Home › Blog

WARNING: HARDCORE SCOTTG POST (now with speaker-safe audio) ⚠️ If you watched my last SecO

WARNING: HARDCORE SCOTTG POST (now with speaker-safe audio) ⚠️

If you watched my last SecOps video with the sound up: sorry about your speakers.
The track was clipping. So I did what any sensible person does at 8am: remastered it in LANDR, rebuilt the export chain, and measured it properly this time (-14 LUFS, -1.5 dB true peak, zero clipped samples). Same film, fixed sound.

What the film shows hasn't changed:
My SIEM caught a Mirai botnet node, attributed it at 0.91 confidence and blocked it at the edge with no human involved.

Then the incident goes to an on-box AI SecOps agent that closes it out:
→ writes the post-incident report
→ proposes changes that I approve
→ writes new detection rules

Claude writes each rule, but it doesn't get to decide whether the rule ships. The SIEM backtests it on the last 5,000 real events. It goes live only if it catches the attacker's own traffic and stays under 1% on everything else.

First real run: 16 reports, 7 new detection rules live, 3 change requests, 0 humans paged.
Evidence decides. The model advises. The SIEM gates. A human approves change.

Live production. Real attackers. Nothing staged. Properly mastered.

🎵 "Grab The Bannas… an Split Bruh" by ScottG (LANDR remaster)

🎬 More films: https://ninjalabz.io

https://lnkd.in/ewvz7TMQ

#cybersecurity#SOC#AI#detectionengineering#threatintel#AgenticAI
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing