// Twice-monthly · defense only
The Agentic AI Defender
Practical defenses for agentic workflows, informed by real-world deployments.
The Agentic AI Defender is a twice-monthly publication for professionals securing AI in production environments. Each issue addresses a complex agentic AI security challenge and delivers actionable controls, such as detection rules, IR runbooks, schemas, and hardening checklists, that you can implement immediately. All content is based on anonymized real-world deployments rather than theoretical guidance.
$7.99 / month · cancel anytime
Quarterly
Threat Landscape Report
agent stack · 15 rules
IR RUNBOOK
SIGMA RULE
// What is inside
Controls you can deploy, not concepts to admire
Every issue ships with downloadable artifacts you can adapt to your environment.
Twice-monthly issues for practitioners.
Full deep-dive playbooks and IR runbooks.
Agentic AI mitigation frameworks, including configuration guidance.
Real anonymized deployment case studies.
Detection engineering you can deploy today.
Retrieval and corpus governance.
Agent identity and access management.
Drift and vendor change response.
// Coverage
The full agent stack, end to end
Coverage includes the full agent stack, from the tools a model can reach to the supply chain behind the model itself.
This publication focuses exclusively on defense tactics and does not cover offensive tools or exploit walkthroughs. It is designed for security and detection engineers, IR responders, ML platform leads, and governance leaders.
// Sample issue
See what an issue looks like
A tactical issue built around one problem, one set of controls, and the artifacts to run them.
The retrieval ledger every RAG deployment needs
Tactical issue · Pillar: Retrieval and corpus governance · Includes: Schema (YAML), 3 detection rules, runbook template
If your RAG corpus is exfiltrated, the retrieval ledger defines the scope of exposure. Without it, you cannot determine what was accessed or what was taken.
Sections in this issue
- •What a retrieval ledger captures (15 fields)
- •Permission-aware enrichment
- •Tier-marking integration
- •Detection rules built on the ledger
- •IR runbook for exfiltration
- •Building incrementally vs all at once
Artifact: Retrieval ledger schema (YAML), three detection rules, and a RAG exfiltration runbook template.
// Fit check
Is this for you?
The Agentic AI Defender is for people who need practical, step-by-step guidance they can use right away. Specifically:
- Senior Security Engineers and Detection Engineers writing detections for AI workflows.
- IR Responders extending runbooks for AI incident classes.
- ML Platform Leads and MLOps Engineers adding security capability to AI infrastructure.
- AI Security Leads building or running defensive programs.
- Security Architects designing AI-aware controls.
Honest exclusions
- ×If you are just starting out in security operations, this may be too advanced. Try the free AI IR Overlay newsletter on LinkedIn, or start with a foundational security course.
- ×If you are looking for offensive AI security content, this is defense only. Look at OffSec's AI-300 or other offensive programs instead.
- ×If you want vendor-specific tutorials, this content focuses on frameworks that work across many vendors.
- ×If you are after academic AI safety research, note this resource is about real-world operations, not theory.
// About the author
Written by a practitioner, from real work
Jacob Ideji is a cybersecurity practitioner and architect with more than a decade of experience in the field, and he has built some of the most secure environments in the world. For the past few years, he has focused on turning his experience into practical advice for AI.
He co-authored the Field Manual for Cyber Incident Handling and Response, a go-to guide for professionals. In the last 18 months, he has published 24 issues in one free newsletter, AI IR Overlay, sharing his hands-on IR experience for AI security. The Agentic AI Defender is his paid Substack, where he goes deeper than in the free newsletter. Subscribers get useful tips, detection rules, runbook templates, and configuration patterns, all based on real experience.
// The Agentic AI Defender
Get practical solutions for agentic workflows, based on real-world experience.
Twice-monthly issues, deployable artifacts, and anonymized deployment case studies for the people defending AI in production.
Subscribe for $7.99/month