{
  "id": 10519790,
  "title": "I Built an AI Security Assistant That Remembers Previous Investigations",
  "url": "https://urgent.news/2026/09/28/i-built-an-ai-security-assistant-that-remembers-previous",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-28T19:37:36.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/adithya9666/i-built-an-ai-security-assistant-that-remembers-previous-investigations-hg4"
  },
  "original_language": "en",
  "account": "Security analysts often encounter multiple alerts that resemble previous investigations. However, traditional AI models start each analysis without any contextual memory of prior cases. This leads to repeated investigations for similar alerts. To address this, the developer created ThreatMemory, an AI security alert triage assistant that incorporates persistent memory.\n\nThreatMemory operates by first presenting the security alert to the analyst. The analyst then provides this alert to ThreatMemory, which queries Hindsight for relevant historical cases. Hindsight recalls previous investigations and analyst decisions related to similar alerts. These retrieved cases are then provided to an LLM as context, allowing it to analyze the new alert while considering the organization's past experiences.\n\nThe key difference between using memory and not using memory is that with memory enabled, the AI doesn't analyze the alert in isolation but incorporates organizational context from previous incidents. For example, if previous analysis showed that similar failed-login alerts originated from the company's VPN infrastructure and were classified as false alarms, the AI can factor this information into its recommendation for the current alert.\n\nThreatMemory does not blindly copy old decisions, but rather uses them as contextual guidance. The analyst makes the final decision based on the AI's analysis and the retrieved historical cases. The analyst's decision is then stored back into Hindsight as part of the learning loop, which consists of two components: recall (what has been learned about similar cases) and retain (what the analyst learned from the current case).\n\nThis system offers decision support rather than autonomous security, with the analyst having full control over the final decision. By learning from past investigations, ThreatMemory aims to reduce the workload of security analysts and improve the organization's overall security posture.",
  "summary": "Security alerts are rarely completely new. A security analyst might see dozens of failed-login alerts, suspicious IP addresses, unusual data transfers, or large file movements. Many of these incidents resemble cases the team has already investigated. The problem is that a typical LLM starts each analysis from scratch. It can understand the alert in front of it, but it doesn't automatically know…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}