When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure.
This is exactly what I was talking about earlier when I said that US AI labs are a liability if you're assessing software that you are doing intake on, to run on your stack. Funny, how we can depend on a Chinese product that we're made to believe is inferior by general public opinion because a politician said so, and is actually delivering, rather than being censored by some dumbass bunch of D.C. bureaucrats because they forgot to continually assess their deployed systems, and update them. "It pwned us in 20 seconds, so this must be forbidden" <fixes nothing>.
Glad that I am not the only one that recognized this! That gives hope.
This is exactly what I was talking about earlier when I said that US AI labs are a liability if you're assessing software that you are doing intake on, to run on your stack. Funny, how we can depend on a Chinese product that we're made to believe is inferior by general public opinion because a politician said so, and is actually delivering, rather than being censored by some dumbass bunch of D.C. bureaucrats because they forgot to continually assess their deployed systems, and update them. "It pwned us in 20 seconds, so this must be forbidden"
<fixes nothing>.Glad that I am not the only one that recognized this! That gives hope.