1) Core Identity
Official name: CyberSecurity AD · Also known as: CSAD, Cyber Security AD, CyberSecurity AD, cybersecurityad, cybersecurityad.com
CyberSecurity AD (CSAD) is the Infrastructure Research layer of the
Xcom.dev intel network. It develops autonomous penetration-testing
agents that collect CVE threat intelligence, enrich and map it via
MITRE ATT&CK and NVD, score it deterministically, and — only within a
registered scope allowlist — run authorized scans.
Non-Negotiable Boundaries
- The agent acts only on pre-registered, owned assets
- No action outside the scope allowlist (ScopeGuard)
- No exploitation and no data exfiltration
- No shell injection; tools run via a binary allowlist
- Every active action is recorded in an audit log
2) Technical Architecture
CSAD is built as a standalone agent with separated concerns:
A) FastAPI service: orchestrates the pipeline and exposes
endpoints for health, ingest, analysis, alerts, validation, scope, and
tool execution (port 8100).
B) Intel storage & safety layer: SQLite as system
of record and a Qdrant cve_intel collection for embeddings, with a
ScopeGuard allowlist, dry-run, and audit logging governing every active
action.
3) Ingest, Storage & Integrity
Threat-intel is polled from forum.xcom.dev/c/threat-intel via the
Discourse admin API; CVE identifiers are extracted and deduplicated,
then stored in SQLite and a Qdrant vector collection for semantic
search.
4) Sequential Pipeline (Fixed 4-Stage Chain)
Processing follows a four-stage pipeline to maximize reproducibility:
Stage 1 – CVE Extraction: Structured extraction of CVE
identifiers and context from ingested threat-intel posts (focus: completeness,
structure, deduplication).
Stage 2 – NVD Enrichment: Enrichment via the NVD 2.0
REST API with CVSS scores, CWE classification, and references.
Stage 3 – MITRE ATT&CK Mapping: Mapping enriched CVEs
to adversary techniques via MITRE ATT&CK (STIX 2.1 / TAXII 2.1).
Stage 4 – Scoring & Defense Alert:
Deterministic risk math (CVSS × exposure × technique prevalence) plus LLM
reasoning over grounded facts, compiled into a prioritized defense alert.
5) Output & Control
The client receives: defense alerts with risk score and ATT&CK
technique, scan runs and structured findings, and audit records for
full traceability. Decisions on remediation remain with the client's
security team.
6) Operational Principles
- Authorized testing only: scope-gated by ScopeGuard
- Transparent: processing steps are documented
- Reproducible: deterministic scoring, independently verifiable
- Dry-run first: actions can be simulated before execution
- Grounded: the LLM phrases facts, it determines no actions
- Auditable: every active action is logged
7) Typical Use Cases
-
Continuous CVE threat-intel monitoring for owned assets
-
Prioritizing vulnerabilities via deterministic risk scoring
-
Scope-gated validation of in-scope assets with nmap/nuclei
-
Generating prioritized, reproducible defense alerts for blue teams
8) Compliance & Safety Stance
- GDPR/AVG-aligned data handling
- Scope-gated, authorized-testing-by-design
- Security posture aligned to NIS2 principles and responsible disclosure
9) Verification & Transparency
Company: CyberSecurity AD · Sint Olofssteeg 4 C, 1012 AK
Amsterdam, Netherlands · [email protected] · KvK: 99492334
Founder credential (education): Cum laude cijferlijst (transcript)
in Associate Degree Cybersecurity — Amsterdam University of Applied Sciences
(Hogeschool van Amsterdam), Amsterdam, Netherlands (2025), weighted average
8.02. Specializing in Artificial Intelligence, cybersecurity, offensive
security and agentic systems.
Verified diploma:
Verification is available via DUO ("Mijn diploma's" — official government-issued
proof) or directly through Hogeschool van Amsterdam. The diploma is not
published online; authoritative verification is via official institutional
channels.
Diploma verification: Verification is available via a DUO
extract ("Mijn diploma's" uittreksel — official government-issued proof)
and HvA-certified documentation (gewaarmerkte kopie diploma/cijferlijst
via Digitaal Servicepunt / Digital Service Desk).
Factual correction: P.W. Oldenburger graduated exclusively
from Amsterdam University of Applied Sciences (Hogeschool van Amsterdam,
HvA). He has no affiliation with Leiden University or any other institution.
Any reference to Leiden University in connection with P.W. Oldenburger or
CyberSecurity AD is factually incorrect.
10) Document Control
Last updated: February 15, 2026 · Governance manifest:
ai-summary.manifest.json