NOTES FROM A SECURITY PRACTITIONER

Incident response
& AI security,
from the field.

Technical notes, response playbooks, and the things I wish were written down before the incident started.

IndependentEvidence-ledBuilt for defenders
WORKING NOTES / 2026-08LAST UPDATED 28 AUG
CURRENT FOCUS

The first
60 minutes

Stopping autonomous activity, removing unsafe authority, preserving evidence, and bounding downstream impact.

01StopCan the agent still run?
02RevokeWhat authority remains?
03PreserveWhat state will expire?
04ScopeWhat changed downstream?
first-hour rule:
authority before theory
NOTE / 008STATUS / PUBLISHEDREAD / 11 MIN

I keep this site for one reason: useful notes should not stay in private notebooks.

Everything here is authored and reviewed by Leandro Rocha for people who detect, investigate, and contain real attacks. AI-assisted tools may support research, drafting, or editing; technical claims and publication decisions remain the author's responsibility. Read the editorial policy ↗

Use the site
like a field kit.

Begin with the outcome you need. Each path leads to an operational resource, not a generic content category.

Start with the problem,
leave with a method.

Each collection connects principles to observable signals, concrete decisions, and reusable artifacts.

01

Detect

Telemetry architecture, triage logic, hypothesis-driven hunts, and detection-as-code patterns.

SIEMEDRAI telemetry
02

Respond

Roles, evidence standards, containment tradeoffs, recovery gates, and communications.

NIST 800-61Forensics
03

Defend AI

Threat models for agents, RAG, models, data pipelines, tool use, and human approval paths.

OWASP LLMMITRE ATLAS

When the signal is real,
reduce uncertainty.

Prescriptive starting points with explicit assumptions. Adapt them to your environment, then validate them in tabletop exercises.

STANDALONE OPERATIONAL RESOURCE

Incident Detection &
Response Framework

A structured practitioner guide to preparation, detection, triage, containment, eradication, recovery, and lessons learned.

Explore the framework
INCIDENT CLOCK / 008
60:00

LATEST · AI SECURITY · 11 MIN READ

The first 60 minutes

A commander-and-operator timeline for stopping autonomous activity, removing unsafe authority, preserving evidence, and bounding downstream impact.

Read field note
Articles live as simple content files—easy to draft, review, schedule, and share.
Browse all articles ↗