Aegis: a security triage agent that remembers human analyst decisions, not just events
Healthy_Baseball_440 · reddit · 2026-09-28
A Reddit writeup details Aegis, a memory-powered account takeover triage agent:
- Problem: Security teams face thousands of auth alerts (failed-login bursts, unfamiliar networks, new devices); most systems treat each as new.
- Key design: Instead of just asking "does this look suspicious?", Aegis asks "have we seen this before, and what did a human conclude?" Using Hindsight as its memory layer, it trusts only confirmed analyst decisions — similarity alone isn't evidence. Loop: alert → investigation → human decision → memory → better future investigations.
- Honest memory: Recalled records are grouped into patterns (credential stuffing, impossible travel, etc.); "unlinked records" lacking case IDs are surfaced explicitly, showing the quality of the memory rather than hiding gaps.
- No bare similarity scores: Instead of "92% similar", it explains why a recalled case matters — same account, matching failed-login pattern, prior benign verdict, no containment taken. E.g., 22 failed logins followed by success looks alarming until a prior benign ruling on the same account is recalled.
Related event: Student Team Shares Design Lessons from Security Triage Agent Aegis(2 posts)→
More from coding & agent
- ZergRouter launches: one dashboard to route models and track spend across multiple coding agents — idanbeck · 2026-09-29
- WebMCP lands everywhere in one morning: Meta wearables, Shopify checkout, Cloudflare — jeff_weinstein · 2026-09-29
- A 9-feature roadmap for building AI agents with Claude Code, from CLAUDE.md to MCP — MaryamMiradi · 2026-09-29
- Zeeg: Paper won't work with WSL, seeking structured visual design agent workflows — zeeg · 2026-09-29
- OriginTrail ships DKG V10.0.19 on mainnet for faster AI agent context graphs — melnykowycz · 2026-09-29
- Models don't have agency, systems do: how shaped tokens become function calls — sethjuarez · 2026-09-29