Using MITRE ATLAS to Make AISecOps Threat-Informed
MITRE ATLAS gives AI security teams a shared map of adversary behavior for threat modeling, detection engineering, red teaming, and incident response.
notebook / 13 entries
I write about security problems, useful patterns, local tools, and what I learn when an agent has to do real work.
essential reading / foundation
Anthropic's framework connects agent identity, least agency, tool boundaries, memory integrity, and recovery into one practical security model.
MITRE ATLAS gives AI security teams a shared map of adversary behavior for threat modeling, detection engineering, red teaming, and incident response.
The OWASP Agentic Top 10 moves security beyond model output and into goals, tools, identities, memory, delegation, and runtime control.
The OWASP LLM Top 10 turns common language-model failure modes into security requirements, tests, telemetry, and response plans.
NIST AI RMF gives an AI security program its operating model: govern the work, map the context, measure the risk, and manage what happens next.
Four failures in Aria's voice input taught me why a green build and a working development demo are not enough.
An audit of Aria's autonomous loop found hundreds of goals, almost no progress, and a completion system that rewarded plausible output.
Aria produced hundreds of useful research reports that nothing ever read. The fix was a small, idempotent consumer pipeline.
A self-observation feature for Aria showed why metrics should remain available without becoming permanent instructions.
What two rounds of testing Aria's language and image models taught me about speed, benchmarks, and knowing when a score is wrong.
A quick way to tell whether your agent setup is ready to grow or still held together by one-off fixes.
A practical security review for agents that can read files, run commands, and use outside services.
Four simple work patterns for agents that use tools, make changes, test the result, and recover from interruptions.
all tags