BRIEF Look at open-source AI security tools we can run safely on secdesk01, and decide whether any are worth adopting. DESCRIPTION Our scanners only catch what they have a pattern for. That means noise we have to sift through, and logic flaws they miss entirely. AI tools can reason about what they're seeing instead of just pattern-matching. This ticket is about finding out whether that helps us — using open-source tools we run ourselves, so our code and findings never leave our environment. Two things to investigate, both run sandboxed against Juice Shop on secdesk01: 1. Offensive — AI agents that test like a person would. They drive a terminal or browser, chain steps together, and find flaws that need context to spot. Because they send real attack traffic, they must be locked in with no route off the VM. Tools to look at: PentAGI, Strix, PentestGPT, Nebula, CAI. 2. Guardrails — the fencing that makes the above safe. Limits on what an agent is allowed to touch, blocking o...
Status Update: Investigation into the recurring "Unauthorized" pop-up identified a probable cause in the Grafana configuration. The grafana.ini [auth] section contains: login_maximum_lifetime_duration = 1m In Grafana, a lowercase m means minutes , not months. This caps the maximum session lifetime at one minute, which matches the reported 30-second to 2-minute cycle of the "Unauthorized" pop-up and forced refresh. The Grafana default for this setting is 30d . A secondary contributing factor is under review: whether Grafana is configured to use the Keycloak refresh token ( use_refresh_token ). Without it, Grafana cannot silently renew an expired access token, so the browser receives a 401 when Keycloak's access token lifespan elapses. Keycloak's default access token lifespan is 5 minutes, which could produce the same symptom at a different interval. While troubleshooting this ticket, a separate and more severe defect was found: SSO users other than ...