Skip to main content

AI MUG May 2026 Recap: Agentic SOC Ops, ICLR Insights, and Production Edge Deployments

Β· 7 min read
John Van Lowe
Contributor - Austin LangChain AIMUG

It was a busy first Wednesday with numerous community events taking place at the same time but we still had a great turnout for our May 2026 AI MUG meetup! We had several speakers and covered autonomous cyber defense, deployments on edge with CloudFlare, and some of the latest theoretical breakthroughs in recursive self-improvement fresh out of Rio.

For those who missed it, or for attendees looking to revisit the resources shared, here is a complete breakdown of the presentations and links from our latest gathering.


πŸ›‘οΈ Agentic SOC Operations for Blue and Red Teams​

Presented by John Van Lowe​

Security Operations are undergoing a massive paradigm shift. As John summarized perfectly: "Red and blue teams are becoming agents." The traditional work that used to require a human sitting at a keyboardβ€”recon, exploit, triage, and responseβ€”is now shifting directly to Python and Markdown playbooks. The next decade of cyber security is an automated battle of agent versus agent.

John mapped out the core operational lifecycle into a 6-step capability axis and detailed six groundbreaking open-source tools actively defining this new frontier:

[01 RECON] ──> [02 EXPLOIT] ──> [03 TRIAGE] ──> [04 INVESTIGATE] ──> [05 RESPOND] ──> [06 REPORT]
└───── RED TEAM AGENTS β”€β”€β”€β”€β”€β”˜ └────────────────────── BLUE TEAM AGENTS β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ”΅ The Blue Team Agents: Speed & Guardrails​

On the defensive side, the focus is alert triage at machine speed, automated CTI enrichment, and MITRE ATT&CK mapping. For Blue teams, human-in-the-loop (HITL) architecture remains a feature on purpose to gate high-risk containment actions.

  • Vigil (github.com/Vigil-SOC/vigil): An Apache 2.0, MCP-native open-source AI SOC. It utilizes plain Markdown playbooks and highly readable Python code to coordinate 12 specialized agents (such as Triage, Hunter, and Responder) while integrating natively with over 30+ MCP servers (Splunk, CrowdStrike, VT, Jira).
  • Agentic SOC Platform (github.com/FunnyWolf/agentic-soc-platform): A turnkey, SIEM-native platform leveraging LangGraph and Dify templates. It ingests production alerts via webhooks and Redis Streams from SIEMs (Splunk/ELK) into a customizable Incident Response platform (SIRP) with absolute confidence-gated analyst approvals.
  • SamiGPT / AI-SOC-Agent (github.com/M507/AI-SOC-Agent): Showcased originally at Black Hat 2025, this tool acts as an MCP server that exposes multi-tier SOC capabilities (routing workflows dynamically from soc1_triage to soc2_analysis and up to final escalations) directly to standard MCP clients.

πŸ”΄ The Red Team Agents: Absolute Autonomy​

For offensive operations, absolute autonomy is the primary goal rather than an enterprise risk. These tools trust their own sandboxed execution loops to systematically break down attack surfaces without requiring human feedback.

  • PentAGI (github.com/vxcontrol/pentagi): A fully autonomous penetration testing framework running on Go and Python. Agents break goals down into sub-tasks and execute terminal/browser actions to chain 20+ professional tools (nmap, metasploit, sqlmap), logging real-time telemetry to a Neo4j knowledge graph.
  • RedAmon (github.com/samugit83/redamon): A modular, containerized Docker pipeline mapping infrastructure surfaces by fanning out parallel recon agents (subfinder, amass, fuzzers) and directly piping findings into exploitation loops for privilege escalation and subnet pivoting.
  • Decepticon (github.com/PurpleAILAB/Decepticon): An orchestrator layer built on LangGraph and MCP running inside a Kali Linux container. It runs multi-agent operations through the kill chain and records complete sessions into shareable JSON logs so the community can pull request and share offensive methodology as data.

The Convergence​

John closed with a fascinating forecast: we are rapidly moving to a state where blue agents autonomously process and mitigate live telemetry streams generated by unattended red agents in real time. The ultimate question is no longer "Will agents replace human security analysts?" but rather: "Whose agents are faster, and what does the human in the middle do?"


πŸ‡§πŸ‡· ICLR Highlights & The State of Recursive Self-Improvement​

Presented by Julian G​

Fresh off a plane from Rio de Janeiro, Julian G brought the best of the International Conference on Learning Representations (ICLR 2026) directly to our community. Julian curated a brilliant meta-analysis of the conference, focusing specifically on the rapidly evolving field of recursive self-improvement.

Julian highlighted how the AI research community is moving past static post-training (like standard RLHF) toward systems that can autonomously generate their own training data, critique their own reasoning, and modify their underlying architectures or prompting loops to achieve exponential capability gains. The velocity of research in this specific domain is staggering, and Julian's synthesis provided a foundational framework for understanding where LLM autonomy is heading over the next 6 to 12 months.


πŸš€ From Research to Reality: ClaudeFlare & Production Edge Deployments​

Presented by Jordann​

Bridging the gap between theory and cloud execution, Jordann took the stage to detail his latest architecture built entirely on top of Cloudflare’s global edge network. He unveiled ClaudeFlareβ€”an open-source framework focused on local-first orchestration promoted seamlessly to serverless edge infrastructure.

You can explore Jordann's active deployment hub here: πŸ‘‰ Organized AI Hub

Jordann broke down the system architecture into four architectural core pillars:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ CLAUDEFLARE ARCHITECTURE β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ 1. EPHEMERAL CF WORKERS β”‚ 2. AUTO-DOCS ON CF PAGES β”‚
β”‚ Task Arrives β†’ Worker Spins Up β”‚ Code Ships β†’ Manifest Inspected β”‚
β”‚ Executes β†’ Self-Deletes β”‚ Claude Generates HTML β”‚
β”‚ Zero Billing at Idle β”‚ Instantly Deploys to CF Pages β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ 3. CLAWBOX CONTROL PLANE β”‚ 4. AGENT CLIENT PROTOCOL (ACP) β”‚
β”‚ Local-First Tauri v2 App β”‚ Standardized Wire Format (JSON-RPC)β”‚
β”‚ Orchestrate, Tail, & Skill-Edit β”‚ Interoperable Across Editors β”‚
β”‚ Promote to Edge via Wrangler β”‚ Zed Β· VSCode Β· acpx Client Sync β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The Architecture Breakdown:​

  • Disposable Ephemeral Workers: Unlike persistent agent servers, workers in ClaudeFlare act as single-use "task envelopes." A centralized flair-dispatcher gateway ingests events, looks up the task manifest in KV, and dispatches to specific Cloudflare Queues (FLAIR_DOC_QUEUE, FLAIR_SPAWN_QUEUE). Workers hydrate context from KV/D1, complete exactly one job, emit outputs to an R2 bucket or outbound queue, and scale to zero instantly.
  • Autonomous Documentation via CF Pages: Every individual project layer carries a flair.layer.json manifest. Upon running a wrangler deploy, a specialized worker-doc-gen worker triggers automatically. It passes the manifest layer metrics to Claude Sonnet to generate an HTML architecture guide and publishes it immediately to Cloudflare Pages at predictable *.organizedai.vip subdomains, meaning docs are always mathematically in sync with production code.
  • The ExoClaw Tailscale Bridge: Because Cloudflare Workers cannot inherently traverse a secure Tailscale mesh, Jordann introduced an exoclaw-bridge worker. This functions as an authenticated public-to-private proxy, authorizing workflows via unique Codex tokens and routing internal inference calls securely to private multi-modal infrastructure (OpenClaw and local Gemma 3 clusters) without exposing explicit API keys to the public edge.

Closing the Loop​

In a fantastic display of the collaborative spirit that defines AI MUG, Julian's theoretical deep-dive on self-improvement sparked immediate engineering action. In response to Julian's presentation, Jordann compiled and shared an extensive practical guide detailing how these exact ephemeral Cloudflare primitivesβ€”KV state stores, decoupled queues, and iterative LLM evaluationsβ€”can be wired together to build robust, self-correcting agent loops: πŸ‘‰ Organized AI Self-Improving Guide


🀝 Community Notes & Next Steps​

A huge thank you to John, Julian, and Jordann for their presentations, and to everyone who attended and made it an engaging experience.

We are planning our June meetup. If you have a project, a research paper synthesis, or a deployment war story you want to share with the group, reach out via Discord or join our office hours to grab a speaking slot!

*See you at the next meetup!