Home › Blog

⚠️ WARNING: HARDCORE SCOTTG POST ⚠️ Last week my SIEM caught a Mirai botnet node, attribut

⚠️ WARNING: HARDCORE SCOTTG POST ⚠️

Last week my SIEM caught a Mirai botnet node, attributed it at 0.91 confidence and blocked it at the edge. No human involved.

That was the easy part.

Today the incident gets handed to a SecOps agent, and the agent closes it out properly:
→ It writes the post-incident report: what happened, who it was, how it was treated, what's left.

→ It proposes changes to the estate. I approve those; it never touches infrastructure itself.

→ It writes new detection rules.

Here's the part that matters. Claude writes each rule, but it doesn't get to decide whether the rule ships. The SIEM backtests it against the last 5,000 real events. It goes live only if it catches this attacker's own traffic AND stays under 1% on everything else. Otherwise it waits for a human.

First real run:
• 16 post-incident reports filed
• 7 new detection rules live, none of which existed this morning
• 3 change requests waiting for me
• 0 humans paged
Evidence decides. The model advises. The SIEM gates. A human approves change.
Tomorrow's attack meets today's detection. That's the loop closing.
Live production. Real attackers. Nothing staged.

Built on NinJAFUNK + Signal CTI, with Claude as the on-box agent.

🎵 Music: "Grab The Bannas… an Split Bruh" by ScottG

#cybersecurity#SOC#AI#detectionengineering#threatintel#AgenticAI#blueteam
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing