February 18, 2026
Topology Beats Noise: Entity-Centric Detection of SSLVPN Abuse
Building an entity-centric ES|QL hunting model for SSLVPN abuse by prioritizing topology over raw alert volume. We explore how infrastructure reuse, cross-organization overlap, and short authentication time deltas can separate adversarial activity from benign noise at scale.