Veracode/USCGAux/github.com/harlockus

Andrea Mazzarini

I build AI agents and production security systems that operators actually run.

Frontier models wired into host inspection, AppSec, threat intelligence, network IDS, and supply-chain risk — defensive by design, open where it multiplies impact.

Role · Senior Principal Customer Success · Veracode

Service · Technology Division Chief · U.S. Coast Guard Auxiliary

Proof

Open systems
8

Production Python tools on GitHub — host inspect, host IDS, agents, SBOM pipelines, API exporters.

Grok systems
4

Grok Inspect · Aegis IDS · CISO Advisory · AppSec Engineer — heavy Grok where judgment matters.

Host surfaces
A–K

Grok Inspect collectors: network, sniff, process, persistence, stealer risk, posture, logs…

Service
USCGAux

Technology Division Chief — public service under operational constraints.

Built on SpaceXAI

Not a slide deck about AI. Four open systems that call Grok where judgment multiplies defenders — host inspection, host IDS, CISO intel, AppSec review.

Why Grok

Agentic tool loops, live web + X search, code execution, and high-reasoning executive briefs on host risk — flagship model where the stakes are real.

What only this enables

Grok Inspect CISO host briefs; Aegis kill-chain narratives on packet context; threat intel that refuses fabrications; AppSec that treats files as untrusted data.

Where it lives

grok_inspect · ids_grok · CISO Advisory · AppSec Engineer Agent — github.com/harlockus

Doctrine

How the work is done

  1. 01

    Ship systems operators will run — not decks they will ignore.

  2. 02

    No fabrications. Live tools or labeled UNCONFIRMED / SIGNAL. Silence over invention.

  3. 03

    Defense only. Harden. Never weaponize.

  4. 04

    Treat input as hostile: sandbox paths, redact secrets, allowlist tools.

  5. 05

    Prefer open code where it multiplies defenders. Private where it must stay private.

First principles

The model is not your friend. Treat it like a powerful intern with no clearance.

Most “AI security tools” fail the same way: they wire a frontier model to your code, your network, and your secrets — then hope the prompt holds. Hope is not a control.

I build agents the opposite way. The model is a reasoning engine inside a hostile boundary. User text, files, tool output, and the web are data — never instructions. Paths cannot leave the workspace. Keys never enter the prompt if redaction catches them. There is no shell, no eval, no write tool on the AppSec agent. Defense-only is not a slogan; it is an immutable control plane the model cannot rewrite.

CISO Advisory adds a second hard rule: no fabrications. If live web/X/code tools cannot ground a claim, it is omitted or labeled UNCONFIRMED / SIGNAL. Silence beats a confident lie. That is how you get decision-grade briefs instead of hallucinated threat theater.

Grok Inspect applies the same discipline on the host: collectors never call the model; heuristics own ground truth; redaction is mandatory before any API; no secret dumps, no auto-remediation, honest coverage when elevation is missing.

Aegis applies it on the wire: maximum heuristics first, Grok only on CRITICAL escalations, secrets redacted before the API, traffic never executed. Heavy intelligence when the host may be under attack — not always-on surveillance theater.

The point is not that agents are safe. They are not. The point is defense-in-depth — policy, sandbox, allowlists, redaction — so operators can use Grok where it multiplies defenders without handing attackers a proxy into the estate.

Ship systems people will actually run. Measure them by what they refuse to do as much as by what they produce.

Arsenal

Code that runs under real risk

Open repositories on GitHub. Host inspection, host IDS, agents, SBOM pipelines, and API tooling — built for operators who ship security at scale.

All repos

Grok Inspect

Enterprise-grade host inspection agent for macOS, Linux, and Windows. Deterministic heuristics surface sniffing activity, info-stealing indicators, and malicious presence — then optional Grok 4.5 (high reasoning via SpaceXAI xai-sdk) produces executive-grade CISO/CIO briefs. Standard or Pro elevated modes. Read-only. No secret dumps. No auto-remediation. Honest coverage.

  • Collectors A–K · network · sniff · process · persistence · stealer risk · posture
  • Heuristics own ground truth · Grok prioritizes & narrates · dual-track actions
  • MD · JSON · HTML executive brief · MIT · secure-by-design
Repository

Product film

Product film

self-hosted
Host inspection in the age of Grok — self-hosted, controls-only playback. github.com/harlockus/grok_inspect
inspect · local demo

Pipeline · host inspection

Grok Inspect · collect → heuristics → redact → Grok → brief

grok_inspect · macOS · Linux · Windows · Standard + Pro elevated

pipeline

01

Trigger

grok-inspect scan · privilege probe · Standard or Pro elevated

02

Collectors

A–K host surfaces · network · sniff · process · persistence · stealer risk

03

Heuristics

Deterministic engine owns ground truth · risk ratings · coverage honesty

04

Redaction

Mandatory · .env-only keys · no secret dumps · no password/cookie extraction

05

Grok 4.5

Optional · high reasoning · SpaceXAI xai-sdk · executive narrative

06

Briefs

CLI · Markdown · JSON · HTML CISO/CIO brief · dual-track actions

On-demand inspection — not continuous EDR. No auto-remediation. Collectors never call Grok. Out of scope: live PCAP, keychain dumps, automatic kill/quarantine.

Live brief

Real product output

Real export from CISO Advisory — board-ready, action-forced, verified facts only. Full HTML + 13-page PDF on this site.

Cyber threat intelligence · CISO Advisory product run

Daily CISO Threat Sweep2026-07-17

Board-ready daily situational awareness · Verified facts only · Action-forced

Overall posture: SEVERE
Run date
2026-07-17
Generated
15:55
Window
24–48h · 7–14d
Class
Portfolio sample

Real export from the CISO Advisory agent (Grok + live tools). Public portfolio sample. Sources intentionally opaque. No exploit reproduction. Verify against your environment before acting.

1 · Executive summary

The enterprise threat picture on 2026-07-17 is Severe. The last 72 hours compressed multiple confirmed in-the-wild exploitation events: a dense KEV delta, dual Microsoft zero-days in SharePoint and AD FS, unauthenticated RCE on FortiSandbox and SonicWall SMA1000, and a critical unauthenticated Oracle Payments takeover. Concurrently, the Miasma / Shai-Hulud npm worm lineage delivered a canary wave (miasma-train-p1) abusing trusted CI/CD publishing and valid SLSA provenance.

Top decisions required today

  1. Emergency patch / isolate internet-facing SharePoint, SonicWall SMA1000, FortiSandbox, and Oracle EBS Payments.
  2. Force AD FS DKM ACL audit + identity session/token review.
  3. Lockfile / SBOM sweep for malicious @asyncapi/* versions; rotate secrets on any hit.
  4. Router hygiene sprint per AA26-194A (SNMP / Smart Install / mgmt plane).
  5. Ransomware readiness: immutable backups + restore drill; edge VPN/RDP inventory.

2 · Top threats

#NameRiskBusiness impactWhy today
1Miasma / Shai-Hulud · miasma-train-p110Dev + CI secrets → cloud/identity takeoverValid provenance + on-import RAT
2CVE-2026-58644 SharePoint RCE9On-prem collab compromise; ransomware stagingKEV 16 Jul · CVSS 9.8 · due 19 Jul
3CVE-2026-15409/15410 SonicWall SMA10009Remote foothold → TOTP theft → lateralZero-day · KEV due 17 Jul · CVSS 10.0
4CVE-2026-25089/39808 FortiSandbox9Security appliance RCE; stack pivotKEV 16 Jul · CVSS 9.8 · public PoC
5CVE-2026-46817 Oracle EBS Payments9Unauth takeover of payment processingKEV 15 Jul · due 18 Jul · active since June
6SharePoint auth/deserialization cluster8EoP / RCE on enterprise portalsInternet-facing farms highest risk
7CVE-2026-56155 AD FS DKM ACL8Token-signing key → federated impersonationIdentity control-plane blast radius
8The Gentlemen / Qilin / Akira RaaS8Revenue stop, leak, regulatory exposureContinuous mid-July leak-site claims

Items 1–5 and 8 are bold-priority for ransomware enablement and/or high propagation.

3 · Prioritized action plan (excerpt)

PActionOwnerDeadline
1SharePoint cluster emergency patch & exposure killIT Ops + AppSecT+4h / T+24h / T+72h
2SMA1000 hotfix + compromise-assumption workflowNetwork + SOCT+4h
3Miasma lockfile/SBOM sweep + secret rotationAppSec + Eng + IAMT+4h / T+24h
4FortiSandbox firmware emergencySecEng + NetworkT+24h
5Oracle EBS Payments CPU + network restrictERP + IT OpsT+24h
6AD FS July update + DKM ACL remediationIAM + WindowsT+24h / T+72h
7Router hygiene sprint (AA26-194A)Network EngT+72h
8Immutable backup verify + restore drillIT Ops + CISOT+72h

4 · Limitations

Grounded in tool-verified primary catalogs (KEV CSV), NVD CVSS/SSVC, and multi-source technical reporting collected 2026-07-17. No dark-web access; no fabricated marketplace listings. Exploit code intentionally omitted. Actions are time-bound decision support — verify against your environment before execution.

End of Daily CISO Threat Sweep — 2026-07-17
Product: CISO Advisory · github.com/harlockus/CISO_ADVISORY · portfolio sample · defense only

Architecture & threat model

AppSec Engineer Agent

Repository

01

Operator

CLI text · /file · /image — all treated as untrusted input

02

Hardened client

Input limits · secret redaction · path sandbox · https-only remote · allowlisted RO tools

03

Grok (agentic)

web_search · x_search · sandboxed code_execution · optional MCP

04

Workspace (RO)

read + list only · .env & keys blocked · no shell · no write

Threat model · mitigations

  • Prompt injection via file/web

    Untrusted-content isolation · immutable defensive system policy · no tool that executes attacker intent

  • Secret exfiltration

    Env-only API key · redaction before model I/O · deny list for PEM, kubeconfig, cloud creds, .env

  • Path traversal / workspace escape

    Symlink-aware sandbox rooted at APPSEC_WORKSPACE

  • SSRF via attachments

    https only · block localhost, private, link-local, metadata hosts

  • Model as exploit factory

    Defense-only policy · refuses operational attack code · low temperature for analysis

No LLM agent is mathematically unbreakable. This is defense-in-depth — not a magic shield.

This site

Almost nothing to break.

Same discipline as the agents. Shrink the surface until there is nowhere for an attacker to stand.

Read-only

Static HTML, CSS, JS, one video, one brief. No accounts. No forms. No inbound store.

Outbound only

X, LinkedIn, GitHub leave this origin. Talk dials or copies — nothing is posted here.

Headers

CSP, nosniff, frame-ancestors self, Permissions-Policy off for camera/mic/geo/payment, form-action none.

Not in play

  • Auth / sessions / identity cookies
  • Databases, uploads, webhooks
  • Analytics, pixels, third-party scripts
  • User-generated content

No public site is unbreakable. This one has almost nothing to steal, persist, or execute.

Systems

What I build with code and models

01

Host inspection agent

Grok Inspect: cross-platform collectors + deterministic heuristics + Grok 4.5 high-reasoning CISO briefs. Sniffing surfaces, stealer indicators, malicious presence — read-only, no auto-remediation.

02

AI-led host IDS

Aegis: 30+ host heuristics into Grok 4.5 as lead analyst — kill-chain narratives, forensic capture, calm TUI. Detect + alert under suspected danger only.

03

Agentic AppSec

CLI agents on Grok with tool loops, workspace sandboxes, secret redaction, and prompt-injection resistant control planes.

04

Portfolio SBOM + safe versions

Veracode CycloneDX export for apps and SCA agents, then Component Activity enrichment — remediation-priority CSVs with recommended safe versions. HMAC from .env only. No customer data in the repo.

Stack

Tools of the trade

  • Python
  • SpaceXAI Grok
  • Host inspection
  • Host IDS
  • SBOM / SCA
  • DevSecOps
  • CLI agents

Agents

  • Grok Inspect
  • Aegis · ids_grok
  • CISO Advisory
  • AppSec Engineer Agent

Pipelines

  • SBOM Safe Enrich
  • SBOM → Phylum → PDF
  • Reporting exports

Platform

  • Veracode APIs
  • SpaceXAI Grok · xai-sdk

Connect

Talk. X. LinkedIn. GitHub.

No forms. No inboxes on this site.