Home › Blog

Most security teams don't have a security programme.

Most security teams don't have a security programme. They have a scanner museum.

Semgrep finds the code problems. ZAP finds the runtime problems. Trivy finds the container problems. Checkov finds the infrastructure problems. Nuclei finds the CVE-of-the-week that someone already tweeted a PoC for. Gitleaks catches the intern who committed an AWS key and then committed a second commit saying "remove key."

Ten tools. Ten dashboards. Ten teams (screw teams now) channels where findings go to die. One overwhelmed human in a spreadsheet at 11pm, questioning every life decision.

I built ANTOS because I was often a human observer of this tragedy ++ Low tolerance for purgatory.

ANTOS is a DevSecOps orchestration pipeline.

Every scanner pushes SARIF into one ingestion endpoint. Claude triages every finding — not "high/medium/low" checkbox triage from a CVSS score someone assigned in 2019, but actual contextual analysis. SQL injection in a test fixture? False positive. XXE in a production XML parser with no defused-xml? That's a breach waiting to file its own incident report. Fix it. Here's the patch.

Cross-tool correlation means Semgrep finds it, ZAP confirms it, and it becomes one issue. Not two tickets. Not the Wednesday standup where Dave from AppSec and Priya from Platform discover they've been fixing the same bug from opposite ends.

Then it writes the executive report. The board deck you were going to spend Friday building out of vibes — done in four seconds, backed by data. They don't know what CVSS is. They understand "24 findings, 18 fixed, here's why the other 6 won't kill us."

Meet Nik0. He's watching the pipeline at 3am, processing the queue, sending passive-aggressive nudges about the critical finding you've ignored for six days. Doesn't sleep. Doesn't get bored. Does get sarcastic about your unpatched dependencies. Feature, not bug. Your dependencies deserve the shame.

Claude does the thinking. Code analysis, fix generation, triage reasoning, report synthesis. Not keyword matching. Not regex. Genuine comprehension of what the code is doing and whether you should care.
Eight stages. No gaps. Every finding gets an ID, a lifecycle, and a fix recommendation. Nothing disappears into a CSV.

I ran it against my own code. It failed itself on a quarter of its own tests and filed them as findings. Grassed itself up. Without being asked. That's the bar.
No SOC team of twelve. No six-figure SIEM contract. Just a pipeline that works.

ninjasignal.ninja/antos

The scanner museum is closed. The pipeline is open.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing