Case intake
Suspicious activity reported
Plan collection
Agent decides what evidence is needed
Run approved tools
Read-only, allowlisted, least privilege
Processes / parent-child
Services / autoruns
Network / DNS / logs / hashes
Normalize evidence
Correlate findings
Assess confidence
Fact vs inference
Safe stop / escalate
Recommend actions
With validation + rollback steps
Human analyst decision
Triage JSON
Executive summary + timeline
Risk score with evidence
- Case intake
- agent — Suspicious activity reported
- Plan collection
- agent — Agent decides what evidence is needed
- Run approved tools
- tool — Read-only, allowlisted, least privilege
- Processes / parent-child
- data
- Services / autoruns
- data
- Network / DNS / logs / hashes
- data
- Normalize evidence
- validation
- Correlate findings
- agent
- Assess confidence
- agent — Fact vs inference
- Safe stop / escalate
- policy
- Recommend actions
- tool — With validation + rollback steps
- Human analyst decision
- approval
- Triage JSON
- output
- Executive summary + timeline
- output
- Risk score with evidence
- output
Project 05 · Security triage
Home-Lab Endpoint Triage Agent
Read-only evidence collection, then a human. Adversarially tested in isolation.
- Architecture
- Case intake → Plan collection → Run approved tools → Processes / parent-child
- Security equivalent
- Read-only collection → Least privilege / separation of duties
- Strongest lesson
- Prove the limits under attack