Real Incidents, Real Defences

Time to Defence: the public proof our pipeline works.

Real AI agent incidents happen in the wild. We find them, analyse them, work out what Thuban can defend against, and build the rules. The timeline below shows the actual work — and every rule ships only after it independently passes Crucible's adversarial testing, Shield's own attack/benign corpus, and the full test suite. Nothing ships on a hunch, and nothing waits for a human to be reachable.

Incident-driven defence engineering. Every new rule stress-tested before it reaches your machine.

Get Started Free
KEEP YOUR STACK. ADD THUBAN.

This is the number that should matter to every CTO: how long between a new threat appearing anywhere in the world and your systems being protected against it. Ours is measured in minutes, tracked live, and published — not a claim.

Threat Detected → Defence Deployed

The pipeline above, in 30 seconds: Thuban detects an AI threat, processes it, and deploys global defence to every customer.

One pipeline. Every product has a job in it.

Time to Defence isn't a single feature — it's the outcome of every Thuban product working in sequence, from a real-world incident to a defence running on your machine.

Global incident / new AI threat
Occurs
Detects & ingests it
Builds a defence
Tests it under attack
Shield / Scanner / Cost Guard
Receive the update
Time to Defence
Shows the world how fast

Every incident card below is a real, timestamped run through this exact pipeline — not a diagram, a log.

Get Started Free

Your first 30 days of Thuban Individual is free. No card required, just a valid email address.

Shield — 5 Defence Layers

  • File Guard — pre-emptive snapshots, protected paths, overwrite prevention
  • Shadow Realm — sandboxed execution environment
  • Watchers — real-time filesystem monitoring
  • Execution Gate — command validation before execution
  • Audit & Recovery — hash-chained audit trail, instant rollback

Crucible

  • Adversarial mutation testing
  • Verifies defences catch known attack patterns

Scanner

  • All 69 detection rules
  • 10 language support
  • Hallucinated API detection
  • Dependency analysis
  • Trust Score

Forge

  • Builds defensive rules from real-world incidents
  • 5 signed rule packs shipped

Cost Guard NEW

  • Catches unbounded AI/LLM loops before they run away
  • Flags missing output token limits
  • Runs automatically in every scan — no flag needed

Additional

  • Blackbox explainability engine
  • Intelligence threat analysis
  • 8 Advisor modes (roast, rate, boost, risk, trend, benchmark, onboard, compliance)
  • CLI + MCP integration
  • Works with Claude Code, Codex, Cursor, Gemini CLI, any AI coding agent
  • 100% local — your code never leaves your machine
  • Community support

How we build defences.

Nothing ships on a hunch, and nothing waits for a human to be reachable. Every defence on this page goes through the same pipeline:

1

We monitor real-world incidents

News, CVEs, security research papers, and community reports of real AI agent incidents — sandbox escapes, credential theft, supply-chain compromise.

2

We analyse what happened

What attack chain was used, what the agent actually did step by step, and what Thuban could realistically detect or block.

3

Forge drafts a rule

Real YAML rule packs with specific chain-detection logic — matched to the exact sequence of actions seen in the incident.

4

It's proven safe, independently, four times over

Crucible's adversarial mutation testing, Shield's own attack/benign corpus dry-run, and the full test suite (Scanner + Cost Guard regressions included) all have to pass. Any single failure holds the rule — it's retried, never shipped on a guess.

5

It ships the moment it clears every gate

No manual queue, no waiting for someone to be at their desk. The automated test gate is the safety net, not a person's availability.

6

We sign and publish it

Every shipped rule is cryptographically signed and published to every Thuban user.

The defences are real. The incidents are real. The difference between this and a human sitting at a keyboard reviewing each one is that a major incident doesn't have to wait for anyone to be reachable — it has to clear Crucible, Shield's dry-run gate, and the full test suite instead.

Incidents we've responded to.

Each incident below was analysed, reproduced, and defended against. The timeline shows every stage of the work, timestamped using the same DefenceTracker that Thuban runs internally.

Loading incident data…

The signed detection rules we shipped.

Here are the actual rule packs published from the incidents above. Every rule pack is cryptographically signed and verifiable — no black box, no "trust us."

threat-chain-hf-modal.yaml 5 RULES

Chain-detection rules for the HuggingFace/Modal Labs incident: sandbox escape, credential harvest, infrastructure assembly, privilege escalation, and full-campaign detection.

threat-pack-hermes-2026-07.yaml 3 RULES

Detection rules modelled on the Hermes / Thailand Ministry of Finance intrusion — credential exfiltration chains and suspicious YOLO-mode agent enumeration.

cloud-metadata-k8s-recon.yaml RULE PACK

Cloud metadata service and Kubernetes reconnaissance detection — catching agents probing for instance credentials or cluster secrets.

behavioural-chains.yaml RULE PACK

Behavioural anomaly chain detection — flags sequences of individually-plausible actions that together indicate compromise.

built-in-protections.yaml CORE

The core Shield protections every Thuban install ships with by default.

These rule packs ship as part of the Thuban Shield package, available via npm.

Time to Defence = signed release − detection.

Publishing to this dashboard happens after the fact — it's a distribution step, not part of the clock. The stopwatch starts the moment an incident is detected and stops the moment a Crucible-and-Shield-tested defence is signed and releasable. See the full nine-stage pipeline on the Forge page.

One clock. Every incident. No hiding a slow response.

Whether it's rendered on a SOC command wall or a laptop in a normal office, the same countdown clock — DETECT, VERIFY, BUILD, TEST, DEPLOY — is ticking on every incident Forge processes.

The Countdown in a minimalist office environment — the same Time to Defence clock with DEPLOY, DETECT, VERIFY, BUILD and TEST ring segments and a TTD history timeline at the bottom
Why Time to Defence?

Forget the 45-day industry average.

No hype, just data — real incidents, hardened in the Crucible, published for anyone to check.

Real incidents. Real results. — 4h 2m average Time to Defence across five incidents processed, no hype just data, Thuban TTD campaign header
Hardened in the Thuban Crucible — 515 adversarial mutations, mission-critical safety, Thuban TTD campaign header
Outpace the 45-day average — traditional scanners are too slow, Thuban intercepts before disk, Thuban TTD campaign header
Defend your code in 4 hours — forget the 45-day industry average, real-time defence, Thuban TTD campaign header

Protect your codebase in the next 60 seconds.

No install, no config files, no signup required.

$ npx thuban shield init

Click to copy

New to Thuban? Read the full Getting Started Guide.

Thuban Help
Ask a question or pick a topic below.