AI risk
AI security systems
How agents use tools, move meaning, expose data, and fail when people trust automation too much.
S6 studies AI agents, automation, SaaS control planes, SOC workflows, Splunk operations, and cyber harm. We publish what we can, test ideas in real systems, and turn useful findings into defensive tools.
current focus
Useful research, not theatre
Research that names the trade-offs
Tools built from real operational pain
Plain guidance for people under pressure
Private handling for capability that can be abused
plain version
We help people understand what is real, what is risky, and what is worth building next.
What S6 works on
The work spans research, public guidance, controlled product builds, and private capability that needs careful handling.
AI risk
How agents use tools, move meaning, expose data, and fail when people trust automation too much.
Security operations
Cleaner log data, better triage, source evidence, SC4S workflows, and fewer wasted analyst cycles.
Public good
Practical guidance, safer learning, and tooling that helps people reduce risk before recovery becomes painful.
Emerging threat research
This is where S6 watches new attacker behaviour, AI-enabled failure modes, public-source exposure, and SOC coverage gaps. The output is plain research, defensive guidance, and careful handoff into products only when that is safe.
Read emerging researchResearch lane 01
How agents, plugins, OAuth scopes, workspace integrations, and SaaS automation can turn small trust mistakes into broad exposure.
Research lane 02
Research into documents, metadata, misconfigured stores, and accidental public signals — handled with suppression and human review gates.
Research lane 03
Emerging attacker behaviour mapped back to log-source quality, parser coverage, dashboard evidence, and what analysts can actually verify.
Research lane 04
Practical threat research for families, creators, and smaller teams who inherit enterprise-style risk without enterprise support.
Product stack
SecHub, SC4S Manager, the SC4S Source Library, and cyber learning games can be discussed plainly. Sensitive OSINT and offensive automation stay invite-only or private because misuse risk is not theoretical.
View the product stack01
Follow evidence before it becomes a tidy product claim.
02
Build small proofs that show what a control can and cannot see.
03
Write the useful parts clearly enough for someone else to check.
04
Turn durable findings into better architectures, workflows, detections, and tools.
Start with the work
The useful conversations start with a field note, a lab, a technical question, or an operational constraint. Preferably more than one.