The Forge Pipeline

Shield enforces. Forge learns. Crucible proves. Blackbox explains.

This is a working pipeline, not a roadmap slide. A threat report comes in, Forge analyses the coverage gap, generates a Shield rule, and throws it into the Crucible. No defence ships without proof it works.

Real-time agent monitoring. Incident-driven defence generation. Every new rule stress-tested before it reaches your machine.

Terminal

  
Get Started Free
KEEP YOUR STACK. ADD THUBAN.

When a new AI-agent attack pattern shows up anywhere in the world, Forge builds a defence for it automatically, hours after detection — not months after your vendor's next release. Every rule is signed, tested, and shipped without waiting on a human.

Get Started Free

Your first 30 days of Thuban Individual is free. No card required, just a valid email address.

Shield — 5 Defence Layers

  • File Guard — pre-emptive snapshots, protected paths, overwrite prevention
  • Shadow Realm — sandboxed execution environment
  • Watchers — real-time filesystem monitoring
  • Execution Gate — command validation before execution
  • Audit & Recovery — hash-chained audit trail, instant rollback

Crucible

  • Adversarial mutation testing
  • Verifies defences catch known attack patterns

Scanner

  • All 69 detection rules
  • 10 language support
  • Hallucinated API detection
  • Dependency analysis
  • Trust Score

Forge

  • Builds defensive rules from real-world incidents
  • 5 signed rule packs shipped

Cost Guard NEW

  • Catches unbounded AI/LLM loops before they run away
  • Flags missing output token limits
  • Runs automatically in every scan — no flag needed

Additional

  • Blackbox explainability engine
  • Intelligence threat analysis
  • 8 Advisor modes (roast, rate, boost, risk, trend, benchmark, onboard, compliance)
  • CLI + MCP integration
  • Works with Claude Code, Codex, Cursor, Gemini CLI, any AI coding agent
  • 100% local — your code never leaves your machine
  • Community support

Nine steps between a headline and a signed release.

This is not AI reading the news. It is a controlled machine-speed security research pipeline — every step logged, every step gated.

1

Signal appears

A report, advisory or disclosure enters the system from a source with a known trust tier.

2

Provenance checked

The source is classified against the trust tiers before anything else happens.

3

Corroborated

Independent confirmation is required. One unverified post never moves the pipeline forward alone.

4

Safely reproduced

Forge attempts to reproduce the incident in isolation — no production access, no live credentials.

5

Defence generated

A candidate protection rule is drafted. It is an untrusted artefact, not a shipped fix.

6

Attacked by Crucible

The candidate is thrown against adversarial variants to see if it actually holds up.

7

Regression tested

The candidate must not break existing protections or legitimate workflows.

8

Human approved

A person signs off. The machine does not mark its own homework.

9

Signed release

Only now does the protection cross the release boundary and reach your machine.

Not every report is equal.

Every signal entering Forge is classified before it can influence anything.

TIER 1 · AUTHORITATIVE

Vendor advisories, CVE/NVD, CISA, OWASP, NIST, maintainer disclosures, peer-reviewed research.

TIER 2 · REPUTABLE

Established cybersecurity publications, named researchers with evidence, major news organisations, IR company reports.

TIER 3 · UNVERIFIED

Social posts, forums, anonymous claims, blogs without technical evidence, auto-generated summaries.

Tier 3 can trigger research. It can NEVER trigger protection.

One invented story cannot become a protection rule.

A malicious actor should not be able to invent a story and cause Thuban to block legitimate commands across thousands of machines.

One reputable story
Observe
Multiple independent credible sources
Investigate
Vendor advisory or successful reproduction
Generate candidate defence
Crucible + Shield + Scanner + Cost Guard all pass
Release

Even Thuban's own AI is not trusted by default.

Forge is treated as a potentially hostile research laboratory. Generated protections are untrusted artefacts until they cross the release boundary.

Autonomous Anvil assembly line rendering candidate defences stage by stage inside an isolated research laboratory
NO signing keys
NO deployment credentials
NO customer secrets
NO write access to main repo

Not every threat gets the same response.

Confidence determines action. Nothing gets blocked on a hunch.

OBSERVE

Unconfirmed or poorly documented reports: add telemetry, increase logging, create research tasks. Do not block anything.

WARN

Credible but incomplete threats: alert user, require approval, offer temporary high-security mode, add expiring narrow rules.

BLOCK

Reproducible high-confidence threats: ship signed enforcement rules, record Crucible test results, provide rollback and compatibility data.

The public proof that machine-speed defence works.

A real trip through the Forge pipeline, timestamped stage by stage.

Global threat map monitors behind the Autonomous Anvil, tracking incidents feeding the Time to Defence countdown
Incident published08:10
Reproduced09:04
186 variants tested10:22
Protection approved11:47
Signed update released12:02
Time to Defence3h 52m

See the live Time to Defence dashboard →

Protect your codebase in the next 60 seconds.

No install, no config files, no signup required.

$ npx thuban shield init

Click to copy

New to Thuban? Read the full Getting Started Guide.

Thuban Help
Ask a question or pick a topic below.