Security triage · evaluation · research
- Role
- Hackathon team contributor; research follow-on
Awarded team prototype · research follow-on
We shipped the prototype.
Then questioned the model.
I built the hackathon's data-to-investigation loop, then helped turn its weak evaluation into a stricter research question.
- Ship
- Correlate
- Score
- Stress test
- Explain
- Bound
- BASELINERandom rows
- TIMEChronological
- SENSORNew detector
- ORGNew organization
Results held until artifacts are mapped
- Hackathon prototype
Four contributors connected data, scoring, explanations, and a working dashboard during the hackathon.
TEAMFour contributorsDEMOWorking dashboardAWARD2nd Place - Not in the public prototype
The public prototype grouped nearby rows; the research design replaces that batch shortcut with bounded, past-only state.
TOKENSEntity + contextSTATEActive storiesBOUNDSExpiry + suppression - Prototype metric is exploratory
A tree model ranks the queue; the interface keeps its grade, confidence, and local drivers visible.
POLICYAllow / block fieldsMODELIncident gradeQUEUEPriority + drivers - Results held until artifacts are mapped
The research plan tests the same estimator across time, detector, and organization boundaries.
BASELINERandom rowsTIMEChronologicalSENSORNew detectorORGNew organization - Results held until artifacts are mapped
The research design tests whether SHAP drivers stay stable and actually affect the fitted model.
STABILITYCompare driver ranksDELETERemove top driversKEEPRetain top drivers - No analyst-outcome claim
A local LLM receives a selected evidence packet only after deterministic triage.
PACKETPrediction + SHAP + storyLOCALSelected cases onlyCHECKSchema + claim IDs