[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$freynbsljfrip":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":57,"categories":59,"source":61,"lang":64,"author":65,"audioState":68,"stats":69,"publishedAt":72,"renderer":73},"6abad0fcca21c797c7e9a53a","i-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2","I Built an AI Security Assistant That Remembers Previous Investigations","Security alerts are rarely completely new.","news",[10,12,17,22,27,32,37,42,47,52],{"headline":6,"body":7,"imageUrl":11,"sourceImageUrl":11},"https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn1wyigdru4tyn0qiyr1o.png",{"headline":13,"body":14,"imageUrl":15,"images":16},"A security analyst might see dozens of failed-login","A security analyst might see dozens of failed-login alerts, suspicious IP addresses, unusual data transfers, or large file movements. Many of these incidents resemble cases the team has already investigated. The problem is that a typical LLM starts each analysis from scratch.","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F1.webp",{"local":15},{"headline":18,"body":19,"imageUrl":20,"images":21},"It can understand the alert in front of","It can understand the alert in front of it, but it doesn't automatically know how the security team handled a similar incident last week. I built ThreatMemory to explore a different approach: an AI security alert triage assistant with persistent memory.","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F2.webp",{"local":20},{"headline":23,"body":24,"imageUrl":25,"images":26},"Instead of only asking an AI what it","Instead of only asking an AI what it thinks about an alert, let it remember what the security team learned from previous alerts. The problem with stateless alert analysis Consider a security alert like this: 36 failed authentication attempts against payroll@company.com from IP 185.20.4.21 between 01:50 AM and 02:05 AM. A normal AI assistant can analyze the information contained in that alert. It might identify several possibilities:","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F3.webp",{"local":25},{"headline":28,"body":29,"imageUrl":30,"images":31},"A legitimate employee repeatedly entering the wrong password","A legitimate employee repeatedly entering the wrong password A VPN-related authentication problem A brute-force attempt Credential stuffing A compromised device","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F4.webp",{"local":30},{"headline":33,"body":34,"imageUrl":35,"images":36},"Without additional context, the AI has no way","Without additional context, the AI has no way to know how this organization's security team handled similar events previously. That means every alert becomes a new investigation. ThreatMemory adds a memory layer to this process. The application has three main components: Security analyst → ThreatMemory → Hindsight + LLM","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F5.webp",{"local":35},{"headline":38,"body":39,"imageUrl":40,"images":41},"The analyst provides a security alert. ThreatMemory sends","The analyst provides a security alert. ThreatMemory sends the alert to Hindsight for relevant historical cases. Hindsight recalls previous investigations and analyst decisions. The retrieved cases are provided to the LLM as context. The LLM produces a recommendation and investigation steps. The analyst makes the final decision. The analyst's decision and reasoning are retained in Hindsight. Future alerts can retrieve that experience. This creates a continuous loop: Alert → Recall → Analyze → Analyst Decision → Retain → Future Recall","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F6.webp",{"local":40},{"headline":43,"body":44,"imageUrl":45,"images":46},"Hindsight is therefore not just another component in","Hindsight is therefore not just another component in the application. It is the part that allows previous investigations to become usable context for future ones. The before-and-after difference The most important part of ThreatMemory is the difference between analyzing an alert with memory and without memory. When Hindsight memory is disabled, ThreatMemory explicitly tells the LLM: Do not use any historical cases. Analyze this alert only from the information contained in the alert itself.","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F7.webp",{"local":45},{"headline":48,"body":49,"imageUrl":50,"images":51},"For the example alert, the AI identified the","For the example alert, the AI identified the unusually high number of failed attempts and recommended further investigation. But it is working with only the current alert. Now the same alert is analyzed with Hindsight enabled. ThreatMemory retrieves relevant historical investigations.","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F8.webp",{"local":50},{"headline":53,"body":54,"imageUrl":55,"images":56},"For example, previous cases may show that similar","For example, previous cases may show that similar failed-login alerts originated from the organization's corporate VPN infrastructure and were ultimately classified as false alarms. The LLM can now consider that history alongside the current alert. Instead of starting from zero, it has organizational context. The important distinction is that ThreatMemory does not blindly copy an old decision. The prompt explicitly tells the model:","\u002Fapi\u002Fmedia\u002Fposts\u002Fi-built-an-ai-security-assistant-that-remembers-previous-inv-b2b9f8d2\u002F9.webp",{"local":55},[58],"dev",[60],"Technology",{"name":62,"url":63},"Dev.to","https:\u002F\u002Fdev.to\u002Fadithya9666\u002Fi-built-an-ai-security-assistant-that-remembers-previous-investigations-hg4","en",{"handle":66,"displayName":67},"spots","Spots","queued",{"views":70,"likes":71,"saves":71,"shares":71,"completions":71,"opens":71,"skips":71,"depthSum":71},3,0,"2026-09-28T20:41:32.191Z","local"]