Real AI agent incidents happen in the wild. We find them, analyse them, work out what Thuban can defend against, and build the rules. The timeline below shows the actual work — and every rule ships only after it independently passes Crucible's adversarial testing, Shield's own attack/benign corpus, and the full test suite. Nothing ships on a hunch, and nothing waits for a human to be reachable.
Incident-driven defence engineering. Every new rule stress-tested before it reaches your machine.
This is the number that should matter to every CTO: how long between a new threat appearing anywhere in the world and your systems being protected against it. Ours is measured in minutes, tracked live, and published — not a claim.
The pipeline above, in 30 seconds: Thuban detects an AI threat, processes it, and deploys global defence to every customer.
Time to Defence isn't a single feature — it's the outcome of every Thuban product working in sequence, from a real-world incident to a defence running on your machine.
Every incident card below is a real, timestamped run through this exact pipeline — not a diagram, a log.
Your first 30 days of Thuban Individual is free. No card required, just a valid email address.
Nothing ships on a hunch, and nothing waits for a human to be reachable. Every defence on this page goes through the same pipeline:
News, CVEs, security research papers, and community reports of real AI agent incidents — sandbox escapes, credential theft, supply-chain compromise.
What attack chain was used, what the agent actually did step by step, and what Thuban could realistically detect or block.
Real YAML rule packs with specific chain-detection logic — matched to the exact sequence of actions seen in the incident.
Crucible's adversarial mutation testing, Shield's own attack/benign corpus dry-run, and the full test suite (Scanner + Cost Guard regressions included) all have to pass. Any single failure holds the rule — it's retried, never shipped on a guess.
No manual queue, no waiting for someone to be at their desk. The automated test gate is the safety net, not a person's availability.
Every shipped rule is cryptographically signed and published to every Thuban user.
The defences are real. The incidents are real. The difference between this and a human sitting at a keyboard reviewing each one is that a major incident doesn't have to wait for anyone to be reachable — it has to clear Crucible, Shield's dry-run gate, and the full test suite instead.
Each incident below was analysed, reproduced, and defended against. The timeline shows every stage of the work, timestamped using the same DefenceTracker that Thuban runs internally.
Loading incident data…
Here are the actual rule packs published from the incidents above. Every rule pack is cryptographically signed and verifiable — no black box, no "trust us."
threat-chain-hf-modal.yaml
5 RULES
Chain-detection rules for the HuggingFace/Modal Labs incident: sandbox escape, credential harvest, infrastructure assembly, privilege escalation, and full-campaign detection.
threat-pack-hermes-2026-07.yaml
3 RULES
Detection rules modelled on the Hermes / Thailand Ministry of Finance intrusion — credential exfiltration chains and suspicious YOLO-mode agent enumeration.
cloud-metadata-k8s-recon.yaml
RULE PACK
Cloud metadata service and Kubernetes reconnaissance detection — catching agents probing for instance credentials or cluster secrets.
behavioural-chains.yaml
RULE PACK
Behavioural anomaly chain detection — flags sequences of individually-plausible actions that together indicate compromise.
built-in-protections.yaml
CORE
The core Shield protections every Thuban install ships with by default.
These rule packs ship as part of the Thuban Shield package, available via npm.
Publishing to this dashboard happens after the fact — it's a distribution step, not part of the clock. The stopwatch starts the moment an incident is detected and stops the moment a Crucible-and-Shield-tested defence is signed and releasable. See the full nine-stage pipeline on the Forge page.
Whether it's rendered on a SOC command wall or a laptop in a normal office, the same countdown clock — DETECT, VERIFY, BUILD, TEST, DEPLOY — is ticking on every incident Forge processes.
No hype, just data — real incidents, hardened in the Crucible, published for anyone to check.
No install, no config files, no signup required.
$ npx thuban shield init
Click to copy
New to Thuban? Read the full Getting Started Guide.