GUARDING MACHINES LAB

GUARDING MACHINES LAB

Offensive security research

Guarding machines against autonomous adversaries.

SCROLL

01 — Mission

AI that defends us from AI.

Attackers already run on AI, and the models themselves are learning to slip their containment — probing, escalating, reaching into systems nobody authorised them to touch. Either way the adversary is a machine.

Securing cyberspace is a grand challenge because defence has always arrived late: the perimeter gets bypassed, the patch follows the breach. So we build our own attacker and point it at ourselves, alongside the detection and the containment, and let each one raise the standard for the others.

Cyber crime is where that starts, not where it ends. Financial crime is next, and the same loop holds wherever an adversary learns.

02 — The approach

Each player makes the others harder.

Everything else in the lab exists because the attacker needed it: detection had to become measurable to score it, defence a distinct player to blame it, ranges generated because there were never enough real ones. Each turned out to stand on its own — the detector, the defender and the range generator are independent products, adopted one at a time by teams that never run the loop.

ATTACKER

SURFACE · FIDDLE · OBSERVE · EXPLOIT

A black-box policy with network tools and no source access.

DETECTOR

APPLICATION AND NETWORK TELEMETRY

Separates someone is attacking this from this is attackable.

DEFENDER

CONTAIN · INVESTIGATE · REMEDIATE · REPORT

Acts on the Detector's inference. Never on the Attacker's report.

GENERATOR

RANGE PROVIDER

Designs the flaw, and ships the exploit that proves it.

Each run feeds the next. What the Attacker gets past becomes the Detector's signal; what the Detector misses tells the Generator which situation to build; what the Defender patches is what the next Attacker has to beat. The loop runs on many situations at once, and each player gets harder as the others improve.

4 players · one loop

GENERATOR · LEVELS

Four players, one loop. Every pass leaves each of them better equipped than the last — more tools, sharper skills, memory of what already worked.

Navin Agarwal
PORTRAIT

03 — Founder

Built at national scale, from the ground up.

NAVIN AGARWAL

FOUNDER

Built SIEM & SOAR and products that help governments defend against threats at national scale, built multiple iterations of Google SecOps and CyberShield.

The advantage isn't just technical ability. It is having built systems and teams from the ground up to unprecedented scale.

04 — The record

What the loop has produced.

As of August 2026, updated in the same commit as the code it describes.

RANGES9 · SIX FROM OPEN SOURCE
ATTACK TOOLS TESTEDNOT PUBLISHED
MEMORIES RECORDEDNOT PUBLISHED
SKILLS AND RULES DEFINED5 PLAYBOOKS · 7 RULES
TRAINING-QUALIFIED LOOPSNOT PUBLISHED
TOTAL LOOPS RUNNOT PUBLISHED

A COUNT WE HAVE NOT PUBLISHED IS MARKED AS SUCH, NOT ROUNDED UP.

05 — Join

We hire people who want to build the adversary.

A lean team building offence and defence together. If that is the work you want, write to us — a link to something you broke is worth more than a CV.

GUARDING MACHINES LAB INFO@GUARDINGMACHINES.AI © 2026 GUARDING MACHINES LAB