IA × IA Project · Field Guide

IA × IA

Looking for ideas for your own defense playbooks? Start with the success stories already in production.

Machine-speed attacks call for machine-speed defense. This guide shows, through success stories in production and playbooks you can adapt, how AI can detect, decide and act on defense, always stating how far it is allowed to go and under which controls. Free, vendor-neutral, and ready to drop into your AI.

It has already become code: Cyberbot was built by someone who watched the talk, walked out and shipped the idea. From log to block in under a minute, in production. Why this project exists →
Rodrigo JorgeCISO at Strattum AI, founder of HumanConf. A living reference on AI applied to security, with cases, architectures, lessons learned and talk materials.
Last updated: Oct 6, 2026
Rodrigo Jorge, CISO at Strattum AI and author of the IA × IA Project
Detect.
Decide.
Act.
Open this guide in your AIChatGPTClaudePerplexityCopilotGrok
1. I have a challengeStart with the success stories in production and the defense playbooks you can adapt. Each one covers architecture, delegated authority and controls.See the guide →
2. I want to build my own playbookPick the challenge, the signals you have, and the actions you would be willing to delegate. The generator returns a playbook in Markdown to discuss with your team or paste into your AI.Build your playbook →
3. I want to use it in my AIEvery case and every playbook exists in Markdown, and the whole guide fits in one file. The buttons above open your AI with the prompt ready; or paste the .md into your agent.What this guide is, as .md →
Defense playbooks

Adapt to your environment.

Architectures ready to become an experiment in your environment. They are labeled as playbooks so a proposal is never mistaken for a case in production.
Build your playbook from these →

PLAYBOOK
03

Agentic SOC

Triage → investigation → containment.

Use agents first to cut repetitive work, then to investigate, and only then grant limited containment authority.

SOCInvestigationResponse
3 levelsof autonomy progression
PLAYBOOK
04

Continuous red team

Trade the annual snapshot for a permanent test.

An annual pentest goes stale on the next deploy. Agents can continuously validate the attack surface, changes and authorized attack paths.

Red TeamExposureValidation
365 daysof continuous testing
PLAYBOOK
05

AppSec in the pipeline

Found it. Fixed it. Tested it. Committed it.

The agent doesn't have to stop at the finding. It can prepare the patch and the tests, leaving the review and the merge to a human.

AppSecCodeDevSecOps
PRas the unit of delivery
PLAYBOOK
06

Brand and identity

Contextual triage at scale, with the takedown ready to go.

New domains tied to campaigns and major brands show up in high volume. The challenge is separating signal from noise, prioritizing risk, and turning a confirmed detection into action.

BrandFraudTakedown
18,000domains tied to Black Friday and major brands in a single month
PLAYBOOK
07

Agent supervisor

More intelligence in the operator. Less power in whoever authorizes.

An operator agent investigates with broad context and proposes an action. A deliberately limited supervisor evaluates the request. A Policy Engine applies the objective rules before anything executes.

AgentsGovernanceAutonomyPolicy Engine
3 layersinvestigate, authorize and execute
BUILD YOUR OWN
+

Build your own playbook

Challenge, signals and authority, in your environment.

Pick the challenge, check the signals you already have and the actions you would be willing to delegate. Out comes a playbook in Markdown, with an authority matrix and an agent badge, to discuss with your team or paste into your AI.

GeneratorMarkdownNo AI in the loop
2 minto the first draft
Detect · decide · act · within limits
Articles

Notes from someone in the game.

Short articles on what changes in defense when the attack runs at machine speed. Each one also exists in Markdown, ready to take to your AI.
All articles →

Whoever fixes it wins the race

The race isn't about detection. It's about remediation, and the scoreboard is the time between a flaw showing up and ceasing to exist.

Oct 8, 2026 · Essay
Talks

Materials by event.

Each PDF is tied to the specific presentation. That way new talks and new versions land here without getting mixed into the case library.
Want a talk on this at your event? →

IA × IA · TI Exames

Security in the age of agents. Attack and defense have changed three times while you were reading this title. Class-format version, with more time for architecture, authority and controls.

Sep 21, 2026 · 7:30–9:00 PMFree class with certificatedeck v1.1
Download PDF

IA × IA · Mind The Sec 2026

Security in the age of agents. Attack and defense have changed three times while you were reading this title.

Sep 15, 2026São Paulo · Kevin Mitnick Room
Download PDF
Want a talk on this at your event?

A talk, class or panel on AI applied to defense, with the cases from this guide and the parts that still don't fit on a slide. Tell me about the event and I'll get back to you.

Request a talkRodrigo Jorge