#tag

Ai Security

4 matching posts.

All tags
PentestAug 24, 202622 min read

AI Vulnerability Discovery: One Frontier Model or Three Specialists?

A reproducible benchmark design for the decision security teams actually face: spend the same research budget on repeated runs of one strong model, or on a diverse model team—and count only vulnerabilities that survive root-cause review, reproduction, and a fixed-version negative control.

#ai-security#methodology#pentest
PentestAug 23, 202616 min read

The Model Proposed the Action. The Broker Decided Whether It Could Exist.

A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.

#ai-security#pentest#methodology#access-control#attack-paths
PentestAug 21, 202618 min read

The Model Found the Vulnerability. The Tool Call Became the Incident.

A balanced operating model for AI-assisted pentesting: where models improve coverage and evidence work, where excessive agency turns a valid test into a destructive action, and how to keep cloud, shell, and Domain Admin authority outside the model.

#ai-security#pentest#methodology#access-control#active-directory
PentestJul 9, 202618 min read

The Model Is Not the Target. The Pipeline Is.

A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.

#methodology#pentest#attack-paths#cloud-security#ai-security