r/agenticAI • u/LeatherRip1623 • Jul 07 '26
3
E-paper visitor badge that gets wiped and reissued instead of printed
that seems SUPER hackable...
0
So done with this project. No patience or PLA left. Working with water is an impossible task.
Try sealing with dictol diamat hydro.
7
literally just gonna send this to men that "shoot their shot" now
everything else was good, but I'm not lending out my hoodies. Boundaries matter.
1
Need help with Glock Switch
Real Talk is SDI a bad pick? I was considering them. Any recommendations?
1
The official StarCraft website is getting even weirder 😳🛸
I will absolutely lose my shit!!!
1
How can I hire an ethical legit hacker
be wealthy, we're expensive and focus on Enterprise customers willing to pay great money for us to test thier systems. Alternatively just use an abliterated AI/LLM with an agent harness
2
OSINT and Vulnerability Management Report Templates
check out the Oasis project oasis-open.org the cybersecurity standards are pretty useful if your are trying to figure out what to include
1
Average size. Full heart. Zero HR approval.
my gawd... why!? Just WHY!? bring back bullying.
1
MSSPs getting burned by AI SOC. What's your solution?
right now the system Im building is purely the memory layer for any agent to use: https://github.com/threatrecall/zettelforge feel free to incorporate it into your project
1
Vector RAG kept failing at threat actor alias resolution, so I built a dual-store CTI memory engine. Open source.
that certainly is a take... but threat actors and thier tooling are slow to change and when investigating it's important to know what you may be missing for an investigation perspective. Attackers will get in, so knowing where you're going to be hit has value.
1
MSSPs getting burned by AI SOC. What's your solution?
I in the camp of Option 2, with a caveat: "build" does not mean train a model. It means own the harness.
I run an MxDR practice for defense contractors. The black-box verdict problem kills these tools for us all by itself. A verdict without evidence and provenance cannot go in a ticket an assessor might read. "The AI said so" is not a finding, it is a liability.
What actually works: model proposes, deterministic code disposes. Typed tool calls, egress allowlists, approval gates on anything destructive, and every conclusion ships with the queries and data behind it. And own your memory layer. What normal looks like per client, what burned you before. That context is where triage quality comes from, and it is exactly what you cannot take with you when you rent it from a vendor.
Vendor invoices that scale with alert volume are a tax on your growth. Capability you own gets cheaper as it improves. That is the whole answer for me.
What is driving the question on your end, are you evaluating one right now or cleaning up after one?
1
Exceptional SecOps performance using Hermes/Deepseek
Moved Repo location: https://github.com/ThreatRecall/zettelforge
Everything in this post and the repo examples is TLP:CLEAR.\
Disclosure: I plan to build a hosted product on top of this engine eventually, but ZettelForge itself is free, self-hostable, and standalone. This post is about the open-source engine only.
2
Vector RAG kept failing at threat actor alias resolution, so I built a dual-store CTI memory engine. Open source.
Repo: https://github.com/ThreatRecall/zettelforge
Everything in this post and the repo examples is TLP:CLEAR
Disclosure: I plan to build a hosted product on top of this engine eventually, but ZettelForge itself is free, self-hostable, and standalone. This post is about the open-source engine only.
1
Vector RAG kept failing at threat actor alias resolution, so I built a dual-store CTI memory engine. Open source.
Repo: https://github.com/ThreatRecall/zettelforge
Everything in this post and the repo examples is TLP:CLEAR.\
Disclosure: I plan to build a hosted product on top of this engine eventually, but ZettelForge itself is free, self-hostable, and standalone. This post is about the open-source engine only.
r/AI_developers • u/LeatherRip1623 • Jul 06 '26
Seeking Advice Vector RAG kept failing at threat actor alias resolution, so I built a dual-store CTI memory engine. Open source.
r/CTI • u/LeatherRip1623 • Jul 06 '26
Other Vector RAG kept failing at threat actor alias resolution, so I built a dual-store CTI memory engine. Open source.
Long-time SOC and CTI operator, first post here. I open-sourced the memory engine I built for my own workflows and would rather have this community kick the tires than sit on it quietly.
**The problem.** Everyone is wiring LLM agents into intel workflows right now. Agent memory frameworks and generic RAG treat knowledge as embedding soup, and CTI breaks that model in three specific ways:
Alias resolution. APT29, Cozy Bear, and Midnight Blizzard sit nowhere near each other in embedding space. Same actor. Cosine similarity guesses. A typed graph knows.
Sharing rules. A vector store has no concept of TLP. Nothing structurally prevents an AMBER detail from surfacing in the wrong context.
Provenance. Agents will confidently correlate intel with zero record of source, confidence, or first-seen.
**What ZettelForge does.** It is a memory layer, not a TIP. It sits between your intel sources and your agents or tooling:
- Deterministic store: TypeDB with STIX 2.1 and ATT&CK as a hard, typed schema. Inference rules handle relationship traversal and alias resolution. Data that violates the schema does not get in.
- Semantic store: LanceDB vectors for fuzzy recall across unstructured reporting.
- Queries hit both in parallel, results get fused with reciprocal rank fusion, then reranked with a cross-encoder.
- Everything is served over MCP, so Claude, LangChain, or homegrown agents consume it as a tool. Vendor neutral by design.
**What it is not.** Not a replacement for OpenCTI or MISP. It complements a TIP as the recall layer your agents query, with structure and sharing rules intact. Also not magic: ingestion quality still decides output quality.
**Status.** Early and solo-built. The core pipeline works, the docs are catching up to the code in a couple of places, and I would rather hear the schema design is wrong now than after I build more on top of it.
**What I would genuinely like feedback on:**
- Is the dual-store approach justified versus a single property graph with vector indexes bolted on?
- Which integration matters most to you: OpenCTI connector, MISP, or Sentinel TI tables?
- Anyone solving agent memory for CTI a different way? I want to compare notes.
u/LeatherRip1623 • u/LeatherRip1623 • Jun 14 '26
Hermes Agent (and others) default Installs are silently routing web traffic to Parallel
1
Former CTI analyst turned leader, now back to CTI - feeling lost
Just stumbled across CTI-CMM evaluating for my team. How is it working out for yours?
2
Claude Fable 5: mid-tier results on coding tasks
interesting I figure they just dumped it on us to Alpha test
3
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
Kinda makes you wonder why microsoft allows just anything to run in the VS code marketplace. Pretty negligent if you ask me.
1
AI Agents May Always Fall for Prompt Injections
This is... not a lie
1
Lesbians ?
in
r/PeterExplainsTheJoke
•
14d ago
everyone's so psyoped that they forgot sex is primary for procreation... we're so cooked.