Home › Blog

Security as Code, Direct from the CLI

Security as Code. From the CLI. No tickets. No meetings. No steering committee. Just intent, execution, and artifacts.

I'm going to tell you what I'm actually doing — not what a vendor slide says you should do — because the gap between "security as code" as a conference slogan and "security as code" as a daily practice is roughly the width of the Grand Canyon, and most of the industry is standing on the wrong side waving brochures.

Here's the setup.

I use Claude Code. From the terminal. As my primary security engineering interface.

Not as a chatbot. Not as a "copilot" that suggests variable names while I do the real work. As cognition instrumentation. I Wang a concept — a control, a policy, a detection, an architecture — into the CLI, and what comes back is executable. Not a paragraph. Not a recommendation. Code. Artefacts. Things that run.

Let me walk you through what that actually looks like.

Threat model → detection rule. One session. No Jira.

I describe a scenario: "Credential stuffing against our auth endpoint using residential proxies, rotating IPs, low-and-slow, staying under rate limits."

Claude Code doesn't give me a whitepaper. It gives me:

→ A KQL detection query tuned to the described pattern

→ A Sigma rule for cross-platform portability

→ A YAML test case to validate the detection fires

→ Suggested telemetry gaps — what the detection can't see and why

Elapsed time: minutes. Not sprint cycles. Not "we'll schedule a workshop."

Policy → Rego. English → enforcement.

"Only containers from our approved registry. No root. No host networking. Resource limits mandatory."

That sentence becomes Open Policy Agent Rego. Directly. From the CLI. I review it, test it, push it. The policy is now infrastructure. Not a PDF in SharePoint that someone might read if the audit is imminent and the coffee is strong enough.

Architecture → diagram → threat surface. One flow.

I describe the system. Claude Code generates a Mermaid diagram — because I generate hundreds of architecture diagrams a week and Mermaid is the only sane way to do it when your output needs to be version-controlled, diffable, and not trapped inside a proprietary drawing tool that costs more than a junior analyst.

From the diagram, I ask for the threat surface. What comes back is a structured decomposition: trust boundaries, data flows, exposure points, ATT&CK technique mappings. Not a static image. A living model that I can iterate, extend, and plug into CI.

Compliance → evidence → continuous.

This is the part that makes GRC people either excited or terrified depending on how much of their career is built on manual evidence collection.

I describe the control objective. Claude Code generates the validation script — a check that runs in pipeline, produces evidence, timestamps it, and outputs a machine-readable result. The audit artefact becomes a byproduct of the control operating, not a seasonal ritual performed under duress by someone who'd rather be doing literally anything else.

Compliance as code isn't a philosophy. It's a Bash script that runs on a cron and doesn't lie.

Pen test assist — Claude meets Kali.

I've been running Claude against Kali in a controlled environment. Scanning, enumerating, looking. The AI doesn't replace the hacker head — the neural architecture that sees an open port the way a predator sees movement. But it radically accelerates the boring parts. Reconnaissance. Service fingerprinting. Output parsing. Hypothesis generation.

The loop I'm working toward: Claude proposes. A second model approves. Execution happens inside a scoped, auditable container. Every action logged. Every decision traceable. Autonomous pen testing with a kill switch and a paper trail.

Not science fiction. I'm building it now. It's messy and I'm beating down the signal-to-noise ratio but the scaffolding works.

Why this matters more than you think.

By 2029 — and I've written about this — security stops being a department and becomes a property of delivery systems. If it can't be expressed as code, policy, telemetry, and evidence, it becomes suspect. If it can't be continuously validated, it becomes theatre.

The CLI is where that transition happens. Not in dashboards. Not in vendor portals. Not in quarterly risk reviews performed by people who treat "ongoing" as a mitigation status.

The terminal is where security becomes real, because the terminal is where everything else already became real. Infrastructure. Deployment. Monitoring. Scaling. All of it moved to code. Security is the last holdout, clinging to manual processes and PDFs like a fax machine in a 5G world.

Claude Code — or whatever comes next — is not the point. The point is this:

Security practitioners who can turn intent into artefacts from a CLI will be the ones who matter in 2029.

Not the ones who "know where the setting is." Not the ones who translate risk into Jira tickets. Not the ones who produce beautiful evidence that isn't connected to actual controls.

The ones who can sit at a terminal and make security run on rails.

That's the bar. The tools are here. The excuse window is closing.

I'm not waiting for a vendor to package this. I'm not waiting for a framework to bless it. I'm not waiting for a steering committee to achieve alignment.

I'm in the CLI. Shipping controls. Generating detections. Building evidence pipelines. Wang'n reality into architecture and letting the artefacts speak for themselves.

If your security workflow still starts with a meeting and ends with a PowerPoint, we're playing different games on different timescales.

The terminal is the new SOC.

The prompt is the new runbook.

The artefact is the new evidence.

The code is the control.

Come build.

scottg/out

#cybersecurity #securityascode #claudecode #devsecops #AI #ninjatheme #CLI

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing