<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: adithya9666</title>
    <description>The latest articles on DEV Community by adithya9666 (@adithya9666).</description>
    <link>https://dev.to/adithya9666</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4147924%2Fae0fe40e-6a07-4940-a3d9-0eef496b4870.png</url>
      <title>DEV Community: adithya9666</title>
      <link>https://dev.to/adithya9666</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/adithya9666"/>
    <language>en</language>
    <item>
      <title>I Built an AI Security Assistant That Remembers Previous Investigations</title>
      <dc:creator>adithya9666</dc:creator>
      <pubDate>Mon, 28 Sep 2026 19:37:36 +0000</pubDate>
      <link>https://dev.to/adithya9666/i-built-an-ai-security-assistant-that-remembers-previous-investigations-hg4</link>
      <guid>https://dev.to/adithya9666/i-built-an-ai-security-assistant-that-remembers-previous-investigations-hg4</guid>
      <description>&lt;p&gt;Security alerts are rarely completely new.&lt;/p&gt;

&lt;p&gt;A security analyst might see dozens of failed-login alerts, suspicious IP addresses, unusual data transfers, or large file movements. Many of these incidents resemble cases the team has already investigated.&lt;/p&gt;

&lt;p&gt;The problem is that a typical LLM starts each analysis from scratch.&lt;/p&gt;

&lt;p&gt;It can understand the alert in front of it, but it doesn't automatically know how the security team handled a similar incident last week.&lt;/p&gt;

&lt;p&gt;I built ThreatMemory to explore a different approach: an AI security alert triage assistant with persistent memory.&lt;/p&gt;

&lt;p&gt;The key idea is simple:&lt;/p&gt;

&lt;p&gt;Instead of only asking an AI what it thinks about an alert, let it remember what the security team learned from previous alerts.&lt;/p&gt;

&lt;p&gt;The problem with stateless alert analysis&lt;/p&gt;

&lt;p&gt;Consider a security alert like this:&lt;/p&gt;

&lt;p&gt;36 failed authentication attempts against &lt;a href="mailto:payroll@company.com"&gt;payroll@company.com&lt;/a&gt; from IP 185.20.4.21 between 01:50 AM and 02:05 AM.&lt;/p&gt;

&lt;p&gt;A normal AI assistant can analyze the information contained in that alert.&lt;/p&gt;

&lt;p&gt;It might identify several possibilities:&lt;/p&gt;

&lt;p&gt;A legitimate employee repeatedly entering the wrong password&lt;br&gt;
A VPN-related authentication problem&lt;br&gt;
A brute-force attempt&lt;br&gt;
Credential stuffing&lt;br&gt;
A compromised device&lt;/p&gt;

&lt;p&gt;Without additional context, the AI has no way to know how this organization's security team handled similar events previously.&lt;/p&gt;

&lt;p&gt;That means every alert becomes a new investigation.&lt;/p&gt;

&lt;p&gt;ThreatMemory adds a memory layer to this process.&lt;/p&gt;

&lt;p&gt;The architecture&lt;/p&gt;

&lt;p&gt;The application has three main components:&lt;/p&gt;

&lt;p&gt;Security analyst → ThreatMemory → Hindsight + LLM&lt;/p&gt;

&lt;p&gt;The workflow is:&lt;/p&gt;

&lt;p&gt;The analyst provides a security alert.&lt;br&gt;
ThreatMemory sends the alert to Hindsight for relevant historical cases.&lt;br&gt;
Hindsight recalls previous investigations and analyst decisions.&lt;br&gt;
The retrieved cases are provided to the LLM as context.&lt;br&gt;
The LLM produces a recommendation and investigation steps.&lt;br&gt;
The analyst makes the final decision.&lt;br&gt;
The analyst's decision and reasoning are retained in Hindsight.&lt;br&gt;
Future alerts can retrieve that experience.&lt;/p&gt;

&lt;p&gt;This creates a continuous loop:&lt;/p&gt;

&lt;p&gt;Alert → Recall → Analyze → Analyst Decision → Retain → Future Recall&lt;/p&gt;

&lt;p&gt;Hindsight is therefore not just another component in the application. It is the part that allows previous investigations to become usable context for future ones.&lt;/p&gt;

&lt;p&gt;The before-and-after difference&lt;/p&gt;

&lt;p&gt;The most important part of ThreatMemory is the difference between analyzing an alert with memory and without memory.&lt;/p&gt;

&lt;p&gt;Memory OFF&lt;/p&gt;

&lt;p&gt;When Hindsight memory is disabled, ThreatMemory explicitly tells the LLM:&lt;/p&gt;

&lt;p&gt;Memory is OFF.&lt;/p&gt;

&lt;p&gt;Do not use any historical cases.&lt;br&gt;
Analyze this alert only from the information contained in the alert itself.&lt;/p&gt;

&lt;p&gt;For the example alert, the AI identified the unusually high number of failed attempts and recommended further investigation.&lt;/p&gt;

&lt;p&gt;That is reasonable.&lt;/p&gt;

&lt;p&gt;But it is working with only the current alert.&lt;/p&gt;

&lt;p&gt;Memory ON&lt;/p&gt;

&lt;p&gt;Now the same alert is analyzed with Hindsight enabled.&lt;/p&gt;

&lt;p&gt;ThreatMemory retrieves relevant historical investigations.&lt;/p&gt;

&lt;p&gt;For example, previous cases may show that similar failed-login alerts originated from the organization's corporate VPN infrastructure and were ultimately classified as false alarms.&lt;/p&gt;

&lt;p&gt;The LLM can now consider that history alongside the current alert.&lt;/p&gt;

&lt;p&gt;Instead of starting from zero, it has organizational context.&lt;/p&gt;

&lt;p&gt;The important distinction is that ThreatMemory does not blindly copy an old decision.&lt;/p&gt;

&lt;p&gt;The prompt explicitly tells the model:&lt;/p&gt;

&lt;p&gt;When historical cases are provided, use them as context.&lt;br&gt;
Memory should influence the recommendation naturally.&lt;br&gt;
Do not blindly copy an old decision.&lt;br&gt;
The analyst always makes the final decision.&lt;/p&gt;

&lt;p&gt;This matters because a similar-looking alert can still represent a completely different incident.&lt;/p&gt;

&lt;p&gt;How Hindsight is used&lt;/p&gt;

&lt;p&gt;The core memory operation is retrieval.&lt;/p&gt;

&lt;p&gt;Conceptually, ThreatMemory takes the current alert and asks Hindsight:&lt;/p&gt;

&lt;p&gt;“What previous investigations are relevant to this alert?”&lt;/p&gt;

&lt;p&gt;The application then passes the retrieved cases to the LLM as historical context.&lt;/p&gt;

&lt;p&gt;A simplified part of the implementation looks like this:&lt;/p&gt;

&lt;p&gt;if memory_enabled and memories:&lt;br&gt;
    memory_text = "\n\n".join(&lt;br&gt;
        f"PAST CASE {i + 1}:\n{m['text']}"&lt;br&gt;
        for i, m in enumerate(memories)&lt;br&gt;
    )&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;context = f"""
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Historical security cases retrieved from Hindsight:&lt;/p&gt;

&lt;p&gt;{memory_text}&lt;br&gt;
"""&lt;/p&gt;

&lt;p&gt;The important part is that the model isn't receiving an arbitrary collection of documents.&lt;/p&gt;

&lt;p&gt;The historical cases are retrieved specifically in response to the current alert.&lt;/p&gt;

&lt;p&gt;That allows semantically similar incidents to become relevant even when the wording or exact details differ.&lt;/p&gt;

&lt;p&gt;Memory doesn't replace the analyst&lt;/p&gt;

&lt;p&gt;One design decision was important from the beginning:&lt;/p&gt;

&lt;p&gt;ThreatMemory is decision support, not an autonomous security system.&lt;/p&gt;

&lt;p&gt;The AI provides:&lt;/p&gt;

&lt;p&gt;A recommendation&lt;br&gt;
Confidence&lt;br&gt;
Reasoning&lt;br&gt;
Recommended investigation steps&lt;br&gt;
Relevant historical cases&lt;/p&gt;

&lt;p&gt;But the analyst makes the final decision.&lt;/p&gt;

&lt;p&gt;The interface contains a dedicated Analyst Decision section with three options:&lt;/p&gt;

&lt;p&gt;False Alarm&lt;br&gt;
Real Threat&lt;br&gt;
Needs Investigation&lt;/p&gt;

&lt;p&gt;The analyst can also provide a reason for the decision.&lt;/p&gt;

&lt;p&gt;That decision is then stored back into Hindsight.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;The source IP was confirmed as corporate VPN infrastructure and the employee verified the login attempts as legitimate.&lt;/p&gt;

&lt;p&gt;This transforms an analyst's investigation from a one-time action into future context.&lt;/p&gt;

&lt;p&gt;The learning loop&lt;/p&gt;

&lt;p&gt;This is where the system becomes more interesting than a simple RAG application.&lt;/p&gt;

&lt;p&gt;Suppose an analyst investigates an alert and discovers that it was a legitimate VPN event.&lt;/p&gt;

&lt;p&gt;ThreatMemory stores that outcome.&lt;/p&gt;

&lt;p&gt;Later, another alert appears with similar characteristics.&lt;/p&gt;

&lt;p&gt;Hindsight can retrieve the previous investigation, allowing the AI to consider the team's previous experience.&lt;/p&gt;

&lt;p&gt;The system therefore has two directions of memory:&lt;/p&gt;

&lt;p&gt;Recall:&lt;br&gt;
“What have we learned about cases like this?”&lt;/p&gt;

&lt;p&gt;Retain:&lt;br&gt;
“What did the analyst learn from this case?”&lt;/p&gt;

&lt;p&gt;Over time, the memory store can contain different types of experience:&lt;/p&gt;

&lt;p&gt;Repeated false alarms&lt;br&gt;
Confirmed attacks&lt;br&gt;
Legitimate backup activity&lt;br&gt;
Business-travel login events&lt;br&gt;
Analyst overrides&lt;br&gt;
Previously unknown patterns that were later resolved&lt;/p&gt;

&lt;p&gt;This makes the memory useful beyond simply remembering conversations.&lt;/p&gt;

&lt;p&gt;What I learned building it&lt;/p&gt;

&lt;p&gt;The biggest lesson was that adding memory isn't automatically useful.&lt;/p&gt;

&lt;p&gt;The memory has to affect the actual workflow.&lt;/p&gt;

&lt;p&gt;A system that retrieves five old records but doesn't change how the current task is handled isn't meaningfully using agent memory.&lt;/p&gt;

&lt;p&gt;For ThreatMemory, the memory layer is directly connected to the decision process:&lt;/p&gt;

&lt;p&gt;Current alert → Relevant experience → AI reasoning → Analyst decision → New experience&lt;/p&gt;

&lt;p&gt;Another important lesson was to keep the scope narrow.&lt;/p&gt;

&lt;p&gt;Instead of trying to build a complete security operations platform, ThreatMemory focuses on one workflow: security alert triage.&lt;/p&gt;

&lt;p&gt;That makes the role of memory easy to understand and easy to demonstrate.&lt;/p&gt;

&lt;p&gt;A limitation&lt;/p&gt;

&lt;p&gt;ThreatMemory is currently a prototype using realistic synthetic security cases.&lt;/p&gt;

&lt;p&gt;That means its historical memory is only as useful as the information stored in it.&lt;/p&gt;

&lt;p&gt;A production system would need much stronger safeguards around data quality, access control, privacy, retention policies, auditability, and the accuracy of analyst decisions.&lt;/p&gt;

&lt;p&gt;It would also need integration with real security systems such as authentication logs, SIEM platforms, endpoint telemetry, and incident-management systems.&lt;/p&gt;

&lt;p&gt;The current application deliberately stops before autonomous response.&lt;/p&gt;

&lt;p&gt;It recommends.&lt;/p&gt;

&lt;p&gt;The analyst decides.&lt;/p&gt;

&lt;h2&gt;
  
  
  Project Links
&lt;/h2&gt;

&lt;p&gt;🔗 &lt;strong&gt;Live Demo:&lt;/strong&gt; &lt;a href="https://threatmemory-f2kdfnwvpefa9isiquicgxv.streamlit.app" rel="noopener noreferrer"&gt;https://threatmemory-f2kdfnwvpefa9isiquicgxv.streamlit.app&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;💻 &lt;strong&gt;GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/adithya9666/threatmemory" rel="noopener noreferrer"&gt;https://github.com/adithya9666/threatmemory&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What's next&lt;/p&gt;

&lt;p&gt;The next step would be to connect ThreatMemory to real organizational security data and allow the memory to grow naturally from real investigations.&lt;/p&gt;

&lt;p&gt;The broader idea goes beyond cybersecurity.&lt;/p&gt;

&lt;p&gt;Many professional workflows have the same problem: people repeatedly make decisions using information that their organization has already learned, but that knowledge is scattered across previous cases.&lt;/p&gt;

&lt;p&gt;Persistent agent memory creates a way for AI systems to carry that experience forward.&lt;/p&gt;

&lt;p&gt;For ThreatMemory, the goal is straightforward:&lt;/p&gt;

&lt;p&gt;Don't make the analyst investigate every alert as if it has never happened before.&lt;/p&gt;

&lt;p&gt;Give the AI access to what the team has already learned — while keeping the human analyst in control.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffkqu55tgm8krd976z58d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffkqu55tgm8krd976z58d.png" alt=" " width="800" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwhl9s64itde9sm610ul4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwhl9s64itde9sm610ul4.png" alt=" " width="800" height="520"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy2bqbvse45g020fs2sab.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fy2bqbvse45g020fs2sab.png" alt=" " width="800" height="520"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwclick0gggvtxr128e7n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwclick0gggvtxr128e7n.png" alt=" " width="800" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>python</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
