WARNING: HARDCORE SCOTTG POST (now with speaker-safe audio) ⚠️ If you watched my last SecO
WARNING: HARDCORE SCOTTG POST (now with speaker-safe audio) ⚠️
If you watched my last SecOps video with the sound up: sorry about your speakers.
The track was clipping. So I did what any sensible person does at 8am: remastered it in LANDR, rebuilt the export chain, and measured it properly this time (-14 LUFS, -1.5 dB true peak, zero clipped samples). Same film, fixed sound.
What the film shows hasn't changed:
My SIEM caught a Mirai botnet node, attributed it at 0.91 confidence and blocked it at the edge with no human involved.
Then the incident goes to an on-box AI SecOps agent that closes it out:
→ writes the post-incident report
→ proposes changes that I approve
→ writes new detection rules
Claude writes each rule, but it doesn't get to decide whether the rule ships. The SIEM backtests it on the last 5,000 real events. It goes live only if it catches the attacker's own traffic and stays under 1% on everything else.
First real run: 16 reports, 7 new detection rules live, 3 change requests, 0 humans paged.
Evidence decides. The model advises. The SIEM gates. A human approves change.
Live production. Real attackers. Nothing staged. Properly mastered.
🎵 "Grab The Bannas… an Split Bruh" by ScottG (LANDR remaster)
🎬 More films: https://ninjalabz.io
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·