// Twice-monthly · defense only

The Agentic AI Defender

Practical defenses for agentic workflows, informed by real-world deployments.

The Agentic AI Defender is a twice-monthly publication for professionals securing AI in production environments. Each issue addresses a complex agentic AI security challenge and delivers actionable controls, such as detection rules, IR runbooks, schemas, and hardening checklists, that you can implement immediately. All content is based on anonymized real-world deployments rather than theoretical guidance.

$7.99 / month · cancel anytime

detection-engineering.pdf

Quarterly

Threat Landscape Report

agent stack · 15 rules

exfiltration.runbook.md

IR RUNBOOK

detection.yml

SIGMA RULE

// What is inside

Controls you can deploy, not concepts to admire

Every issue ships with downloadable artifacts you can adapt to your environment.

01

Twice-monthly issues for practitioners.

02

Full deep-dive playbooks and IR runbooks.

03

Agentic AI mitigation frameworks, including configuration guidance.

04

Real anonymized deployment case studies.

05

Detection engineering you can deploy today.

06

Retrieval and corpus governance.

07

Agent identity and access management.

08

Drift and vendor change response.

// Coverage

The full agent stack, end to end

Coverage includes the full agent stack, from the tools a model can reach to the supply chain behind the model itself.

MCP and tool-surface hardeningRetrieval and RAG governanceAgent identity and certificate managementApproval-queue and tool-call admission controlDetection engineeringModel promotion governanceMedia genuineness and deepfake preventionAI supply chain integrity

This publication focuses exclusively on defense tactics and does not cover offensive tools or exploit walkthroughs. It is designed for security and detection engineers, IR responders, ML platform leads, and governance leaders.

// Sample issue

See what an issue looks like

A tactical issue built around one problem, one set of controls, and the artifacts to run them.

the-agentic-ai-defender / issue

The retrieval ledger every RAG deployment needs

Tactical issue · Pillar: Retrieval and corpus governance · Includes: Schema (YAML), 3 detection rules, runbook template

If your RAG corpus is exfiltrated, the retrieval ledger defines the scope of exposure. Without it, you cannot determine what was accessed or what was taken.

Sections in this issue

  • What a retrieval ledger captures (15 fields)
  • Permission-aware enrichment
  • Tier-marking integration
  • Detection rules built on the ledger
  • IR runbook for exfiltration
  • Building incrementally vs all at once

Artifact: Retrieval ledger schema (YAML), three detection rules, and a RAG exfiltration runbook template.

// Fit check

Is this for you?

The Agentic AI Defender is for people who need practical, step-by-step guidance they can use right away. Specifically:

  • Senior Security Engineers and Detection Engineers writing detections for AI workflows.
  • IR Responders extending runbooks for AI incident classes.
  • ML Platform Leads and MLOps Engineers adding security capability to AI infrastructure.
  • AI Security Leads building or running defensive programs.
  • Security Architects designing AI-aware controls.

Honest exclusions

  • ×If you are just starting out in security operations, this may be too advanced. Try the free AI IR Overlay newsletter on LinkedIn, or start with a foundational security course.
  • ×If you are looking for offensive AI security content, this is defense only. Look at OffSec's AI-300 or other offensive programs instead.
  • ×If you want vendor-specific tutorials, this content focuses on frameworks that work across many vendors.
  • ×If you are after academic AI safety research, note this resource is about real-world operations, not theory.

// About the author

Written by a practitioner, from real work

JI

Jacob Ideji is a cybersecurity practitioner and architect with more than a decade of experience in the field, and he has built some of the most secure environments in the world. For the past few years, he has focused on turning his experience into practical advice for AI.

He co-authored the Field Manual for Cyber Incident Handling and Response, a go-to guide for professionals. In the last 18 months, he has published 24 issues in one free newsletter, AI IR Overlay, sharing his hands-on IR experience for AI security. The Agentic AI Defender is his paid Substack, where he goes deeper than in the free newsletter. Subscribers get useful tips, detection rules, runbook templates, and configuration patterns, all based on real experience.

// The Agentic AI Defender

Get practical solutions for agentic workflows, based on real-world experience.

Twice-monthly issues, deployable artifacts, and anonymized deployment case studies for the people defending AI in production.

Subscribe for $7.99/month