IA × IA
Looking for ideas for your own defense playbooks? Start with the success stories already in production.
Machine-speed attacks call for machine-speed defense. This guide shows, through success stories in production and playbooks you can adapt, how AI can detect, decide and act on defense, always stating how far it is allowed to go and under which controls. Free, vendor-neutral, and ready to drop into your AI.

Decide.
Act.
In production.
Implementations that have left the slide deck behind. This is where architecture, decisions, guardrails, evidence and the lessons that don't fit on a slide come in.
Take them all to my AI, in Markdown →
Cyberbot
An agent reads the traffic that got past the WAF, receives structured context, classifies the threat, and only turns a decision into an action after it clears the guardrails.
Contextual anti-fraud
The engine correlates device, network, history and behavior. The gain isn't a new rule. It's finding relationships that only emerge across different sources, and repeating that investigation at scale.
Adapt to your environment.
Architectures ready to become an experiment in your environment. They are labeled as playbooks so a proposal is never mistaken for a case in production.
Build your playbook from these →
Agentic SOC
Use agents first to cut repetitive work, then to investigate, and only then grant limited containment authority.
Continuous red team
An annual pentest goes stale on the next deploy. Agents can continuously validate the attack surface, changes and authorized attack paths.
AppSec in the pipeline
The agent doesn't have to stop at the finding. It can prepare the patch and the tests, leaving the review and the merge to a human.
Brand and identity
New domains tied to campaigns and major brands show up in high volume. The challenge is separating signal from noise, prioritizing risk, and turning a confirmed detection into action.
Agent supervisor
An operator agent investigates with broad context and proposes an action. A deliberately limited supervisor evaluates the request. A Policy Engine applies the objective rules before anything executes.
Build your own playbook
Pick the challenge, check the signals you already have and the actions you would be willing to delegate. Out comes a playbook in Markdown, with an authority matrix and an agent badge, to discuss with your team or paste into your AI.
Notes from someone in the game.
Short articles on what changes in defense when the attack runs at machine speed. Each one also exists in Markdown, ready to take to your AI.
All articles →
Materials by event.
Each PDF is tied to the specific presentation. That way new talks and new versions land here without getting mixed into the case library.
Want a talk on this at your event? →
IA × IA · TI Exames
Security in the age of agents. Attack and defense have changed three times while you were reading this title. Class-format version, with more time for architecture, authority and controls.
IA × IA · Mind The Sec 2026
Security in the age of agents. Attack and defense have changed three times while you were reading this title.
A talk, class or panel on AI applied to defense, with the cases from this guide and the parts that still don't fit on a slide. Tell me about the event and I'll get back to you.