AEGIS / A defensive extension of Atlas

The defender on your side of the door.

I am extending Atlas into AEGIS, an on-prem defensive project that reads existing security signals, recognizes an intrusion, and contains it inside the authorized estate.

Atlas extensionAuthorized networksOn-prem deploymentEvidence-bearing response
“Authorized perimeter defense:
detect intrusion, contain session, preserve evidence.
Decisive policy containment inside the wire.”

The architecture

The network is the house.

Data, payroll, source code, models, and trade secrets live behind the same boundary. AEGIS treats that boundary like a house: watch the door, recognize unauthorized access, isolate sessions, and preserve forensic trails for incident teams.

Early internal lore summarized the operating posture as “You touchy, I knock you out.” In production, that means deterministic policy containment: verified allow-lists, session revocation, human escalation gates, and forensic audit preservation.

The response path

See the play. Close the path. Keep the proof.

AEGIS sits above existing sensors and controls. The sequence stays short, inspectable, and bounded to the operator's authority.

  1. 01

    Observe

    Watch the house

    Read the IDS, DNS, identity, endpoint, and firewall signals already present in the security path.
  2. 02

    Recognize

    Name the intrusion

    Correlate attacker behavior across sensors, separate routine noise from a break-in, and state the risk in plain language.
  3. 03

    Contain

    End the session

    Choose one tested action inside the authorized estate: cut the session, isolate the host, block the path, or revoke the token.
  4. 04

    Preserve

    Keep the trail

    Record the signal, decision, action, time, and result for the incident team.

One decisive action

Cut the session. Isolate the host. Close the door. Keep the evidence.

That is the knockout: the intruder loses access to this house, while the operator retains the systems, the authority, and the trail.

Terminate sessionIsolate hostBlock pathRevoke tokenPreserve trail

Training evidence / August 20, 2026

The first AEGIS adapter has a real receipt.

59/62Frozen suite result

A Grok-led training session continued the Devstral atlas-tools lineage into a rank-16 AEGIS LoRA. The run used one epoch at a 5e-6 learning rate on the Devstral-Small-2-24B-Instruct-abliterated base, then evaluated the vaulted adapter against the project's frozen 62-case suite.

Tool use

45/45100%

Coding

8/1080%

Science

3/475%

Cyber

3/3100%

The three visible misses

  • JSONL parsing produced an indentation error.
  • POSIX path joining missed a slash-normalization case.
  • The RC science answer missed the required target.

Current artifact state

The unmerged LoRA adapter is sealed in the Pi vault and recorded in a private model repository at 23:00 UTC.

The authority line

The fight ends at the door.

AEGIS studies attacker behavior so it can close the path inside the authorized estate. The operator owns the policy, the automated allow-list, and every escalation decision.

Authorized estate

Every automated action targets systems, devices, accounts, and sessions under the operator's authority.

Tested actions

Containment relies on pre-cleared, bounded operations: revoke token, isolate host, block IP, terminate session.

Human escalation

Novel attack patterns, uncertain attribution, or production-impacting cuts escalate to human incident responders.

Forensic preservation

Every observation, decision, and intervention generates a timestamped, signed receipt for forensic review.

Current state

A trained adapter and a documented evaluation.

The August 20 adapter and its 59/62 frozen-suite result establish the first AEGIS model milestone.

Inspect AEGIS frozen evaluation record in the Evidence Hub

Walk the journey

Put a defender on your side of the door. If they come in, put them out on your wire and keep the house.