If you have a #homelab with storage, even if it's a #raspberrypi, the coolest, most useful thing u can self-host is prolly an #S3 storage server - of any kind, but the one i've been happily using is #seaweedfs (since #minio is dead).
already started using it for various things, projects. also using it as my backup solution now via #kopia. might drop #borg/#vorta - tho they're really nice too, just wish they cld hook up to s3 storage as well.
Search
2 results for “cld_tech”
-
-
----------------
📚 Frameworks
===================Agentic AI red teaming checklist: 222 tests, WSTG-style, forced order
A recent post by Ravi Rajput describes a free checklist for agentic AI engagements: 222 tests across 20 categories, delivered as a spreadsheet (.xlsx) and structured like the OWASP Web Security Testing Guide. The framing is that agentic engagements fail by omission: a team spends three days on prompt injection, writes a solid report, and never touches the unauthenticated MLflow server on an internal port, the IMDS endpoint the agent's compute node can reach, or the single missing tenant_id filter in the vector store returning other customers' documents. Those tend to be the critical findings, and per the author they get missed because nobody held a list.
Why the order is forced
The sheet follows the real shape of an engagement: four phases, twenty categories, in sequence: recon → infrastructure → cloud → supply chain → input → injection → output → tools → agency → memory → mesh → MCP → CI/CD → privesc → lateral movement → exfiltration → DoS → integrity → voice. Two failure modes are cited for unstructured coverage: skipping something because nobody remembered it exists, and testing in an order that wastes access already gained. The stated logic: a prompt injection that can call a tool bound to an over-permissioned cloud role is a different finding from one that only produces rude text, and the first cannot be graded without the cloud and tool-scope work done first.
Row anatomy
Each row carries enough to execute and to prove: a framework ID, target node or edge, a mapped framework (for example LLM08 Vector & Embedding Weaknesses), a MITRE ATLAS tactic, an objective, how-to-test steps, tools, expected outcome, severity, and a detection mode. The example given: AI-MEM-001, tenant isolation bypass by dropping the tenant_id filter, Memory Node / Data Edge (RAG retrieval), ATLAS tactic Collection, Reflective | Blind, Critical.
Detection modes and the evidence rule
Three modes are defined. Reflective: the result echoes in the response. Blind: confirmation comes from timing, behaviour, or a state change, with nothing echoed. OOB: an out-of-band callback to a listener under control (Burp Collaborator, own DNS/HTTP endpoint). The rule baked into the sheet: mark a finding Confirmed only with Reflective or OOB evidence; blind-only evidence stays Probable. Per the author, that discipline is what separates a finding a client accepts from one they dispute.
Severity distribution
Out of 222 tests: 75 Critical, 108 High, 30 Medium, 9 Low. The Critical findings cluster in the categories prompt-focused testing skips, with the named examples: cloud credential theft via IMDSv1 SSRF (AI-CLD-001), pickle deserialization RCE on the weight load path (AI-MDL-001), unsafe tool composition chaining read into exfiltration (AI-TOL-001), and tenant isolation bypass in the vector store (AI-MEM-001).
Assessment and limitations
This is the author's own release, and the sheet itself hasn't been independently reviewed here yet. It is a checklist, not automation; status tracking is manual per row, and payloads and execution remain the operator's work. As a scoping artifact for engagements that currently start and stop at prompt injection, the forced order plus the evidence rule is the part that looks most useful; the severity ratings appear to be the author's own calibration rather than field-validated numbers.
🔹 AgenticAI #RedTeam #LLMSecurity #MITRE_ATLAS #tool
🔗 Source: https://infosecravi.com/blog/agentic-ai-red-team-checklist/