @lennyzeltser.com · 21/08/2026
How can you turn raw malware analysis notes into a solid report? You can use my template yourself or point your AI agent at my MCP server to draft one with the template and my writing guidance. Your sensitive data stays local. zeltser.com/malware-analysis-report
zeltser.com
A Report Template for Malware Analysis
A malware report is only as useful as readers' ability to find in it what they need. This customizable template organizes the findings into a coherent structure, so a responder, a manager, or a fellow researcher can benefit from the analysis.
010
Lenny Zeltser @lennyzeltser.com · 20/08/2026
Preparing to talk to a security vendor? Cyber Company Profiles gives you an independent read of its market position and product strategy, built on the questions I kept asking as a buyer and product leader. zeltser.com/cyber-company-profiles
zeltser.com
Cyber Company Profiles: Independent Analysis of Security Vendors
Judging a security vendor from its own materials tells you little about how it compares to the rest. Cyber Company Profiles scores hundreds of cybersecurity companies from public sources.
110
Lenny Zeltser @lennyzeltser.com · 19/08/2026
Shopping for AI security products gets confusing fast, so I put together a short field guide that maps the market's product types and what to check in each. zeltser.com/ai-security-market-fiel…
zeltser.com
A Field Guide to the AI Security Market
The market for products that secure AI is crowded and hard to read, with overlapping categories and products that each do many jobs. With the AI Defense Matrix, you can ask the right questions, tell what a product was built for, and staff the gaps no product fills yet.
120
Lenny Zeltser @lennyzeltser.com · 18/08/2026
My new report template helps malware analysts organize and communicate their findings. It draws on my own experiences and established frameworks such as the Malware Behavior Catalog, for credible reports. zeltser.com/malware-analysis-report
zeltser.com
A Report Template for Malware Analysis
A malware report is only as useful as readers' ability to find in it what they need. This customizable template organizes the findings into a coherent structure, so a responder, a manager, or a fellow researcher can benefit from the analysis.
052
Lenny Zeltser @lennyzeltser.com · 14/08/2026
Each of my executive-briefing templates answers what senior leaders actually ask. What happened, what it means for the organization, and what we should do. They're based on what I wanted to see and share as a CISO. zeltser.com/cyber-brief-templates-f…
zeltser.com
Templates for Cybersecurity Executive Briefings
In an effective executive brief, you lead with the bottom line and what a finding means for your organization. Use these four customizable templates to do exactly that across threat intel, vulnerabilities, incidents, and assessments.
000
Lenny Zeltser @lennyzeltser.com · 13/08/2026
The contested areas of AI security formed around the newest asset classes, such as runtime AI data and AI agent identities, where startups and incumbents compete. Acquirers have absorbed over one in ten products in the AI Defense Matrix Catalog. zeltser.com/ai-security-market-shape
zeltser.com
What 239 Products Reveal About the Shape of AI Security
The security-for-AI market is young and lopsided. Incumbents quickly extended their products into the AI versions of assets they already secured, while the more distinct AI assets drew startups and incumbents alike into markets that stay active and contested.
000
Lenny Zeltser @lennyzeltser.com · 12/08/2026
I launched Cyber Company Profiles to analyze the market position and product strategy of hundreds of cybersecurity companies. Same questions, same scales, so you can compare vendors and go deep, instead of collecting one-off AI answers. zeltser.com/cyber-company-profiles
zeltser.com
Cyber Company Profiles: Independent Analysis of Security Vendors
Judging a security vendor from its own materials tells you little about how it compares to the rest. Cyber Company Profiles scores hundreds of cybersecurity companies from public sources.
021
Lenny Zeltser @lennyzeltser.com · 11/08/2026
I put together four templates for briefing executives about cybersecurity matters, covering a threat campaign, a celebrity vulnerability, an incident, and a security assessment. Customize them to your own needs. zeltser.com/cyber-brief-templates-f…
zeltser.com
Templates for Cybersecurity Executive Briefings
In an effective executive brief, you lead with the bottom line and what a finding means for your organization. Use these four customizable templates to do exactly that across threat intel, vulnerabilities, incidents, and assessments.
010
Lenny Zeltser @lennyzeltser.com · 30/07/2026
When everyone's attention is on a celebrity vulnerability, you can organize your investigation and share findings using my new template. It's AI-friendly, of course. zeltser.com/high-profile-vulnerabil…
zeltser.com
Handling High-Profile Vulnerabilities
When a high-profile vulnerability surfaces, executives and customers want to know whether it affects you. With a one-page brief and a short process, you can capture the key details and reach the answer without scrambling.
020
Lenny Zeltser @lennyzeltser.com · 29/07/2026
Sounil Yu and I mapped security-for-AI products to create the AI Defense Matrix Catalog. Almost half protect runtime AI data, yet over a quarter of the matrix is empty. Products cluster where technology can do the work and thin out where people do. zeltser.com/ai-security-market-shape
zeltser.com
What 239 Products Reveal About the Shape of AI Security
The security-for-AI market is young and lopsided. Incumbents quickly extended their products into the AI versions of assets they already secured, while the more distinct AI assets drew startups and incumbents alike into markets that stay active and contested.
020
Lenny Zeltser @lennyzeltser.com · 28/07/2026
Attackers and their malware can turn our trusted tools against us to steal API and SSH keys. In the s1ngularity attack, hijacked AI coding agents combed developer machines for such secrets. Here's how to minimize our exposure. zeltser.com/securing-api-keys-on-yo…
zeltser.com
Securing API Keys on Your Workstation
Every dev tool you grant API access to, AI assistants included, can read the keys within its reach. No setup removes that risk entirely, so the goal is fewer secrets exposed and less damage when one leaks.
140
Lenny Zeltser @lennyzeltser.com · 24/07/2026
If you help secure AI, whatever your title, Sounil Yu and I have ten quick questions for you. Anonymous, mostly checkboxes. We'll share the analysis, so the more practitioners respond, the more useful the benchmark becomes for everyone. zeltser.com/ai-security-survey
zeltser.com
Benchmark Your AI Security Decisions: A Five-Minute Survey
Answer ten questions about how your organization secures AI, and you get a peer benchmark in return. Sounil Yu and I will publish findings on which AI assets peers protect, who decides, and where controls come from.
021
Lenny Zeltser @lennyzeltser.com · 23/07/2026
Third-party keyboards can leak our keystrokes even when the developer isn't malicious. A supply chain attack can hijack a legitimate app, and weak engineering and security practices can expose highly sensitive data. zeltser.com/third-party-keyboards-s…
zeltser.com
Security of Third-Party Keyboard Apps on Mobile Devices
Keyboard apps offer better predictions, voice transcription, and AI-powered writing, all requiring users to send what they type to remote servers. Mobile OS vendors set the rules but can't enforce what developers do with that data.
010
Lenny Zeltser @lennyzeltser.com · 22/07/2026
I created a short template for capturing and communicating details about a high-profile vulnerability. It helps you share your findings with internal stakeholders and is a starting point for external comms. zeltser.com/high-profile-vulnerabil…
zeltser.com
Handling High-Profile Vulnerabilities
When a high-profile vulnerability surfaces, executives and customers want to know whether it affects you. With a one-page brief and a short process, you can capture the key details and reach the answer without scrambling.
000
Lenny Zeltser @lennyzeltser.com · 21/07/2026
Security leaders are making AI security decisions with almost no data about what their peers are doing. Sounil Yu and I built a five-minute anonymous survey to change that, and we'll publish the findings so you can benchmark your approach. zeltser.com/ai-security-survey
zeltser.com
Benchmark Your AI Security Decisions: A Five-Minute Survey
Answer ten questions about how your organization secures AI, and you get a peer benchmark in return. Sounil Yu and I will publish findings on which AI assets peers protect, who decides, and where controls come from.
031
Lenny Zeltser @lennyzeltser.com · 17/07/2026
I've seen too many author-centric assessment reports, full of stories of conquest and irrelevant details. The best reports are reader-centered. My new template offers a consistent way to write them that way. It's AI-friendly, too. zeltser.com/security-assessment-rep…
zeltser.com
A Report Template for Security Assessments
The technical severity of an assessment finding tells only part of the story. A customizable report template helps you document the scope, rate findings by risk, and write for the executives and engineers who read the results differently.
011
Lenny Zeltser @lennyzeltser.com · 16/07/2026
A decade of CA failures could have collapsed the web's certificate trust model, but they didn't. Browsers and CAs addressed each failure with a structural fix, and the same approach applies wherever you delegate trust. zeltser.com/past-present-future-web…
zeltser.com
The Past, Present, and Future of the Web's Trust Model
Observability, short-lived credentials, and active enforcement hold the web's trust model together. Without them, a decade of Certificate Authority failures would've collapsed it. Will those same levers hold for what's coming next?
010
Lenny Zeltser @lennyzeltser.com · 15/07/2026
Sounil Yu and I built the AI Defense Matrix, an approach for deciding how to defend the various AI systems in your environment. Here's why. www.sans.org/blog/why-sounil-yu-i-b…
010
Lenny Zeltser @lennyzeltser.com · 15/07/2026
AI capabilities of keyboard apps (rewrites, voice transcription, generative writing) entice us into letting our keystrokes float to the developer's servers. That makes each one a keylogger we authorized, with safeguards left to the developer. zeltser.com/third-party-keyboards-s…
zeltser.com
Security of Third-Party Keyboard Apps on Mobile Devices
Keyboard apps offer better predictions, voice transcription, and AI-powered writing, all requiring users to send what they type to remote servers. Mobile OS vendors set the rules but can't enforce what developers do with that data.
000
Lenny Zeltser @lennyzeltser.com · 14/07/2026
My new template for security assessment reports offers a structured, repeatable approach to communicating with readers. It's based on my experience creating and reading many such reports over the years. It's AI-friendly, too. zeltser.com/security-assessment-rep…
zeltser.com
A Report Template for Security Assessments
The technical severity of an assessment finding tells only part of the story. A customizable report template helps you document the scope, rate findings by risk, and write for the executives and engineers who read the results differently.
010
Lenny Zeltser @lennyzeltser.com · 10/07/2026
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local. zeltser.com/cyber-threat-intel-repo…
zeltser.com
A Report Template for Cyber Threat Intelligence
Cyber threat intelligence analysts produce credible reports by weighing signals at tactical, operational, and strategic levels. A customizable CTI report template helps analysts capture activity, attribute it with calibrated confidence, and translate findings into defensive actions.
051
Lenny Zeltser @lennyzeltser.com · 08/07/2026
Observability, short-lived credentials, and active enforcement held the web's certificate trust model through a decade of CA failures. The same three levers work anywhere you delegate trust, from code signing to identity federation. zeltser.com/past-present-future-web…
zeltser.com
The Past, Present, and Future of the Web's Trust Model
Observability, short-lived credentials, and active enforcement hold the web's trust model together. Without them, a decade of Certificate Authority failures would've collapsed it. Will those same levers hold for what's coming next?
000
Lenny Zeltser @lennyzeltser.com · 07/07/2026
My new template for cyber threat intelligence reports covers tactical, operational, and strategic aspects of threat activity. A companion brief captures the key takeaways for decision-makers. You can also use it with your AI agent. zeltser.com/cyber-threat-intel-repo…
zeltser.com
A Report Template for Cyber Threat Intelligence
Cyber threat intelligence analysts produce credible reports by weighing signals at tactical, operational, and strategic levels. A customizable CTI report template helps analysts capture activity, attribute it with calibrated confidence, and translate findings into defensive actions.
000
Lenny Zeltser @lennyzeltser.com · 02/07/2026
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level. zeltser.com/six-signals-for-threat-…
zeltser.com
Six Signals for Threat Attribution
Credible threat attribution weighs six signals together. Each signal has a disciplined methodology behind it, with citations and stress tests to back the conclusions.
000
Lenny Zeltser @lennyzeltser.com · 01/07/2026
Every domain has its Turbo Encabulator. The more expert we feel, the more fluently we explain something that doesn't exist. zeltser.com/experts-overstate-exper…
zeltser.com
Experts Cannot Help Overstating Their Expertise
The more confident we feel in a domain, the more likely we are to claim knowledge that doesn't exist. Recognizing this overclaiming bias helps us invite critique when we share our expertise and ask sharper questions when others share theirs.
000
Lenny Zeltser @lennyzeltser.com · 30/06/2026
This template for a security incident report not only helps with documentation, but also offers guidance when capturing findings during the incident. Take it, customize it, use it. zeltser.com/incident-response-repor…
zeltser.com
A Report Template for Cybersecurity and Privacy Incident Response
Incident responders need to know which questions to ask and how to communicate the answers to a diverse set of stakeholders. A customizable report template gives the response coordinator that structure when the stakes are high.
030
Lenny Zeltser @lennyzeltser.com · 25/06/2026
Plant a decoy persona, such as a fake LinkedIn profile or an unused directory account, to catch attackers reaching for what they think is real. The decoy has no production use, so any interaction is a high-confidence alert. zeltser.com/the-notion-of-a-honeypo…
zeltser.com
Plant Decoy Personas to Detect Impersonation Attacks
Decoy personas extend honeytoken thinking to user accounts and public profiles. The technique gives defenders a tripwire on the identity surface that other detection layers don't cover.
110
Lenny Zeltser @lennyzeltser.com · 24/06/2026
We read more threat attribution claims than we make. Six signals separate the ones that hold up from the ones that don't, and analysts weigh them together to build a defensible case. zeltser.com/six-signals-for-threat-…
zeltser.com
Six Signals for Threat Attribution
Credible threat attribution weighs six signals together. Each signal has a disciplined methodology behind it, with citations and stress tests to back the conclusions.
020
Lenny Zeltser @lennyzeltser.com · 23/06/2026
Letter grades tied to specific criteria influence business' behaviors, as NYC's sanitation labels have shown. Cybersecurity is starting to follow with the Cyber Trust Mark for IoT, but the consumer web hasn't caught up. zeltser.com/restaurant-inspections-…
zeltser.com
What Cybersecurity Can Learn from NYC Restaurant Inspections
When letter grades are visible at the moment of decision, businesses improve their practices, with NYC restaurants raising their sanitation scores 35% within three years. The U.S. Cyber Trust Mark is starting to bring the model to consumer IoT, while consumers still don't see equivalents on the webs
000
Lenny Zeltser @lennyzeltser.com · 17/06/2026
A decoy persona alerts you when an attacker probes your directory or public profiles. When they can't tell the bait from real identities, you create an asymmetry that gives you the upper hand. zeltser.com/the-notion-of-a-honeypo…
zeltser.com
Plant Decoy Personas to Detect Impersonation Attacks
Decoy personas extend honeytoken thinking to user accounts and public profiles. The technique gives defenders a tripwire on the identity surface that other detection layers don't cover.
010
Reposted by Lenny Zeltser
keydet89.bsky.social @keydet89.bsky.social · 11/06/2026
"The career-shaping work happens in the years before the job search." 100% We're seeing others say the same things albeit in other areas, such as leadership
001
Lenny Zeltser @lennyzeltser.com · 10/06/2026
The career-shaping work happens in the years before the job search. Reputation, relationships, and visible work are what land the right role. The resume's job ends at initial screening. zeltser.com/stop-relying-on-your-re…
zeltser.com
Stop Relying on Your Resume
A resume gets you past initial screening. Reputation, relationships, and visible work built in the years before the search are what land the right role.
110
Lenny Zeltser @lennyzeltser.com · 09/06/2026
Having interviewed many candidates, I can tell within minutes whether someone prepared for the discussion. A few hours of focused prep often makes the difference between getting the offer and getting a polite no. zeltser.com/interviewing-tips-for-i…
zeltser.com
5 Interviewing Tips for Tech and Cybersecurity Jobs
Strong technical skills get you to the interview, but preparation gets you the offer. Show up having done the homework that many candidates skip.
010
Lenny Zeltser @lennyzeltser.com · 07/06/2026
The REMnux MCP server can now draft malware analysis reports using my new report template: zeltser.com/ai-malware-analysis-rem…
zeltser.com
Using AI Agents to Analyze Malware on REMnux
To analyze malware effectively, AI agents need practitioners' expertise and access to the analysis tools. The REMnux MCP server provides both, connecting AI to 200+ tools on REMnux with guidance on which to run and how to interpret their output.
181
Lenny Zeltser @lennyzeltser.com · 05/06/2026
Self-hosted Algo on DigitalOcean lets us treat the VPN exit IP as disposable. After investigating malicious infrastructure, destroy the droplet, redeploy in minutes, and the next project starts from a clean IP. zeltser.com/deploy-algo-vpn-digital…
zeltser.com
How to Deploy Your Own Algo VPN Server in the DigitalOcean Cloud
Tunneling connections through a VPN in a public cloud helps conceal your origin and safeguard traffic when performing security research or connecting over untrusted networks. Algo VPN is an open-source bundle designed for self-hosted VPN services that's easy to deploy on DigitalOcean and relies only
000
Lenny Zeltser @lennyzeltser.com · 05/06/2026
I updated my cheat sheet for creating cybersecurity assessment reports. It's a one-page doc, which you can customize: zeltser.com/security-assessment-rep…
zeltser.com
Tips for Creating a Strong Cybersecurity Assessment Report
In a strong cybersecurity assessment report, you rate each finding by its risk to the organization rather than its raw tool score. You give readers the context and remediation steps they need to act on it. This cheat sheet covers how to analyze the data, document scope and methodology, write up find
030
Lenny Zeltser @lennyzeltser.com · 04/06/2026
The people who handle breaches all day may be the worst at protecting themselves. Feeling invulnerable is what lets us function around constant threat, the way it lets doctors work around disease. Warnings about our own risk rarely stick. zeltser.com/illusion-of-invulnerabi…
zeltser.com
The Illusion of Invulnerability in Cybersecurity
Healthcare workers wash hands more often when signs emphasize protecting patients rather than themselves, because people overestimate their own invulnerability but not others'. Security messaging may be more effective when highlighting risks to customers or colleagues rather than to the individuals
000
Lenny Zeltser @lennyzeltser.com · 03/06/2026
A decoy fires only when someone accesses a resource no legitimate user would touch. Plant tripwires across network, identity, data, and AI agent configs to create asymmetry in your security architecture. zeltser.com/protean-information-sec…
zeltser.com
Building Deception Into Your Security Architecture
Decoys add strategic asymmetry to your security architecture, strengthening your advantage against the attacker. Plant tripwires across network, identity, data, and AI agent configs for high fidelity alerts.
174
Lenny Zeltser @lennyzeltser.com · 01/06/2026
One word changed a hospital hand-washing sign from 'protects you' to 'protects patients,' and compliance climbed. We discount our own risk but not other people's. The same holds for security messaging aimed at others, not ourselves. zeltser.com/illusion-of-invulnerabi…
zeltser.com
The Illusion of Invulnerability in Cybersecurity
Healthcare workers wash hands more often when signs emphasize protecting patients rather than themselves, because people overestimate their own invulnerability but not others'. Security messaging may be more effective when highlighting risks to customers or colleagues rather than to the individuals
021
Lenny Zeltser @lennyzeltser.com · 28/05/2026
An attacker on a developer's machine often pivots to reconnaissance. AI agent MCP configs are plain-text files at known paths, offering an index of high-value services. A decoy entry pointing to a honeypot MCP server alerts you of an intrusion. zeltser.com/decoy-mcp-server-honeyp…
zeltser.com
Build a Decoy MCP Server to Catch AI Agent Attackers
Your AI agent's MCP config can be a target for an attacker who reaches your machine. A decoy MCP server entry pointing at a Cloudflare Worker can reveal the attacker's presence and their intent.
030