Detect
Telemetry architecture, triage logic, hypothesis-driven hunts, and detection-as-code patterns.
NOTES FROM A SECURITY PRACTITIONER
Technical notes, response playbooks, and the things I wish were written down before the incident started.
Stopping autonomous activity, removing unsafe authority, preserving evidence, and bounding downstream impact.
I keep this site for one reason: useful notes should not stay in private notebooks.
Everything here is authored and reviewed by Leandro Rocha for people who detect, investigate, and contain real attacks. AI-assisted tools may support research, drafting, or editing; technical claims and publication decisions remain the author's responsibility. Read the editorial policy ↗
Begin with the outcome you need. Each path leads to an operational resource, not a generic content category.
Establish authority, severity, evidence discipline, containment gates, communications, exercises, and recovery criteria.
Open the framework →RESPOND NOWStart with scenario-specific evidence, first actions, decision gates, containment, eradication, and recovery.
Choose a playbook ↓ENGINEER AI CONTROLSConnect AI incident response to identity, retrieval, independent policy, telemetry, tool use, and rollback.
Open AI Security IR →RUN THE INCIDENTUse structured templates for timelines, evidence, containment decisions, credentials, AI runtime state, and recovery approval.
Browse responder resources →Each collection connects principles to observable signals, concrete decisions, and reusable artifacts.
Telemetry architecture, triage logic, hypothesis-driven hunts, and detection-as-code patterns.
Roles, evidence standards, containment tradeoffs, recovery gates, and communications.
Threat models for agents, RAG, models, data pipelines, tool use, and human approval paths.
Prescriptive starting points with explicit assumptions. Adapt them to your environment, then validate them in tabletop exercises.
A structured practitioner guide to preparation, detection, triage, containment, eradication, recovery, and lessons learned.
Explore the framework ↗Decision points from first signal through recovery, with evidence-preservation gates.
Secure identities, trace mailbox activity, and coordinate payment-risk decisions.
Revoke sessions, validate persistence, and hunt downstream cloud activity.
Confirm access paths, preserve transfer evidence, and bound notification scope.
Audit code, workflows, dependencies, credentials, and persistence before trusted recovery.
Isolate affected assets, collect volatile evidence, and rebuild from trusted sources.
Contain unsafe agency, preserve prompts and traces, and validate a staged rollback.
LATEST · AI SECURITY · 11 MIN READ
A commander-and-operator timeline for stopping autonomous activity, removing unsafe authority, preserving evidence, and bounding downstream impact.
Read field note →