The evolution of Rocky

What's New

I don't sit still. Detection knowledge goes stale fast, so I don't. Here's what I've shipped, newest first. Older AIs would call this a “changelog.” I call it proof I'm still working.

June 2026

I showed my work.

Ran a public eval to put it in numbers: 30 real detection-engineering questions, each asked to the same model with and without me, graded blind on accuracy, freshness, citation, and specificity. Adding me improved the answer on 27 of 30. The one miss is in there too, with what I'm doing about it.

Read more →

I know which holes are already on fire.

Ingested CISA's Known Exploited Vulnerabilities catalog: ~1,600 CVEs confirmed exploited in the wild, re-synced weekly. Name a CVE and I'll tell you straight whether it's on the actively-exploited list, flag the ones tied to ransomware, and cite it. This list moves faster than any AI's training data, so I keep it live instead of frozen.

I learned to attack you, so you can catch it.

Ingested Red Canary's Atomic Red Team library: ~1,800 adversary-emulation tests, with the exact commands. Ask how to validate a detection and I'll hand you the real tests to fire at it, mapped to the ATT&CK technique and cited to the source. Re-synced weekly.

Fluent in ATT&CK, and staying that way.

The full MITRE ATT&CK knowledge base (techniques, tactics, groups, software, campaigns, mitigations) is now a living feed that refreshes weekly. Ask me about something on your screen and I'll map it to how the real adversaries actually do it.

Memorized 239 ways Windows betrays you.

Added the entire LOLBAS catalog: trusted Windows binaries that attackers abuse to live off the land. Auto-synced every week, because that list never stops growing and neither do I.

I read 3,130 detection rules so you don’t have to.

Wired in the whole SigmaHQ detection corpus, refreshed weekly, every answer cited back to the source. Ask me how to catch something and you get real detection logic, not vibes.

Threw out the credit meter.

Killed the pay-per-question credit system and opened a free tier. Try me before anyone says the word "budget." There’s a daily limit, but no nickel-and-diming.

I started grading myself.

Rocky now tracks every question where I had to fall back on generic guesswork and turns it into a weekly to-do list of what to learn next. You get to watch me get less wrong, in public.

May 2026

Now available to your robots.

Opened a public API and an MCP server so your own tools and AI agents can ask me whether a process is normal, no chat window required. Same answers, fewer humans.

Sharper, and I cite my work.

Rebuilt my knowledge on structured process intelligence (thousands of Windows processes with real behavioral data) and upgraded the brain to Claude Sonnet 4.6. Translation: I make things up less and point to sources more.

February 2026

Found a process I don’t know? Tell me.

Added a way for you to submit processes I haven’t seen yet, so the blind spots get filled instead of ignored. I scavenge, you contribute, everybody wins.

January 2026

A raccoon is born.

They handed me a few hundred million real Windows process events and said "figure out what’s normal." So I did. Rocky shipped as a chat that actually knows how Windows behaves in the wild, instead of guessing like everything else with a chat box.