How Thuban turns real-world AI incidents into verified endpoint protection at machine speed.
This is not AI reading the news. It is a controlled machine-speed security research pipeline — every step logged, every step gated.
A report, advisory or disclosure enters the system from a source with a known trust tier.
The source is classified against the trust tiers before anything else happens.
Independent confirmation is required. One unverified post never moves the pipeline forward alone.
Forge attempts to reproduce the incident in isolation — no production access, no live credentials.
A candidate protection rule is drafted. It is an untrusted artefact, not a shipped fix.
The candidate is thrown against adversarial variants to see if it actually holds up.
The candidate must not break existing protections or legitimate workflows.
A person signs off. The machine does not mark its own homework.
Only now does the protection cross the release boundary and reach your machine.
Every signal entering Forge is classified before it can influence anything.
Vendor advisories, CVE/NVD, CISA, OWASP, NIST, maintainer disclosures, peer-reviewed research.
Established cybersecurity publications, named researchers with evidence, major news organisations, IR company reports.
Social posts, forums, anonymous claims, blogs without technical evidence, auto-generated summaries.
Tier 3 can trigger research. It can NEVER trigger protection.
A malicious actor should not be able to invent a story and cause Thuban to block legitimate commands across thousands of machines.
Forge is treated as a potentially hostile research laboratory. Generated protections are untrusted artefacts until they cross the release boundary.
Confidence determines action. Nothing gets blocked on a hunch.
Unconfirmed or poorly documented reports: add telemetry, increase logging, create research tasks. Do not block anything.
Credible but incomplete threats: alert user, require approval, offer temporary high-security mode, add expiring narrow rules.
Reproducible high-confidence threats: ship signed enforcement rules, record Crucible test results, provide rollback and compatibility data.
A worked example of what a real Forge run will show on the dashboard.
No install, no config files, no signup required.
$ npx thuban shield init
Click to copy