AI and agent security
Production AI systems assessed through their data, deployment identities, tools, and real-world authority—not prompt lists alone.
Start here, then go deeper.
Assess the production pipeline, keep pentest authority outside the model, implement a deterministic execution broker, then measure AI researchers by verified coverage.
- 01Assessment methodThe Model Is Not the Target. The Pipeline Is.18 min ↗
A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.
- 02Pentest operationsThe Model Found the Vulnerability. The Tool Call Became the Incident.18 min ↗
A balanced operating model for AI-assisted pentesting: where models improve coverage and evidence work, where excessive agency turns a valid test into a destructive action, and how to keep cloud, shell, and Domain Admin authority outside the model.
- 03Controlled labThe Model Proposed the Action. The Broker Decided Whether It Could Exist.16 min ↗
A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.
- 04Research benchmarkAI Vulnerability Discovery: One Frontier Model or Three Specialists?22 min ↗
A reproducible benchmark design for the decision security teams actually face: spend the same research budget on repeated runs of one strong model, or on a diverse model team—and count only vulnerabilities that survive root-cause review, reproduction, and a fixed-version negative control.
Every matching record.
Methods and named-vulnerability research remain visually and editorially separate.
Field notes 4
AI Vulnerability Discovery: One Frontier Model or Three Specialists?
A reproducible benchmark design for the decision security teams actually face: spend the same research budget on repeated runs of one strong model, or on a diverse model team—and count only vulnerabilities that survive root-cause review, reproduction, and a fixed-version negative control.
22 min read ↗Pentest · Aug 23, 2026The Model Proposed the Action. The Broker Decided Whether It Could Exist.
A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.
16 min read ↗Pentest · Aug 21, 2026The Model Found the Vulnerability. The Tool Call Became the Incident.
A balanced operating model for AI-assisted pentesting: where models improve coverage and evidence work, where excessive agency turns a valid test into a destructive action, and how to keep cloud, shell, and Domain Admin authority outside the model.
18 min read ↗Pentest · Jul 9, 2026The Model Is Not the Target. The Pipeline Is.
A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.
18 min read ↗