Refuted by Default: Dragos’ Methodology for AI-Driven Vulnerability Detection in OT Security Software
ID: 43699f59-3665-5b89-b9b2-2fb8c32b59c8
STIX ID: report--43699f59-3665-5b89-b9b2-2fb8c32b59c8
Feed Name: Dragos Blog
This report describes Dragos’s methodology for running AI-driven, adversary-modeled vulnerability hunts against its own OT codebase: building threat-model maps, running four operating modes (from single-session to large-scale harnesses), and enforcing a strict refute-first verification pipeline that requires observable proof and skeptical judgment before findings reach engineers. The program produced thousands of candidates, high refutation rates, and several confirmed issues (including critical findings), and emphasizes continuous sweeps, diff-level checks, and composition-based chain-building to harden critical-infrastructure software against AI-equipped adversaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
