What can cyber defense learn from the famous Move 37 in Go?
There's an ongoing debate about whether AI will meaningfully change cyber offense beyond simply making attacks faster and more scalable.
We built AI agents that run red and blue team operations against live detection stacks. They simulate real attack campaigns, measure what gets caught, and generate validated detection rules from the actual telemetry.
(4) For more details, see my blog post at 0Labs: https://t.co/irO4knH8o5
We're starting to work with select partners to scale this up. If you'd like to speak with us about this, please reach out.
(3) Then it adapts when detected, and maps exactly where your detection coverage succeeds and fails. This is continuous, adaptive detection validation for every team that can't afford expensive purple team engagements.
(2) Our platform allows you to plug in your detection logic, select a threat profile, and launch a validation run against a live cyber range where an AI-driven attack agent executes full multi-step campaigns.
(1) Detection engineering has a fundamental asymmetry. Attackers privately test and iterate their techniques against proprietary security tools until they evade defenses, but defenders rarely, if ever, have the ability to do the reverse. We're building 0Labs to change this.
@EsbenKC recently convinced me that not writing publicly is worse than publishing something imperfect. So, I decided to write about some life experiences that shaped how I think about risk, decisions and building things. This is my first one. Link in reply.